- Nokia's new N97 vs. the iPhone
- Talk-powered cell phones?
- FBI: Copper thieves jeopardize U.S. infrastructure
- 10 Microsoft research projects
- Smartphone smackdown: Storm vs. iPhone
Secure networking developer ConSentry Networks has introduced what it calls its Intelligent Switch architecture - in essence, a firmware upgrade which adds application and role-based control within the network.
The ConSentry devices were already able to pull a user's profile out of an identity store such as Microsoft Active Directory, RADIUS or LDAP, and use this to control network and application access, as we reported in our review last year.
What's new, claimed the company's CTO Jeff Prince, is it can now work out who should have access to what and where automatically, based on role data stored in the directory.
"The system now uses roles, and enforces without you having to program ACLs into switches, set up VLANs or anything. The IT manager doesn't have to get involved," he added. "In effect, it writes your business policies to the switch."
He said this means an organization can consolidate its security permissions in one place - the directory - with the ConSentry system automatically binding changes into the network.
This is already working well, said Lou Owayni, global network and telecom manager at Adaptec, which has a Cisco core with ConSentry LANShield edge switches.
"With LANShield, when new users are placed in Active Directory, I can safely and automatically add them to the LAN and implement access controls with a single touch," Owayni added.
Like other flow-based network devices such as WAN accelerators and IPS, the ConSentry switch includes a deep packet inspection (DPI) processor able to identify applications at Layer 7, not just by port number. The system can also tie in with ID management software and handle non-user devices such as printers, Prince said.
He noted that ConSentry does still sell NAC appliances, in particular to companies which aren't ready to refresh their edge switches and want to add security non-disruptively. (Learn more about NAC products from our Network Access Control Buyer's Guide)
He said though that this application and role-based security really belongs within the edge switch, and predicted that other vendors would follow ConSentry's lead over time.
"Cisco with Trustsec has acknowledged the need to bring in user and role data, and so does Juniper's announcement this week," he said.
Juniper already has similar security technology, in its UAC devices, and is about to launch a range of enterprise switching products.
Prince said that the Intelligent Switch firmware is already shipping within ConSentry's 24 and 48-port switches, and will be a free upgrade for switch or controller customers with a support contract.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comments (3)
There is still company doing NAC?!By Anon on July 26, 2008, 3:15 amI am really sorry to hear there are still companies around doing NAC development! Wake up! NAC is the stuff that CSCO invented to push sales of their hardware and...
Reply | Read entire comment
NAC MarketBy Ray Wizbowski on April 5, 2008, 12:31 pmThe last moth has been very interesting, but not surprising. I have been commenting that 2008 would be a shake out year for NAC in which the real market leaders...
Reply | Read entire comment
Too little too late for ConSentry?By Anonymous on April 4, 2008, 2:30 amThe NAC market really has taken a hit recently. With Lockdown closing down, Vernier changing into autonomous something, and ConSentry layoffs in March, are smaller...
Reply | Read entire comment
View all comments