Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Nevis NAC gear secures insurance company network

Devices restrict consultants and feature other capabilities not yet tapped
By Tim Greene , Network World , 12/06/2007
Newsletter Signup
  • Share/Email
  • Tweet This
  • Comment
  • Print

The chance discovery of a consultant plugging in a laptop on its network led Missouri insurance company GEHA to install NAC as a means for segregating visitors from the corporate LAN.

Since installing Nevis Networks' LANenforcer devices on its network this fall, the company has used it to control unauthorized visitors, but has held off using other features except for monitoring purposes, says Justin Gerharter, systems engineer for the firm.

Eventually, the company will use the gear to scan endpoints to make sure they comply with security posture and to monitor behavior of devices after they are on the network to make sure they behave according to policy.

The company saw a need for NAC in July when it caught an unauthorized user logging in. "One day the guy sitting next to me happened to be going through DHCP scopes and saw an unfamiliar network name associated with an IP address," says Gerharter. "Sure enough, it was a consultant who had plugged a laptop in. That was the incident that drove home the need for [NAC]."

The consultant wasn’t up to mischief, but the incident set off a wave of concern. "The question was raised, how many times has this happened?" Gerharter says.

The desire was to make sure that every machine that got on the network at the very least was authorized to be there, he says. "If they were on, we wanted to make sure we had control over where they could get to," Gerharter says.

The company sought advice on which NAC vendor to use from its resellers and came back with Cisco and Nevis as options. The company tested Nevis gear at a VAR's demonstration site. It tried but could not schedule a test of the Cisco gear, so Gerharter chose Nevis.

He liked that the Nevis device is in-line and plugs into access switches, becoming an enforcement point for the NAC policies. The company has about 25 Cisco access switches that feed into a Cisco core. The company required one LANenforcer 2024 at each site plus a LANsight management platform.

To put the device in place, he unplugged the connections between the access and core switches and plugged them into the LANenforcer instead. The device is set up with port pairs, one port taking the connection from the access switch, one taking the connection to the core switch. “You plug the edge switch into the top port and the core switch into the bottom port of the same port pair,” he says.

  • Share/Email
  • Tweet This
  • Comment
  • Print
Comments (2)
Login
Forgot your account info?

Tim, what gives?By Anonymous8021x on January 7, 2008, 10:36 amTim, You'd think with all the buzz around NAC you'd have had more to write about in the closing weeks of 2007 than some Nevis press releases. Three articles on...

Reply | Read entire comment

Read GEHA's blog on their NAC experienceBy domwilde on December 7, 2007, 7:31 pmwww.bumpinthewire.com

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed