Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

Security appliances should not be in-line rather than out of band

Two industry insiders debate the best approach to NAC
Face-off By Grant Hartine, Mirage Networks , Network World , 01/29/2007
  • Share/Email
  • Tweet This
  • Comment
  • Print
Grant Hartline, Mirage Networks

Regardless of a network access-control solution's features, maintaining an operational network infrastructure should be its main priority. Out-of-band solutions offer the best way to take advantage of NAC's superior network protection without compromising network uptime.

Whether for policy enforcement, quarantine, compliance or visibility, every NAC solution depends upon a pervasive network deployment. Deploying in-line devices throughout a network infrastructure is an unavoidable outage event, requiring a scheduled window of downtime. Even a temporary evaluation of an in-line NAC solution requires a burdensome change-control process across all involved departments.


Face-off:Security appliances should be in-line rather than out of band

By contrast, out-of-band solutions are flexible in their implementation and can be deployed quickly in the middle of a workday, without the risk of interrupting critical business operations. In short, out-of-band NAC solutions provide network protection, with no single point of failure and minimal risk to the operational status of the network.

The potential risks and costs of a spike in network load are much higher with in-line solutions, because they must act as a pass-through for critical network-control packets. These spikes can be caused by attack propagation, the introduction of a new network application or an increase in normal traffic flow. Out-of-band solutions are not in the path of control packets and frames, thus eliminating any potential for network failure under times of high load.

Networks that provide real-time applications such as voice, video and status monitoring demand consistent, reliable network performance. Placing in-line solutions into these environments requires an additional point of latency and the potential for jitter injection. Out-of-band solutions protect real-time environments without injecting any latency or jitter that would impact user experience in these segments.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Comments (5)
Login
Forgot your account info?

Face-off: NACBy Inbox on January 28, 2007, 5:51 pmWhat do you think about the best way to do NAC? Read Jeff Prince on in-line solutions and Grant Hartine on out-of-band answers and jump in with your thoughts.

Reply | Read entire comment

inline vs out of bandBy Anonymous on January 29, 2007, 1:50 pmIf inline methods could provide the same availability and performance as network switches today, there would be no reason to do this out-of-band. The only reason...

Reply | Read entire comment

In-line vs. OOB isn't aboutBy Anonymous on January 29, 2007, 4:30 pmIn-line vs. OOB isn't about in-line products being immature. This is about being able to actually deploy a solution without business disruptions. Regardless of...

Reply | Read entire comment

It's All About The ServiceBy Anonymous on January 30, 2007, 11:00 pmIt doesn't matter if it's in-line or out-of-band. When I select any vendor I challenge their dedication to solving my problems. I don't care about who has the...

Reply | Read entire comment

NAC Appliances vs. FirewallsBy Anonymous on February 4, 2007, 11:24 amExcellent discussion points from both of them. However, Mr. Prince's comment that the devices should be in-line just as firewalls are is a little off the mark....

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed