Introduction to MSS
Arista Multi-domain Segmentation Services (MSS) is a key component of Arista's Zero Trust Networking (ZTN) strategy. It helps organizations enhance network security by implementing microperimeter segmentation, which reduces the attack surface and limits lateral movement within the network. MSS enables the creation of fine-grained security policies based on endpoint identity and application behavior, moving beyond traditional network boundaries.
This guide provides a comprehensive overview of MSS, covering its core features, deployment steps, and operational aspects. It details how to leverage tools like CloudVision, MSS Studio, Policy Manager, and the ZTX Monitor Node to build and enforce zero trust policies.
Key Features and Concepts
- Microperimeter Segmentation: Define granular security zones around endpoints and workloads.
- Zero Trust Policy Enforcement: Ensure all network traffic is explicitly allowed by security policies.
- Traffic Visibility: Monitor network flows and identify policy violations.
- CloudVision Integration: Utilize CloudVision for policy management, configuration, and dynamic group discovery.
- ZTX Monitor Node: Provides visibility into app-to-app traffic for policy development.
Getting Started with MSS
The deployment of MSS involves several key steps, starting with understanding the requirements and proceeding through configuration and policy implementation. This guide walks users through the entire process, from initial setup to ongoing management.
For more detailed information, refer to the official Arista documentation available at Arista.com.