Skip to content

Publication Date

Better connecting the university by simplifying identities

Client type: Public sector

Industry: Education

Solutions: Cisco SD-Access Fabric

The education sector, from school service centres to university campuses, presents a complex challenge of access rights, devices and multiple identities. With teachers and students often using their own devices (BYOD) as well as classroom equipment, how can organizations strengthen security without making account and access management more cumbersome?

The challenge: managing permissions without complications

Legacy segmentation limits agility.

  • Security defined by IP address ranges or switch ACLs, with multiple rules and a higher risk of errors
  • Static assignment of network port configurations, which is difficult to adapt without manual intervention
  • Layer 2 service extension across the campus, which can lead to major outages and weakened security
  • An inconsistent user experience between wired and wireless networks
  • Difficulty supporting BYOD (Bring Your Own Device)

Today’s solutions make it possible to segment as close as possible to the source: the user.

Our solution: replacing the IP address with identity through SD-Access Fabric

With Cisco Identity Services Engine (ISE), permissions are based on identity, regardless of who is moving, where they are on campus, or whether they connect through a wired or wireless network. Users are added to a virtual network with access rights.

Since ISE integrates natively with other tools, identities are aligned with existing profiles in another user database, such as Active Directory or Microsoft Entra ID. It is therefore a simple solution to implement with the infrastructure already in place by importing all groups and using them as a point of definition for identities.

Result: effective micro-segmentation, without added complexity

With SD-Access Fabric and micro-segmentation, security is enabled by default without having to define any security policy. Permissions are granted based on what has been assigned to identity types, such as student or teacher.

As a result, the same person keeps the same permissions no matter where they connect from or which device they use. For example, a teacher can move from their tablet to the computer in their lab. Micro-segmentation, through SGT identity (Secure Group Tag), defines access rules within the same virtual network.

Benefit: stable and secure access, regardless of location or device

SD-Access Fabric enables

  • Full mobility, as students and teachers retain their access rights at all times
  • Built-in security, because segmentation automatically follows the user or device
  • The end of VLAN-based segmentation, resulting in simplified, consistent and scalable management
  • Reduced IT support workload, with fewer support tickets to open a port or change a VLAN
  • Easier BYOD management

Cisco’s modern security approach is particularly well suited to education environments, where a wide variety of managed and unmanaged devices (BYOD) coexist. Users need to access educational and administrative resources from multiple campuses, remote sites or off-site locations, while benefiting from a simple and seamless experience. Through an architecture based on Zero Trust principles, identity-based access control, network segmentation and application visibility, Cisco makes it possible to apply consistent and granular security policies while ensuring a smooth user experience, regardless of the device used, the network accessed or the user’s location.

Emile DesRosiers

Émile Des Rosiers

Solutions Architect, ITI

Also: the same simplicity and fluidity for connected devices

With SD-Access Fabric, devices and IoT objects (Internet of Things) can also be authenticated and authorized, just like users.

Think of different types of equipment connected to the network, such as:

  • Cameras
  • Building access control systems
  • Fire safety devices
  • Sensors and thermostats
  • HVAC controllers
  • Etc.

Each device has specific connectivity needs depending on the solution associated with it. Some require Layer 2 extension across the entire campus, while others support older protocols. Very often, the solutions behind these devices must be managed and operated by external providers.

SD-Access Fabric therefore offers the same mobility and built-in security benefits as it does for users, while also making it easier to isolate connections for external providers.

From a technical standpoint, there is no longer any static port configuration; everything is dynamic. This brings significant operational efficiency gains for IT teams.

Emile DesRosiers

Émile Des Rosiers

Solutions Architect, ITI

pop up newsletter

Newsletter

Subscribe and get an e-book on technological challenges and IT solutions.