Wednesday, August 30, 2017

Aruba ClearPass Part 2



Is your business prepared? Today’s organizations face a complex IT infrastructure, more exposed to cyberattacks than ever. The Internet of Things, an always-on mobile workforce and BYOD make visibility into your network more challenging and critical.

Identifying what’s on your network is a never-ending challenge. Not only do you need to prevent malicious users from gaining access, you have to protect against unauthorized devices and applications.

Businesses today embrace the idea of anywhere, anytime connectivity, but often ignore the need for secure network access control. Many employ a “laid back NAC” solution. Others choose the same vendor for security and network infrastructure. Both these approaches give the illusion of security, even compliance, but in reality, leave extensive security gaps.

As an Aruba ClearPass expert and partner, Convergent Technologies Group can help you reduce time spent identifying devices on your network, enforce policies, and protect your network. We will help you address questions, like:

  • What’s on my network?
  • How do I simplify mobile security?
  • Can I limit mobile devices without limiting productivity or increasing security risks?
  • How do I unify internal and external security tools?

Get started by taking this brief assessment to help you determine your network’s level of security and see how your business might be at risk. To enforce security standards throughout your enterprise, you need secure enterprise network access control (NAC). 

Aruba ClearPass is changing the NAC space, helping companies understand what’s on your network and keeping your information secure. This is an important first step in building a strategy to take control of what’s connecting to your network to keep your data secure and your business safe.

For more information about what the Aruba ClearPass solution can do to defend your network, contact Convergent Technologies Group at sales@ctgva.com or 804-353-5307.




Tuesday, August 22, 2017

Aruba ClearPass Part 1



By Jeff Joyner


Network Access Control or NAC has been around for over a decade, but there are many organizations where this technology has yet to be embraced.  This may be changing thanks to the trend of BYOD (bring your own device).  Companies who want to have more control with the devices allowed on their network are turning to NAC to provide this type of security solution.  The HPE/Aruba ClearPass platform is a best-of-breed product that will provide granular control of wireless and wired access and be able to grow as your company grows.

Say you want to allow employees the ability to connect their personal tablets or laptops to the corporate network where you control which resources can be accessed.  And you want to make sure these devices have appropriate security software installed and updated.  You also have contractors on site that require wired and/or wireless connectivity to the network and need to have access to specific resources during business hours only.  ClearPass can do all of this and much more.

Guest wireless is often offered with either an open (no password) network or with a password that rarely gets changed.  ClearPass can automate individual password generation per user with limitations on bandwidth and time-of-day access if preferred.  You can also force guests to request access with approval from an internal user (manager, receptionist, etc).

ClearPass is flexible in that it works with many vendors, so you don’t have to rip out your current switching environment to make this solution work.  It also supports multiple operating systems including Windows, Mac OS X, Linux, iOS and Android.

For more information about what the Aruba ClearPass solution can do for your network, contact CTG Sales at sales@ctgva.com or 804-353-5307.



Jeff Joyner is a network engineer at Convergent Technologies Group.

Friday, July 14, 2017

A New Compute Experience: An Exploration of HPE’s Gen10 Servers

By Rod Knowles

Is your business finding it difficult to adapt to industry and marketplace shifts, analyzing the customer experience and/or innovating products and services rapidly?  If so, then you’re probably not thinking about, or have a plan in place for your digital transformation.  In today’s economy, digital transformation is the key to a businesses success and remaining ahead of the competition.  Through 4 key transformation areas:  Protecting the digital enterprise, Empowering the data-driven organization, Enabling workplace productivity and Transforming to a hybrid infrastructure, companies can increase profits, agility, flexibility, employee productivity and the customer experience while reducing costs and risk.  For businesses to thrive and easily adapt to their digital transformation, they need a computing environment that will deliver a Hybrid IT infrastructure providing agility, security and economic control.  HPE’s new Gen10 server line accomplishes just that.  Automation, optimized performance of workloads, secure compute lifecycle and flexible capacity are just a few of the benefits your company can gain from switching to an HPE Gen10 server.  In the next few sections, I will break down the benefits on the Gen10 line as its related to agility, security, and economic control.

Obtaining a more agile infrastructure

Manual IT operation processes can be slow and error-prone.  With the new iLO5, being introduced in all Gen10 servers, you will be able to accelerate maintenance tasks, at scale, with automated scheduling and rollback.  iLO5’s RESTful API helps automate and operate server components in all Gen10 servers from staging and updating the server BIOS, iLO, Secure Boot and TPM.  With iLO5’s intelligent provisioning, IT departments can perform initial setup tasks 22% faster than with previous versions of IP on Gen9 servers. Gen10's new Intelligent Systems Tuning can harness the power of the next generation of Intel Xeon processors and balance workloads which allows you to run more workloads on more cores, up to 28 on Intel's New Xeon Platinum processors, resulting in reduced licensing costs and more power/cooling efficiency. Couple that with HPEs new NVDIMMs to utilize the fastest persistent memory available, while realizing the real-world benefits of memory backup power, OS & Application support, reduction of database licensing costs and the fastest tier of storage on HPE Servers.

Increasing security awareness and control

Gen10 security, a better way to stay one step ahead of increasingly sophisticated attacks and protect your business utilizing the world’s most secure industry standard servers. Let’s talk about that for one quick moment, “The World’s Most Secure Industry Standard Servers”.  As recently announced at HPE Discover 2017, HPE engaged InfusionPoints to conduct an independent assessment of the security of the Gen10 Server’s hardware and platform firmware against three of HPE’s competitors. The test consisted of attacks against physical interfaces, platform firmware, and network interfaces.  The results showed that HPE Gen10 servers are a significant step ahead of their competitors and that HPE’s introduction of silicon root of trust will set new standards in providing auditable control of the integrity of platform firmware.

The new Gen10 family of servers provides a host of security features:  firmware protection, run time attack detection, behavioral risk mitigation, data protection, compliance planning and End of Life disposal.  HPE’s new firmware protection is backed by HPE’s own silicon fingerprint unique to each and every server.  With HPE’s silicon root of trust, Gen10 servers WILL NOT boot unless the firmware matches the fingerprint and is protected through the entire supply chain: manufacturing, distribution, shipping, configuration, and installation. It’s locked and HPE is the only vendor who can do this.  When the server boots, millions of lines of firmware code run and verify before the operating system even boots.  Additionally, the firmware is checked every 24 hours verifying validity and credibility of UEFI, CPLD, iLO, IE and ME and reports any malware or compromised code.  Firmware can also be checked and validated on drives, NICs and other HPE server options containing firmware. When a detection of compromised firmware is discovered, the ability to send alerts and quickly recover to a good known state can be set to occur automatically or you can choose to take the compromised server offline.  The ability to recover other server settings can also be recovered as well as the future ability to recover operating systems. 
HPE’s Gen10 servers also offer advanced machine learning that identifies any malicious behavior.  Think of it like this:  The system endlessly trains itself and learns behavioral patterns.  It then analyses and identifies changes in these patterns that may relate to suspicious activity and informs you if there is a threat.  This advanced machine learning technology utilizing Niara’s behavioral analytics protects your organization from inside attacks.  Gen10 servers are protected from inception to their demise. When your server(s) are being disposed of, its embedded data cannot be reconstructed or accessed any longer, forever, utilizing enhanced data protection and encryption.

Managing Your Time and Money Productively

In addition to the Gen10’s server line agility and security features, Economic Control helps you control costs with over-provisioning, out-of-control public cloud costs and the pressures of transforming without the appropriate budget.  Utilizing HPE Flexible Capacity will help align your costs with monthly usage and requires no upfront payments.  Pay only for what you use and scale in minutes, not months.  If you're currently a legacy Gen9 server owner, there are several options for transitioning to a Gen10 server by utilizing one of HPE’s investment models for transforming from legacy IT to a hybrid IT model.

For more information on HPE Storage and Networking, please contact Convergent Technologies Group at 888-353-5307 or via our contact us page



 Rod Knowles is a solution architect with Convergent Technologies Group.

Wednesday, June 14, 2017

A Recap of HPE Discover 2017

Charles Fowler

This past week I attended Hewlett Packard Enterprise’s (HPE) Discover 2017 in Las Vegas, NV. Discover is HPE’s annual customer and partner conference where HPE showcases new products and services. The conference lasts 3 days and is broken up into focus areas and general sessions. This was my first year attending as a partner rather than a HPE employee. The experience was not much different other than I hosted 4 clients vs the average 12 clients while employed at HPE which made it a bit more relaxing and fewer logistics for sure.

The general session concentrates on HPE’s direction and how they are solving the current needs of a digital world. This year’s general session focused primarily on Hybrid IT, Generation 10 Servers, and Project New Stack. Meg Whitman, HPE’s CEO, is focusing her efforts on 3 key areas: Digital Transformation, Hybrid IT, and the Intelligent Edge. These are all areas where Whitman sees the potential for tremendous growth in a world where everything computes. HPE’s recent acquisition of SimpliVity and Nimble were also mentioned in her keynote but, were not primary topics of conversation. There was a hint that those two technologies may be instrumental in HPE’s composable infrastructure solutions of the future. Whitman stated that HPE has seen a 30% revenue gain in all-flash storage last quarter and they are expecting that number to grow with the acquisition of Nimble. Whitman said while cloud computing is certainly a fit for some companies, HPE can deliver those same services in a hybrid cloud at a fraction of the cost. HPE believes more and more people are moving away from the cloud due to lack of control, security, performance, or cost. Whitman was not recommending that customers pull the plug but rather invest in a hybrid model that has all the benefits of the public cloud without some of the pitfalls. Additional cost savings may be realized using HPE’s Flex Capacity consumption model, which was also discussed in multiple keynotes and breakout sessions during the week. 

The Intelligent Edge was another focus area for Whitman, claiming a 30% increase in Aruba revenue over the last consecutive 7 quarters. As a partner, and former HPE employee, I can attest to that growth as I have seen a huge amount of Cisco customers moving over to Aruba, both on the wired and wireless networks. Aruba has jump charged HPE’s network business with no signs of it slowing down. While Aruba has mostly been present on the network edge, they will be releasing a new core switch that will be available for purchase soon. Whitman’s point about the intelligent edge was that everything will one day be internet connected, placing more importance on the edge that supports those devices. The internet of everything (IOT) is well underway.

Whitman next introduced Clark Golestani, Global CIO and President of Emerging Business at the pharmaceutical behemoth Merck. Golestani was very complimentary of the products and services provided by HPE. He went on to say that he was doing business with HPE based on the quality of their products, capabilities to support his company, ability to respond, and security. Golestani emphasized Merck’s pathway to hybrid cloud stating that Merck could not risk their business or the welfare of their clients on a cloud only model, supporting the hybrid direction Whitman announced during her keynote. 

Next, Whitman introduced Antonio Neri (Exec VP and GM of HPE’s Enterprise Group). Neri focused on the complexity of Hybrid IT. He mentioned HPE’s commitment to simplify hybrid IT by helping customers define the right hybrid mix using Pointnext software, power the right mix utilizing the HPE ecosystem, and optimize the right mix with consumption models. The point being, companies will now have a mix of traditional IT, private cloud, and public cloud. The challenge will be managing all 3 of those efficiently.

Neri introduced Alain Andreoli, SVP and GM of the HPE Data Center Infrastructure Group. Andreoli spoke about the new Generation 10 Proliant servers, touting the inherent security features built in to the silicon of each new Gen10 server. Neri touted HPE as being the first to incorporate this into their servers. He also spoke about active protection and recovery, a technology that constantly monitors the server for malicious behavior through machine learning. Neri mentioned Niara, a recently acquired security company, as being behind some of these security improvements. There was also mention of an end-of-life security feature that would make it impossible to recover data from retired servers.

All in all, it was a great event. It was a good mix of education and entertainment. Getting ahead of what is coming can never be a bad thing. It would have taken me weeks to learn everything I was able to cover in just few days at HPE Discover. The shear amount of equipment and resources they dedicate to this event is amazing. While I find the breakout sessions useful, it is the technology expo and the keynotes I enjoy the most. My purpose for attending is to learn about existing and future technologies, and a general understanding of how these are being applied to make a positive difference in our everyday lives. If you have not attended HPE Discover, I recommend you consider attending in the future. As the Director of Sales at Convergent Technologies Group, it would be my pleasure to host you at the 2018 Discover.


Cheers

Tuesday, May 16, 2017

WannaCry Ransomware

By Jeff Joyner 

The WannaCry ransomware (aka WannaCrypt) is a ransomware computer worm infecting 200,000+ computers worldwide. It targets MS Windows systems (desktop and server) exploiting an SMB protocol vulnerability resulting in files getting encrypted until the victim pays a ransom in BitCoin currency ($300-$600) to the attacker. Windows 10 and Windows Server 2016 operating systems are not affected by this attack.

A patch was released by Microsoft for each of the affected, currently supported operating systems back in March. Patching systems with Windows Updates is an easy way to prevent devices from being infected. 

For information on older systems (Windows XP, Server 2003), Microsoft has published additional guidance at this link: https://blogs.technet.microsoft.com/msrc/2017/05/12/customer-guidance-for-wannacrypt-attacks/

Additionally, MalwareBytes and Webroot have stated that they actively block WannaCry attacks.

Call CTG sales or your account manager to learn how we can secure your network from threats like this.

Jeff Joyner is a Senior Network Engineer at Convergent Technologies Group.

Ingram Micro Cloud Summit

By Jeff Garell

 

I had the good fortune to attend the Ingram Micro Cloud Summit last week in beautiful Phoenix, Arizona. This conference offers the opportunity to talk to representatives from a large cross section of cloud service providers. Some of the names are quite well known such as Amazon, Microsoft, Dropbox, and Hewlett Packard Enterprise and others you may not have like Odin, Intermedia, and NCR (among many others).

I should clear up that this conference is exclusively focused on companies like CTG that help customers make informed decisions about technology. I mention this simply to explain that many of the sessions were about attempting to convince us to sign on with them to sell their stuff and how to market/price/deliver these services.  Candidly, it can be a bit of a meat grinder at times but the alternative is to attempt to reach out and coordinate with each of these organizations individually with the possibility of missing some of the lesser known names that may be a great fit.  And there’s no way to do all of that in 2 days without a conference like this one.

So after being educated, solicited, and sold to for two days here are just some of the highlights and takeaways:

The Thursday morning keynote by Marc Randolph, one of the founders of Netflix, was thoroughly entertaining, informative, and entrepreneurial.  He spoke about the process that he and his cofounder went through before finally settling on this twice discarded idea of sending movies through the mail. Interestingly, the idea originated in the days of VHS tapes and was undoable in terms of mailing & storage costs for that format. The DVD technology shift enabled them to re-visit the idea a second time, but they had another thing they were pursuing, so they shelved it again.   Eventually they came back around to this DVD through the mail thing and got started.  Marc discussed the trial and error processes, the successful and unsuccessful campaigns, learning to iterate their promotions and changes more quickly, and how they were at one point perched on the edge of closing up the shop.   He told the story of their meeting with Blockbuster and for the low price of $50 million they could be purchased.  Blockbuster said no (obviously) and on the plane ride back from that meeting Marc and his partners decided to take down Blockbuster, who then was the largest player in the movie rental business, bar none.  And they eventually did.  All in all the message was to continue to generate ideas, spend a little time determining the feasibility, quickly chuck the ones that don’t make the cut (you don’t have that kind of time to waste, do you?), and move forward with the promising one(s).  That ideas come from everywhere and usually from a “pain” that you experience – as in, “wouldn’t it be nice if someone could find a way to fix [insert a daily annoyance you experience]?” Why not be that “someone”?

A meeting with Dropbox was interesting and enlightening. I’ve been a Dropbox user since getting a beta invite a lifetime ago but honestly didn’t look into, or understand, what kind of business/enterprise offering they had, or even why.  I walked into the meeting a bit skeptical about what I would possibly learn…and said as much, politely of course.  It turns out, there is a “there” there and it falls under the “Shadow IT” umbrella.   For those that don’t know what that means, it’s when your employees go outside of the internal IT services being offered and sign up for things like Dropbox in order to perform their job.  For example, Dropbox makes it really easy to share documents with anyone in a secure manner.  So imagine a marketing department needing to share image files with an outside ad agency or print shop that can’t be emailed because of their size.  Poof!  Dropbox account.  The problem with that approach is multifold. First is that there’s no way for the business to know exactly what data is being shared outside the organization and to whom.  The enterprise edition gives IT the control and reporting to know these details.  Second, is that the Dropbox terms and conditions state that the data in an account belongs to the account holder.  Imagine you have to let someone go and learn that they have been using this unmanaged & unapproved service that is now full of your proprietary information.  Dropbox considers it the account holder’s, not yours.  Finally, there are integrations and add-ons to do things like Rights Management and Data Loss Protection.

On a similar note, I attended the Microsoft Secure Productive Enterprise pre-conference session to learn about new advances in Office 365 and how it continues to improve security in a cloud connected world.  The session focused on what you get with the addition of the Enterprise Mobility & Security option – and there’s a lot. Microsoft covered quite a bit in the two hour session and it could have gone much longer once Q&A started.  In a nutshell, this additional service gives you the ability to manage and control mobile devices, advanced eDiscovery, and create policies around encryption, rights management, and Data Loss Protection to name just a few things. These kinds of features are important for everyone but exceptionally important for those industries where data loss is an expensive proposition (I’m looking at you, healthcare, legal, financial, and utilities).

There was so much more in that whirlwind two day conference and I’m still going through my notes and will be grabbing presentations as soon as they’re made available – so there will possibly be a part two to this post. The only item on my wish list for this conference, and keep in mind I’m a grizzled old nerd, is that there were technical deep dive or hands on options. It’s one thing to tell a room full of sales guys that your product does x or y that are thinking “show me the money!”, it’s another when you have folks like me (and there were many) that are thinking “show me the console!”. I’m hoping there will be a technical track added in the future.  The good news is I got to meet all of the right people to setup trials and demos to get my hands on those consoles – which also will undoubtedly spawn more blog posts. (You have been warned.)

Jeff Garell is the co-founder of Convergent Technologies Group.