R E L A T E D   C O N T E N T
ADVERTISEMENT

Weak networks need NAC bypass

Confusion reigns due to lack of clear definitions

Martin Courtney, IT Week 09 Mar 2007
ADVERTISEMENT

The majority of current network access control (NAC) solutions fail to address basic security problems, and the proprietary approach adopted by Cisco, Microsoft and the Trusted Computing Group is blocking the development of a certified, interoperable NAC standard.

Ofir Arkin, chief technology officer (CTO) at network security specialist Insightix, says that the lack of a clear definition of what NAC is and does is confusing potential customers, and allowing vendors to tag the NAC label onto a broad range of products that do not merit the description.

Host admission control schemes are designed to protect enterprise networks by allowing or denying network access to PCs, laptops and other devices based on the health and security status of those machines.

The best-known examples are Cisco’s Network Access Control (NAC), Microsoft’s Network Access Protection (NAP), and the TCG’s Trusted Network Connect (TNC), but a host of other software vendors are jumping on the NAC bandwagon, including Symantec and Sygate.

‘Each of the Cisco, Microsoft and TCG initiatives are trying to put more and more companies onto their approach, rather than thinking about how to work out a mutual standard or work together,’ said Arkin.

‘Cisco concluded in 2003 about how NAC should work, but you can call anything a NAC solution – the problem is what it is doing and whether it has the type of components that a NAC solution should have.’

Arkin says most NAC solutions fall at the first hurdle through their inability to keep real time conceptual information about the network, which means that any element is allowed to operate without intervention.

Another problem is that the 802.1x security measures only enforce usernames and passwords for computers, and not printers, IP telephone handsets, cameras or wireless access points, leaving them open to have their MAC addresses discovered and re-used by hackers.

‘Many companies are looking for a silver bullet that does everything in terms of network security and management, but this does not exist. NAC is one important piece of an internal network security infrastructure, but you need to understand its capabilities and its limits, and what it actually provides,’ added Arkin.

See also:

Network specialist Extreme announces upgrades to switch firmware  29 Jan 2007
Security vendor Sophos has bought US network access control specialist Endforce  15 Jan 2007
Unified Access Control network access control from Jupiter integrates Funk Soft tech  13 Nov 2006
Microsoft’s Network Access Protection tools could be removed for being too complex  29 Sep 2006
AEP says the kit can work seamlessly with Cisco, Enterasys, Extreme, HP and 3Com managed network switches  19 Sep 2006
NAC upgrade and two new security appliances provide single sign on and validation of user identities.  17 Jul 2006
SC Safeword SecureWire devices deliver unified threat management  01 May 2006

All Network Infrastructure

Like this story? Spread the news by clicking below:

Post this to Delicious del.icio.us    Post this to Digg Digg this    Post this to reddit reddit!

Permalink for this story

M A R K E T P L A C E
Sponsored links
F E A T U R E D   J O B S
| Aston Carter
Java, J2EE, Developer, Spring, Hibernate, London, city, Graduate. This is an amazing opportunity to join a successful city based team working at the cutting edge of development. My client is looking for strong Java/J2EE developers ... more >
| Aston Carter
E-Commerce, Greenfield, Agile, Java, J2EE, , JavaScript, SQL, London, City Graduate This is an exceptional opportunity for a talented Java, J2EE developer keen to work in a successful development team within arguable the best agile ... more >
| Rullion Computer Personnel Ltd
2nd Line Support Analyst London £35, 000 to £40, 500 My client is a global market leader in the Internet Applications Industry. The company is continually progressing and looking for areas of growth and this ... more >
| Rullion Computer Personnel Ltd
Security Architect / Information Security Specialist – St Albans - Global Leader - Shine At The Highest Level Security Solution Architect / Information Security Architect required by renowned blue-chip organisation offering the finest security projects ... more >
More job opportunities