Micro Segmentation
  • 27 Sep 2023
  • Dark
    Light

Micro Segmentation

  • Dark
    Light

Article Summary

Service Overview

Micro Segmentation is a network observation and security platform that provides protection against malware spread across both server and desktop endpoints, regardless of location. As a SaaS based platform, management of rules and policies is available from anywhere. Policies can be based on endpoint type (ex. production servers, servers that make up a business application) or end user group (ex. Sales, IT). This allows for an incredibly granular protection structure without manually configuring each endpoint. Expedient will assist with the configuration and deployment of Micro Segmentation, and clients have full access to view network traffic paths, create policies, and deploy agents.

Service Features

  • Single sign on and multi-factor authentication to the management portal
  • Agent-based deployment
  • Network visualization to tailor policies to how traffic actually flows
  • Assistance with policy, workload group, and tag creation
  • Allow list design
    • All non-allowed traffic is blocked

Default Deployment Settings

  • Default policies for Expedient managed services
  • Assistance with agent deployment
  • Agents enabled in observe mode, ensuring no disruption to traffic
  • Direction on enabling policies

Use Cases

  • Ransomware prevention
  • Granular network security
  • East-west traffic firewall
  • Older operating system threat protection
    • Windows
    • Linux
    • macOS

Responsibility and Accountability Matrix

Micro Segmentation Responsibility Matrix 

Task 

Expedient 

Client 

Co-Managed  

Co-Managed tasks can be performed by Expedient or Client based on Client's preference 

Tenant creation

 

 

 

User authentication configuration

X




Agent Installation

X

X

X

Expedient will work with clients on best practices for deployment

Default policy configuration

X




Tag creation

X

X

X

Expedient will work with clients on best practices for tags

Workload Group creation

X

X

X

Expedient will work with clients on best practices for workload groups

Policy creation

X

X

X

Expedient will work with clients on best practices for policies

Best practice guidance

X



Expedient will provide guidance on the best practices for micro segmentation and policy enforcement

Policy enforcement


X



Supported Platforms

Applications/Platforms Supported

Expedient Services

  • Expedient Enterprise Cloud
  • Dedicated Private Cloud
  • Enterprise Workspace
  • Expedient Edge
  • vColo
  • Colocation
Operating Systems (virtual or physical)
  • Workload OS (Servers)
    • AIX - 7.1
    • CentOS - 6.7, 6.8, 6.9, 6.10, 7.2, 7.3, 7.6
    • macOS - 10.10, 10.11, 10.12, 10.13, 10.14, 10.15
    • RHEL - 6.7, 6.8, 7.1, 7.2, 7.3, 7.4
    • SUSE - 12, 12 SP2, 12 SP3, 12 SP4
    • Ubuntu - 12.04, 14.04, 16.04, 18.04
    • Windows 32-bit - XP SP3, 7, 2003 SP2, 2003 R2, 2008 SP1, 2008 SP2, 2008 R2
    • Windows 64-bit - 2003 SP2, 2003 R2, 2008 SP1, 2008 SP2, 2008 R2, 2012, 2012 R2, 2016, 2019 Standard, 2019 Datacenter, Windows 7 Embedded Standard, 10 Pro, 10 Home, 11
  • User OS (endpoints with user logins, using user identity for policies)
    • macOS - 10.10, 10.11, 10.12, 10.13, 10.14, 10.15
    • Windows 64-bit - 7, 8, 8.1, 10, 10 Pro, 10 Home, 11
Hypervisors (support for workload and user OS)
  • VMware ESXi
  • Hyper-V
  • AHV

Hyperscale Cloud (support for workload and user OS)

  • Amazon Web Services
  • Microsoft Azure
  • Google Cloud Platform

Was this article helpful?