Network World
Friday, November 27, 2009
DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Momentum building for identity management

Identity-management technologies are beginning to weave together the application and network layers of corporate networks, significantly improving access control, easing management burdens and helping users meet stringent compliance and security mandates.

Sony Bravia 46-Inch HDTV
11/27/09
Wal-Mart has a 46-inch HDTV, the Sony Bravia KDL-46S504, on sale for $798. This 1080p HDTV features a 60Hz refresh rate and a 20,000:1 contrast ratio. It also has three HDMI inputs, and is Bravia Link compatible. The lowest price we found for the KDL-46S504 on PriceGrabber was $1200 at Crutchfield, so you'd save about $400

Get Real Business Results From Social Media
11/27/09
Can you tell which of the following tweets is from a small but rapidly growing company?

Acer Aspire AS5517-1208 Laptop
11/27/09
RadioShack is offering the 15.6-inch Acer Aspire AS5517-1208 laptop for $400. This Aspire laptop features an AMD Athlon 64 Dual Core processor, 4GB of RAM, and a 320GB hard drive, and it runs Windows 7. It's currently selling on the RadioShack Website for about $550, so the deal is a good $150 off

The tools of this emerging trend will be on display this week at the annual Digital ID World conference in Santa Clara, where vendors such as Apere, Applied Identity, Caymas, ConSentry Networks, Identity Engines and Trusted Network Technologies (TNT) will display their network access control (NAC) gear. NAC relies on identity to determine which machines get on the network - and more important, what users are authorized to do once there.

While NAC is gaining momentum, users and analysts say the unification of the network and application layers via identity is a missing link to reducing risk in a compliance-driven world where access is expected from anywhere and network perimeters are disappearing.

Click to see: Identity and the network

Identity and the network
A number of network access-control vendors slated to appear at this week's Digital ID World conference are adopting identity technology to help improve network and data security by integrating the network layer and the application layer.
Vendor Product Comment
Apere Identity Managed Access Gateway Combines provisioning tools with access control.
Applied Identity Identiforce Identity-based network access management.
Caymas Identity-Driven Access Gateway Network access control and SSL VPN in one box.
ConSentry Networks LANShield Controller Enforcement of user-based access controls.
Identity Engines Ignition Designed to replace RADIUS servers.
Trusted Network Technologies Identity Driver; I-Manager; I-Gateway Trio of products marries user data and policies.

"It is becoming more important to know who is on the other end of the wire," says Jon Oltsik, senior analyst for information security at the Enterprise Strategy Group. "Security, compliance and global business initiatives are going to drive these two [layers] together."

To underscore this emergence of sophisticated NAC options, Cisco and Microsoft last week at the Security Standard conference introduced a white paper detailing how users can integrate Cisco's Network Admission Control and Microsoft's Network Access Protection (NAP) technologies. The companies said they would support each other's protocols, but stuck to their previous statements that they would develop their own NAC frameworks while providing methods for users to integrate the two.

They said interoperability would hinge in part on a single agent that will ship with Vista and Longhorn Server, and that will work on the Cisco and Microsoft platforms and can be used by third parties to tie their systems into the architecture. Cisco will continue to develop its Trust Agent to support non-Microsoft platforms.

The companies plan to begin a beta test with a limited number of users by year-end, but the entire architecture won't be available until Microsoft's Longhorn Server ships in late 2007.

By contrast, Caymas, ConSentry, TNT and others are shipping hardware and software that goes beyond validating that a machine is current on patches and antivirus and spyware signatures - which are the pre-admission to the network checks Cisco and MS initially are focused on - into postadmission controls that use identity and policies stored at the application layer to govern how the network looks and reacts to a particular user.