
foundation and architecture of the sage zero trust blockchain protected fabric for industrial IoT, detailing identity based access, zero trust remote access, and distributed ledger enforcement.
Explore zero-trust remote access, secure file transfer, and data exchange within the sage fabric for OT and IT, featuring blockchain-backed policy enforcement and one-way IPsec tunneling.
Install the sage fabric across three nodes, define sites, and compare standard versus custom installations, while reviewing minimum hardware requirements and initial topology for IT, OT, and center sites.
Install xage zero trust blockchain-protected fabric for IIoT by provisioning three Linux VMs (manager, IT, OT), configuring networking and SSH, and deploying the stage manager and edge nodes.
Explore the sage zero trust fabric dashboard through a system overview of sites, nodes, and zips, and learn about backups, audit logs, and access management.
Explore identity-centric zero-trust access management for OT, mapping user groups to device groups via policies, using edge node reverse proxies and MFA-enabled authentication.
Configure users and user groups with multi-factor authentication by creating administrator and normal user roles, enabling one-time passwords and authenticator app verification, and testing login across the fabric.
Configure ssh access to OT edge nodes using ssh proxy and web ssh proxy, set up device groups, and define read-only access policies with stage manager approvals.
Explore session collaboration enabling Ahmed to have full control while Hatim remains read-only via web ssh, with policies and device groups enforcing granular access.
Explain session collaboration in sage fabric: full-control users can invite read-only peers; sessions end for others when the inviter logs out, with a disconnect all option.
Xage is specialized in Zero Trust approach for access management for critical infrastructure including the operational technology to serve basically three key use cases:
1) Zero trust secure local access for floor operations within the OT infrastructure itself, as well as
2) Securely facilitate vendor and third-party OEM remote access into the critical infrastructure down to the OT devices the L1 devices the PLCs and the RTUs, as well as
3) Enable Dynamic data security to secure the sharing of events and data streams from the OT devices to any external entity without exposing those OT systems to any other networks
So all the sessions will always be terminated within the OT infrastructure itself to achieve that
Xage is basically three different products bonded into one single fabric platform
1) Identity-based Access Management
2) Zero trust Remote Access
3) Zero Trust Data Security
Xage does privilege access management, it basically allows you to create or integrate with active directory and create user accounts with specific privileges to Target critical devices where the Xage fabric will be the interface for accessing those critical devices and all the critical device credentials will not be exposed to the user, however it will be closely managed by the Xage fabric itself
In this course we will try to cover the following
- Foundations and Architecture
- Zero Trust Remote Access, File Transfer, and Data Exchange
- Installation and Deployment
- GUI demstifyied
- Access Management
- Device Management
- Policies
- Configure Users & User Groups with MFA
- WebSSH Access Policy with Authorization
- Session Collaboration
Please note that xage image download/license requires xage support entitlement or to be an active partner with xage