Security in Action – Top Use-Cases with Nile NaaS
Nile’s mission is to be the “easy button” for network and security in on-premises deployments. The company was founded by networking industry veterans, including former Cisco executives John Chambers and Pankaj Patel, to address the complexity of enterprise LAN environments. Nile has pioneered a new architectural approach, backed by numerous patents, that has led to its recognition as a Visionary in the Gartner Magic Quadrant for Enterprise Wired and Wireless LAN Infrastructure. The Nile service is deployed globally across various verticals, powering large-scale environments such as a 12 million square-foot warehouse and concurrently supporting over 200,000 users.
Shiv Mehra detailed Nile’s Zero Trust fabric, designed to counter common attack paths by securing the infrastructure, controlling network access, and governing post-access activity. The infrastructure itself is hardened by design; Nile hardware has no direct management interfaces like SSH or Telnet, and all communications between fabric components are mutually authenticated and encrypted with MACsec. Access control operates on a “deny by default” principle where physical ports are “colorless,” meaning access is determined solely by identity, not port configuration. Nile makes identity verification a cornerstone, supporting seamless wired and wireless SSO integrated with IdPs, traditional 802.1X/RADIUS, and a robust system for IoT devices that combines continuous fingerprinting with optional device validation to ensure proper identification and segmentation.
This identity-first approach enables a “segment of one,” where every user and device is isolated by default, preventing lateral movement and network reconnaissance as demonstrated in a live demo. The policy engine, called the Trust Service, enforces granular, least-privilege access by requiring every entity to belong to a group (user, device, or application). Policies are then built by defining rules between these groups, enhanced with contextual attributes like device compliance status from an MDM or EDR. A final demo showcased the ease of this model by creating a policy in a few clicks to allow only a specific video streaming protocol between employees, while all other inter-employee traffic, including pings, remained blocked, illustrating how Nile simplifies the implementation of true microsegmentation.
Presented by Shiv Mehra, VP, Service and Solution, and Jaswanth Kongara, Solutions Engineering. Recorded live at Security Field Day 14 in Silicon Valley on September 25, 2025. Watch the entire presentation at https://techfieldday.com/appearance/nile-presents-at-security-field-day-14/ or visit https://techfieldday.com/event/xfd14/ or https://NileSecure.com for more information.
Transcript
So before we look at, uh, some details on the fabric, let's try and understand today, how does an attacker infiltrate a network? Right? It's all about the initial breach.
Either you're carrying a, a box of donuts, someone holds a door, you land up in there, get an MTQ, plug a laptop in, right? That's one way, which is on multiple blogs around that. Others, you have stolen credentials, right?
So that's one way to at least breach the network. Next, once you are in there, you can use some scanning tools to figure out the topology of the network. What's where, what are some critical resources?
And then you can go undetected by just laterally moving, right? Most customers are not implementing private VLANs, they're not implementing IP access list. Add that layer to switch, right?
So you start jump, infect the network, and that's how you kind of hijack it. So we looked at this problem statement and thought, how could we build this entire zero trust fabric, right? So the first thing obviously is we have to make sure the network itself is very secure.
So ESH touched upon some of these things, right? How do you make sure that this hardware cannot be hacked, right? If you eliminate SSH, if you eliminate telenet, if you eliminate H-G-T-P-S log into the boxes, uh, right?
You basically have gotten rid of that, eliminate that problem. So you don't have to worry about changing oil if you don't have a gas engine, right? So that's, that's the approach we took, and we're gonna double click on each one of these in a minute.
The second one was, how do you access the network, right? If everything is blocked by default, everything is denied by default. You have to present identity, you get on the network.
And by identity, I just don't mean users only you hear from us. Iot, iot, iot. For us, it doesn't matter what you plug in a device, it has to have an identity, either a user or it has to be a device.
And then finally, once you have access, what can you do? Right? What can shiv with his Intune compliant laptop do versus what can shiv with his personal iPhone on that corporate network too, right?
So you have to distinguish between those two. And, you know, Sosh mentioned about attributes sets. So we'll again, get into more details as we go along.
So let's click on this first infrastructure. We spoke about mutual lot, right? Every AP can only communicate with the Nile Switch and the Nile Cloud, right?
Every switch can only communicate, you know, with the Nile, uh, neighboring switch or AP and the cloud. So we make sure that you mutually auth based on TPM search, based on keys that are encrypted right in, in that platform itself. Uh, we also make sure that everything is max encrypted.
So AP to switch communication, switch to switch communication is encrypted, all ports are blocked, right? So we will show you a demo. JA is gonna go into some more details.
Uh, you don't have SSH, you don't have Telenet, right? We are trying to make sure that you don't, you don't have the ability to really, you know, hack into those boxes. So the question then is how do you get metrics?
What happens when something breaks, when I wanna troubleshoot? So two things, right? The first part is we stream metrics from these devices every minute, and in some cases, multiple times are met, right?
So by metrics I mean ccrs, CPU, memory usage, radio buffers, all the wifi stuff. Nothing to do with user data. So the good thing is we can literally see minute by minute, you know, how things are progressing.
Is there a process that's kind of leaking memory, right? Can we look into that right away and nip it in the bud right before we, before it gets really big? The second thing is, you know, software is software.
Things can break, right? This can crash. So how do you get those last breadth of logs that are there in that, in that unit?
So we have two ways to do it. Uh, it's basically using Bluetooth. So Bluetooth is turned on either in a factory default state on this device or when that device fails.
And the beauty is you don't have to be on site to get those logs, the neighboring switch or the neighboring ap. Uh, our, our uh, uh, p and e team, which is a production network engineering team, they can turn on Bluetooth on a good switch, connect to the neighboring switch, pull those logs, right? Or you have a nine mobile app, you have a work order job associated with that site, you can then go and pull some commands using some commands.
That last breath of logs. So the idea really here is that if you really need it, yes, you can get it through that Bluetooth, which is only turned on during a crash or during factory, uh, default state. The next thing is how do you access the network, right?
Ish. Alluded to that all wired ports are blocked, they're colorless ports. We don't have config on those ports because config means I'm a human.
I will make an error, right? It's just a matter of time. Uh, I could have templates.
One small change could really bring the entire network down or could cause a vulnerability. So these ports are colorless. We do not do any config on these ports.
No VLANs, no identity, no trunks, none of that stuff. So how do you authenticate that you have to provide identity, identity for users and devices, both users, it's very straightforward. So they said we do SSO, so we can actually have a docking station connect in there.
Uh, if that device identity is not available, they will get thrown the IDP page, you basically log in, do your MFA, you're on the network at that point, if that user leaves, because we have skim the question on protocols, we support skim integration, you disable the user in your IDP, we get notified right away. We kick you off, right? So that's how Skim and and SSO is integrated into the platform for both wired and wireless.
So you can run open SSO, open SS is great for your personal devices, right? I want Shiv, I wanna know, this is Shiv, I wanna know this is Shivs iPhone, but I don't want him to be in the corporate network. So I create an open ss ID with SSO, so he can log into that device, or on my guest portal, I can have an SSO option as well, right?
So we've made SSO in the cornerstone of, of Nile, right? Because that is the zero trust core principle, right? And the beauty is people today don't revoke certifications on Radius.
Most people don't when you leave the company, but everyone disables, uh, user IDP, right? So that can kick all our devices off, it can kick your corporate device off, it can kick your personal device off the network right away. Same thing goes with Radius, right?
We will integrate with our existing infrastructure to SU's point, we are not saying it's all or nothing, right? With Nile, you can start and integrate with your ice, with your clear path, with your four coats of the world. We will do radius with them.
We will get the ad groups based on ad groups. You know, we can put them on different segments if you choose to do so. Or you can go with Nile Radius and Nile Trusts service and not even have to deal with any of that stuff, right?
So that's all, again, built in every wire port by default. In fact, your default state comes up as parallel one X and Macko, right? So if you are a device that is capable of Radius, you send us an epo, EPO l start, we will start radius with you, right?
If you don't, we'll start to do Macau on the backend, but it's not Macau by itself, it's Macau plus fingerprinting, right? So we make sure that we can onboard a device using fingerprinting. Okay?
That's great. What happens if I get that Costco printer, which is identical to my finance printer? That's where we do device validation as well, where you can give us SNMB credentials, SSH credentials that we can, you know, walk through that device and validate that this is your device.
So that's where we try to make sure that even device is not a second class citizen. Anything and everything we can do to identify that and put that on the right segment and apply the right policy is what that access comes from. And then guest was the same thing, right?
All guest users are isolated. That's the segment of one. It doesn't matter whether you're a guest IOT user, by default, every device is an island.
You could be on the same subnet, different subnets, but logically you could think of them as a slash 32, right? Every device has to basically go through the fabric and has to get authenticated, and then you apply the policy. So if you look at Nile Service guest as a customer, you get a portal where the SSID is already there.
You just have to enter the SID name, put your terms and conditions, choose your authorized, click through access code SMS and hit Safe. What happens in the backend is we give our public IP addresses automatically. We take the traffic, send it to the fabric, fabric, creates a tunnel to the closest Nile pop.
You can apply URL filtering over there and send it to the network, uh, to the internet. So now every single guest user is also isolated and it's a service you don't ever have to worry about dealing with, with, you know, putting anchor controllers, uh, creating an IP SEC tunnel between corporate control anchor controller, running a separate clear pass and ice over here, having your own firewall, internet, all that stuff goes over that complexity just gone. And the beauty is we are not configuring it.
Customers are not configuring it, it is part of the fabric as it comes up, right as you enable those features. So the segment of one is a very important concept because that's where we can isolate every single device, uh, and make sure only based on identity, we, we give them, uh, access. So what is identity?
So we have developed this whole zero trust policy, what we call a micro segmentation or the trust service. It's essentially taking a device and putting it into a group. It is absolutely mandatory that every device falls into a group.
So what is a group? There are three types of groups. The user groups, the device groups, and the apps groups, right?
So the user group is, Hey, you're coming through Skim. I get your skim groups and based on that, I know your sales or marketing and I put you in a sales group or a marketing group. Your choice, you decide, uh, or an employer or an admin.
Uh, you are coming from a device, uh, manufacturer like, uh, a printer or, or an IOT device. You create a security IOT devices, you create your printers, you create a Zoom rooms, and based on identity, they get in there again with device validation, like SSH Telenet or SNMP. com of the world, right?
Or it's gonna be my data center apps. And then you start to create a policy saying user shiv, whether it does skim or Radius, whether he does it on his personal laptop or not, we wanna identify him as a user and put him in a user group. So he'll always land up in, in that user group.
So Shiv will land up in the user group called, you know, uh, employee 'cause I'm an employee even for my personal device. Then I would choose an attribute set Shivs in Intune compliant laptop, because now we get the TLS certificate, we check with Intune, uh, and then I say the data center is my destination, the app group. And I say allow, what that now means is when Shiv connects to the network and he's connecting with his Intune compliant laptop, he has access to data center subnets and the internet.
When Shift connects through his, you know, phone using SSO, he's again in the same user group because he's an employee, but his attributes set does not match Intune compliant. So he only gets internet access, right? So now we are using Identity, but with that we are adding attributes towards Reh said, time of the day, wired or wireless, you know, and it doesn't have to be in tuned, it can be, you know, CrowdStrike, it'll be Sentinel One.
We keep adding all these M-D-M-E-D-R integrations where we can integrate with them and then create that policy, that granular policy. So you said, uh, sorry, Jack Poller with Paradigm Technica, you said that in the guest case, guest traffic goes through, it, gets sent all the way out to your pop. That's correct.
Where then you validate it and then you send it on. So you're effectively man in the middle. Yes.
In the non guest case where you have a validated user and they're going to the internet, are they also going through your pop or they just going straight out To the, that is going straight? So there are two options. Uh, one option is we will send it to the Upstream Edge device and go to the internet directly.
Mm-hmm. Right? The other option is you can create a policy and say, I wanna send all my data center traffic from an employee who's Intune compliance should go through Zscaler.
So you could then send that, uh, from the local site wherever neither is deployed, right? You go have multiple sites, we will find the Locus, local Zscaler in know Palo Alto or Entra Hop and send it over there. And from there it would go there, right?
Okay. So, so, uh, we, we already do, uh, obviously the identity profiling posture, we can do that today with really any infrastructure, with any NAC to some degree complex. It's difficult time consuming, lots of maintenance.
How do you guys make it easier? Right? So if you look at our integrations, right?
I mean, we, we show you some demos from what we have. There's not an overlay system. It's all integrated into one, right?
So when you're onboarding a device, it's tied to the policy itself because we are getting identity from onboarding. So you don't have a hundred places that you go and do it. Uh, it's all in one single ui.
Uh, even the integration within Intune, there are five, six parameters you enter there, you integrate within Intune, right? You go to the policy, you create a user group, you say, I want to do it with, uh, skim integration or within Intune, and you put it in there. So the idea really here is to not have hundreds of clicks.
And we show you some demos where you'll see onboarding devices, even in ClearPass and ice, it's, it's a lot of work, right? With Nile, you can just go and create a fingerprint rule and you're kind of done, right? You add a data validation if you want to do it in part of the policy, and then you make sure that HP printer from your finance team is, is very different from what you bought from Costco.
I guess, I guess my point is, HP Aruba says the same thing about ClearPass profiling posture the assignment, it, it make it sound like it's very easy and it does work. It works well, never quite as easy as it said. So I'm, I'm interested to see how it, how It is.
Yeah. So we can certainly show you, right? And the other big thing that value added you're gonna get here is, let's take fingerprinting for example, right?
How would you do fingerprinting with, with other devices, with the, with other Mac solutions? You wanna set a DCP frame, maybe a radius frame, and that's about it. And that only happens, you know, once in a bloom when it's not happening every minute with Nile fingerprinting, what's happening is we are the fabric.
Everything is going through us. We are seeing MDNS frames, we are seeing user agent data, we are seeing D-H-C-P-D-N-S, right? We're seeing a bunch of frames and we are getting that continuous loop going through.
So for us, when we say zero trust, we're taking some of the core principles of zero trust, right? First is, you know, always authenticate and authorized, continuously authenticate and authorized, which is what we are able to do with both fingerprinting and with, with, with the radius or skim. Uh, and then also just, just in time access, right?
That's where we can create these policies all in one single dashboard, if you will, right? And these are not disparate products. It's not products that we pull together and stack them, right?
It's natively built in. It makes it easier for us to do than, you know, having to board something up. Thank You.
Alright, so SS integration we can do with, uh, do this with vendors. Again, our goal is to not go and reinvent the wheel everywhere, right? Where it makes, where it makes sense to do a full stack solution, we will do a full stack solution, right?
Where it makes sense to integrate with other services, whether they are eds, whether they are SSC integrations, whether it's your skim, uh, sorry, your Sims platform, you know, Splunks of the world, uh, the, the service novels of the world. We will integrate with them and provide you a full ecosystem, uh, uh, that you already have in place. Uh, so we quickly going to, going to go into demos.
These are recorded demos and we'll walk them, walk you through them. Uh, the first demo Jas is gonna walk through. This is about that zero trust network, right?
What are we doing that network layer, what happens when you scan the network, if even if you're a user that connected right now to the Nile network, you have a default gateway. And since it's an L three architecture, we are the default gateway. So what do you see, right?
So that's gonna be demo one, demo two, three, and four is just gonna highlight how do we do the fingerprinting macoff all, uh, in that portal? one x? Uh, and then demo five, uh, just is gonna come back and, and talk about, uh, how do we do the access policy, right?
So you'll see some of the UI elements in there. And, and this is kind of, uh, very, very new. Uh, as we, as we roll this out, odi, Jess, Thanks, sh Hello everyone.
I'm Jess font. I'm one of the solution engineers at Nile. Um, and I'm here to today demo about how the network discovery is going to, we are going to block the network discovery, right?
So let's imagine a common enterprise scenario, right? We have a couple of employees connected to the same SSID and all getting an IP address from the same segment, right? So in a traditional network standpoint, that means that all of them can openly communicate with each other.
That would also expose your network to threats like lateral movement and internal reconnaissance, right? So in this page, you're looking at the Nile Control Center on the device page, and you can see there are four active clients all connected to the same network. Catch me if you scan and all getting an IP address within the same subnet.
So what you don't see here is what you see from an attacker perspective, right? And this page that you're looking at right now, it's the core of our n intelligent access control that we call as trust engine. And by default, you can see that communication between the employees is automatically blocked, right?
No one configured that, that's the default state. So now what that means is, even if all these devices are in the same segment, you have to go in a traditional network, apply layer to acls and like, you know, do your integrations and stuff. But in this case, none of them can talk to each other, right?
So that's what we are gonna demo on the right hand side screen where that's a client and simulate that's, you know, let's say take an example that it's an attacker, right? So what's the first thing that they do when get on the network? They try to like, you know, see what their IP address is, try to reconnaissance their internal network and go from there.
3 in this case with a subnet mask of slash 28, right? So from there, I can initiate a quick NMAP scan on my subnet that I found from my IF config, right? And this can be the same attacker that you just plug into a, uh, wired port on a, uh, device or unplug a camera and plug your device in, right?
3, which has some ports open, which is of course, like, you know, that own host. And you're also seeing the default gateway and even on the default gateway, right? You're not seeing any of the ports being open.
All the ports are completely closed, right? So by doing this way, they're really not able to like, you know, discover any other elements in their network, right? So let's say if an attacker comes in and like, you know, unplugs a camera and plugs his laptop in, even if they get an IP address, they really cannot move anything, right?
So let's imagine they get creative and they're able to like, you know, fish an employee and understand, do a social engineering and understand what the management subnet of the network is, right? In our case, they even cannot. 0 slash 28.
So they go ahead and like, you know, initiate an NMAP scan again on that to see what are all the hosts that are alive. And so that, you know, I can find out and what happens, right? 6, and it only has ports 80 and four foot ERs.
com, right? In this case, this gives the users to like, you know, local ability to troubleshoot themselves and open the tickets with, um, you know, their own internal IT teams. So just as a demo here, like, you know, even in a, where the attackers come in and like, you know, do the internal recon and then find all the devices and do Nmap port scans and all, we block everything by default, right?
This is the power of Nile trust engine, where we automatically come in and apply the policy at a network fabric layer and not just on individual endpoints and right individual acls, right? So in a way where like, you know, we all know that, you know, when the attackers come in, they tend to move very fast, but by our way, Nile makes sure that, you know, the attackers can't move at all in network. And I hand this over to share for the next demos.
I think the key thing about this demo really is that Be before we switch demos, I question for this. So if I'm doing network discovery, yeah, as an adversary, and yet my computer is a Windows domain join computer, maybe I've got a couple applications open, why would the discovery not show the domain controllers and the applications I'm currently actively communicating? If you're A domain join controller and like, you know, that you're connected to, then it would show like, you know, which ports you're connected to and stuff, but in this way we are really ing your whole network in your subnet that you're connected to, right?
Yeah. So we are acting as like, you know, the default gateway. So all the traffic is coming to us.
So that's where we are able to like, you know, filter all those things out. Basically this network, there's no point Yeah, honestly, that I can talk to per employer Endpoint isolation I'm all about, okay? Yeah.
But this demo is all about the, you know, you are on the network, that printer network, right? I unplug the printer, I plug my laptop in. Now what can I, if the policy, the default policy is talk to anyone, right?
Because you right, in that case, what you gonna do is you gonna find scan on that, right? Yeah. That's, that's important.
But yes, your current domain controller, you have access courses, you can certainly pick Okay With the policy you Mike, And then related to that, and if this is a, a future demo, you know, please say so, uh, if I am, all right, so I've got an adversary and my users working away, they fell for a capture attack. Now I got an adversary on my computer, they scan around, you guys are gonna see that, right? Are we able to then take that as a signal and reduce the access to this laptop has, back to this idea of blast radius, a one, No, that we, that is, so that really means knowing the persona of that, that user, right?
That is something we're not doing today. That is on our roadmap for sure. We figured out, hey, this is a user, they should only be marketing person.
They should only be doing these things. Why is this guy in Bitbucket? Right?
Or or why is this guy somewhere else? So that's something we are not doing today, but that is certainly something we want to get to, Right? So even if they do, if they do the scan, you've stopped it, but we don't necessarily have detective capability.
Yes. Yes. Alright.
You talk about default, oh, I'm sorry, go ahead. Go ahead. You talk about default policy.
Yes. How difficult is it to change up that policy? You talk about granularity, right?
Are you gonna show that? Yeah. So we will show you a, a demo, uh, in the last demo, we will talk about those, those details on, on how this will come together.
Uh, the idea really here is that today the default is denied, right? So you go and create your user groups, you create your device groups, data app groups, and then you start to connect them together. That is what we are doing today.
But as ish alluded, our goal is we all know what a printer is, right? We know that these printers talk on these specific ports. If there is an employee, can an employee talk to a printer?
So very quickly, this demo is all about, I connected two devices to the network. They show up as waiting for approval in the dashboard, right? So you just cannot connect and get an IP by default, right?
Even if I unplug that printer port and plug a PC in, we don't care because that port is colorless, it is identity that matters. It's not that it's a printer port anymore. Uh, it's basically now a, a regular port.
So what we are showing here is they don't have an IP address. I can go and basically approve these devices manually and put them on a segment and then move on, right? So segment is a layer three construct as opposed to saying a vlan, you put them on a segment, segment equates to a subnet.
However, that's tedious, right? So I can go and very easily create a, uh, fingerprint and we have thousands and thousands of fingerprints in there. You can be as, uh, high level as you want.
You can say printers and scanners versus HP printers versus HP printer LaserJet 5,400, right? You can go to that level and you can create that as a fingerprint. So now all HP printers can land up in there.
Right? Now, if you wanted to have a policy for a finance HP printer, you can easily do that as well, right? By going to the policy manager and adding some more, uh, you know, information about that, that particular printer.
So we give you that fingerprinting, uh, that you can very easily get your IO OT devices onboarded and add that extra layer of, of, uh, authentication. I wish I had this a month ago, I won't get into it, but we had a customer who had a kiosk that got moved and then we couldn't trace it because there was no way to trace it. And we're trying to work with a wiring vendor or something like that.
Just You would just see it Kiosk and Oh, that's awesome. We would see it, we would see it right there, right? So in this demo, as soon as I approve it, you will get an IP address.
You're on the network, right? And this is the access piece. Uh, the next demo I wanna quickly talk about is do one x.
I literally plugged this laptop in this MacBook over here. And because MacBook has that, if you do the enable one x by default, it just has a popup. It just came right up because it sent an EPL message to us.
We, the EO start and we started the entire transaction. one x approved. So again, no user inter intervention required.
one x, same policy as wireless, right? So we try and make that, uh, common over there. Uh, and the next one Ys is, so I don't wanna start, you know, authorizing your Dell versus your IBM versus, you know, his, his his or her Mac.
So I put this on the docking station. one x. I have a general rule that I call the, you know, the, uh, sorry, is this on the Ys?
Is it running? Is the play button running? Yes, it is.
All I do is I say a pre-op segment, which is a quarantine segment and a post-op segment. So I enable as an admin wide SSO, and that feature is all about, hey, let, let me put someone on the pre-auth or the quarantine segment. What that means is your, your laptop, uh, connection network, we have no fingerprint, no identity.
So we basically put you on the quarantine segment and on the quarantine segment, the only thing you can do is basically get the popup for intra or Okta or Ping ID h you log in, put in your credentials in there, and once you do that in there, we move you to the employee SSO segment, right? And now you are on the employee SO segment and that's how we can monitor all these devices that are on the docking station. You leave the company, we, we kill, uh, kill you from Okta, automatically you get thrown off the network, right?
So you're not on the network anymore. So in this case, I'm using authentic as an IDPI put in my credentials, I'm on the network, very, very seamless right? Now, the the thing to do here is not actually change segments, right?
This is where policy comes into play. You, you can literally put someone on the employee segment, right? Uh, but they don't go anywhere because you're controlling that based on policy.
Only when they authenticate is when they can start going, uh, elsewhere. So there are multiple ways you can make this more and more simpler without having any issues with these experience. Alright?
Just, I'm gonna hand it over to you. Thanks shi. So in this demo, uh, like all the other demos that we saw earlier, we can see that, you know, the devices are not able to talk to each other and you know, the attackers cannot recon or like, you know, map your internal networks, right?
So in this demo, we'll showcase how it's gonna work when like, you know, when you want to make the changes to your, you know, when you want to make changes to like, you know, to that policy to allow specific granular control for that, you know, video streams or printing things to work out, right? So in this case, again, um, I'm gonna like, you know, quickly fuss for a little bit here. 3 and five 13 IP addresses in here.
And by default, as we shown earlier, you know, these two devices cannot even talk to each other, right? So as you can see on the bottom right screen, I'm trying to do a ping ICMP ping to the, uh, device on top, which is five 13, and the ping doesn't even work, right? So in this case, um, We Also started a VLC uh, stream, right?
A video stream, and from the bottom device we'll try to like, you know, fetch that stream and that would not even work, right? So in this case, because again, from going back, the employee to employee communication is blocked, right? So this is where we go into our Nile trust engine, where we go and like, you know, we'll see how easy it is to edit a policy set.
So now I just adding a policy to allow the employees to talk to each other, and that too specifically only to allow the RTP streams, right? So in this case, I'm like, you know, just giving it a source group and a destination group, which is my employee subnet, and I'm just allowing specifically an RTP stream, right? So once I do that, and once this policy is pushed, as you can see, we are not opening the entire hole of like, you know, in your subnet saying that, oh, just let them talk to each other on every port and every device, right?
We are punching a selective path saying that you can only stream, uh, you know, the RTP streams coming to your laptops. So that is where on the bottom right screen, the moment the policy is pushed, you can see that the device is able to fetch, uh, the video stream, right? The best thing out of that is because we just allowed the RTP stream, when we do an ICMP ping again from the bottom device, like, you know, one of these employee laptops, that is still blocked.
So this is how easy it is to like, you know, just create couple of clicks, one or two clicks, and being able to like, you know, uh, punch one specific hole that you want to allow your employees to talk to each other on specific protocols and paths, right? And as you can see, again, like, you know, uh, you are still not able to communicate on ICMP Ping, right?