Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Juniper embraces 802.1X to control network access

New software makes switches enforcement points in security architecture.
By Tim Greene , Network World , 11/13/2006
  • Share/Email
  • Comment
  • Print

An upgrade to Juniper Networks' network access-control software makes it possible for customers to block network access via any switch, not just by Juniper firewalls.

When Juniper's Unified Access Control (UAC) 2.0 is released next month, it will support 802.1X port-level authentication, which can restrict what devices gain access to a network before they are assigned IP addresses. This 802.1X support puts Juniper on footing with Cisco and other vendors whose NAC schemes call for enforcement of access policies on all access switches. Juniper launched its UAC architecture using its firewalls as enforcement points with the intent of adding 802.1X later.

UAC 2.0 machines with profiles that fail security scans can be locked out of the network or quarantined on a designated virtual LAN, says John Oltsik, an analyst with Enterprise Strategy Group. UAC 2.0 still supports its existing enforcement mode of restricting access via Juniper firewalls.

UAC, Juniper's architecture for access control, is compliant with an alternate, open-standard scheme called Trusted Network Connect promoted by Trusted Computing Group and works with any 802.1X switch. UAC competes with Cisco's Network Admission Control, which supports enforcement by its own 802.1X switches.

Juniper also is a partner with Microsoft, so its Network Access Protection software can fit into the UAC architecture.

The new Juniper 802.1X features come via technology Juniper acquired when it bought Funk Software last year. In particular, Juniper is adding client software called an 802.1X supplicant, which can be downloaded to machines as they seek authorization to join the network. The supplicant, sold as Odyssey Access Client by Funk, lets 802.1X switches enforce what switch-level access the supplicant machine will get.

Juniper also is adding a stripped-down version of Juniper's Steel-Belted Radius authentication, authorization and auditing software to its Infranet Controller device. Infranet Controller stores access policies and delivers them to the enforcement points. It also authenticates users and can push the 802.1X supplicants and endpoint scanning software to machines logging in.

With a RADIUS server onboard, Infranet Controllers don't need to access a separate RADIUS server, says Rob Whitelely, an analyst with Forrester Research. While most large businesses may have more than one RADIUS server, many are under control of remote access administrators, not security administrators, he says, so having the software integrated can reduce deployment headaches.

  • Share/Email
  • Comment
  • Print
Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.

Download the white paper.

Applications: taking back control

Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.

Learn more today.

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed