03Identity-driven network access

ให้สิทธิ์ผู้ใช้และอุปกรณ์จาก Identity, Posture และ Context

Arista Guardian for Network Identity (AGNI) เป็น NAC ที่เชื่อม User, Endpoint และ IoT เข้ากับ Policy กลาง พร้อม Profiling, Continuous posture และ Microsegmentation สำหรับ Wired และ Wireless แบบ Multi-vendor

Connected architecture

องค์ประกอบที่ทำงาน
ร่วมกันเป็นระบบ

Architecture ถูกแบ่งเป็น Layer ที่ชัดเจน เพื่อเลือกเริ่มจากส่วนที่จำเป็นและเชื่อมต่อกับระบบเดิมขององค์กรได้

01

Identity sources

เชื่อม Directory, IdP, MDM และ Certificate เพื่อระบุตัวตนผู้ใช้กับอุปกรณ์

02

AGNI policy

ประเมิน Identity, Device profile, Posture, Location และ Risk ก่อนกำหนดสิทธิ์

03

Network enforcement

ทำ AAA ผ่าน RadSec หรือ RADIUS และส่ง Role/Segment ไปยัง Wired กับ Wireless infrastructure

04

Continuous trust

ติดตาม Context หลังเชื่อมต่อและเปลี่ยน Policy เมื่อ Posture หรือ Risk เปลี่ยน

Core capabilities

ความสามารถหลัก

เลือกใช้ตาม Outcome, Operating model และข้อจำกัดของระบบจริง โดยไม่จำเป็นต้องเปิดใช้ทุกส่วนพร้อมกัน

01

Device profiling

จำแนก Managed, Unmanaged, IoT และ Guest device เพื่อกำหนด Onboarding flow ที่เหมาะสม

02

Posture assessment

ประเมิน Health และ Compliance ก่อนและระหว่างการเชื่อมต่อ Network

03

Microsegmentation

ใช้ MSS และ UPSK แยกสิทธิ์ตาม User, Device และ Application โดยไม่ต้องพึ่ง VLAN จำนวนมาก

04

Open integration

รองรับ Multi-vendor network พร้อม API และ Pub/Sub สำหรับเชื่อม Security ecosystem

Portfolio & deployment

รุ่นและรูปแบบ
ที่ควรพิจารณา

รายการนี้ใช้เป็นแกนสำหรับ Architecture workshop การเลือก SKU, License และ Sizing จริงต้องตรวจสอบ Requirement กับ Datasheet รุ่นล่าสุดอีกครั้ง

01Cloud service
CloudVision AGNI cloud interface

AGNI Cloud

NAC แบบ Cloud-native ลดภาระติดตั้ง Infrastructure และรองรับหลาย Site จาก Policy กลาง

Cloud-hosted policyRadSecMulti-site operations
เหมาะกับองค์กรที่ต้องการ Rollout รวดเร็ว บริหารสาขาร่วมกัน และใช้ TLS-protected AAA ระหว่าง Network กับ Cloud
02Customer controlled
AGNI integrations and services overview

AGNI On-premises

วาง Management และ Policy service ภายในสำหรับข้อกำหนด Data residency หรือ Network isolation

On-prem deploymentRADIUSLocal policy services
เหมาะกับพื้นที่ที่ต้องควบคุม Service ภายในและต้องออกแบบ Availability, Sizing และ Lifecycle เอง
03Policy building blocks
AGNI simple scalable secure capabilities

Identity & access

ประกอบ Policy จาก Identity, Profile, Posture, Location, Time และ Risk

802.1XMABGuest/BYODUPSK
รองรับ Use case ตั้งแต่ Corporate device ไปจนถึง Headless IoT และ Guest onboarding
Expected outcomes

สิ่งที่ทีม Infrastructure
ควรวัดผลได้

  1. 01เห็นอุปกรณ์ก่อนให้สิทธิ์
  2. 02ลด Manual VLAN และ Policy sprawl
  3. 03ควบคุม IoT และ BYOD ได้ละเอียดขึ้น
  4. 04เลือก Cloud หรือ On‑prem ตามข้อกำหนด
Architecture & sizing workshop

ออกแบบ CloudVision AGNI ให้เหมาะกับ Campus ของคุณ

เตรียมจำนวน Site, User, Device, Application, Link, Identity source และระบบเดิม เพื่อวาง Architecture, License และ Pilot scope ร่วมกัน