Network World
Thursday, January 8, 2009
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Community

Navigation

True defense in depth...

0

from the internet core, where they dominate, down to the customer edge, firewall, IPS, enterprise core, UAC to access switch where the EX comes into play. Juniper end-to-end. Now that's network nirvana. I see Juniper in a better strategic position attacking the enterprise from above, the internet core where they dominate, than Cisco defending from below. Which reminds me, the local Cisco guys tried to pitch NAC to us and after realizing the enforcement is done by a PC inpath with traffic we nearly fell out of our chairs. That's not an engineered product but a hack job and is akin to building a freeway overpass of standard rebar and concrete but introducing a section made of wood (a disaster waiting to happen). UAC (or NAC in Cisco terms) enforcement is more logical in the access switch using a combination of granular ACL which is lacking on Cisco, QoS for throttling suspicious traffic being examined and VLAN.

Reply

The content of this field is kept private and will not be shown publicly.
  • Allowed HTML tags: <a> <em> <strong> <i> <b> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd> <blockquote> <br /> <br> <p>
  • Lines and paragraphs break automatically.
  • You can use BBCode tags in the text.
  • Web page addresses and e-mail addresses turn into links automatically.

More information about formatting options

CAPTCHA
This question is for testing whether you are a human visitor and to prevent automated spam submissions.

Advertisement: