Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
Net/Systems Management /

Security services becomes part of the fabric

Related linksToday's breaking news
Send to a friendFeedback

Sign up to receive this and other networking newsletters in your inbox.

Regular readers of this column will recall two cardinal rules I believe frequently go a long way in determining the success or lack thereof of a new management product. The first rule is that, unless there is a compelling reason to do so, separate standalone boxes that exist solely for the purposes of management are generally to be avoided. Whenever possible, it's always more effective to leverage comparable management functionality that is supported within the network, if such is the case. Support staff training and implementation complexity are often two of the primary reasons.

The second rule is that, whenever possible, new management products should be integrated with the existing transport and management products that are already in place. In this context, the term "integrated" generally means that the new product should be able to perform some subset of useful management functions on the existing boxes and should be able to share some subset of data with products already installed at Command Central.

Recent security announcements from Cisco illustrate that the vendor understands (and often benefits) from these two rules. New enhancements to IOS include intrusion-detection features acquired through last year's purchase of the Wheel Group. Fifty-nine attack signatures from the former Wheel Group's NetRanger ID system have been built into the IOS Firewall, which is supported on 1700, 2600, 3600 and 7200 class routers. Using this approach, the IOS Firewall can then detect hacker attacks directly within the router itself.

This functionality appears to support both the first (i.e. utilize the management functionality that is embedded within the network) and second (ensure that the new management system can effectively integrate with what is already running at Command Central) cardinal rules.

However, one important thing to realize is that, much like the management system itself, security management is made up of a number of separate components. One size definitely does not fit all when data traffic encryption, authentication, access control, accounting and logging are taken into consideration. This clearly applies to both vendors as well as products.

Therefore, while embedded firewall and attack detection support functionality within the network infrastructure makes a great deal of sense for many good reasons, by no means does it constitute the total security picture. Users are well advised to apply the same two cardinal rules to the complete systems and network security picture that they should apply to the network management system.

RELATED LINKS

Renaissance Worldwide, Inc. (www.rens.com) is a leading provider of integrated business and technology. The Network Business Practice of Renaissance Worldwide has a unique advisory service, InvestmentHealth (tm) that enables companies to make complex network investment decisions simple and quantifiable.

More information from Cisco

Hacker group Cult of the Dead Cow tries to convince world its Back Orifice tool is legit
Network World, 07/12/99

Review: eNTrax Security Suite
Network World, 03/22/99

Intrusion-detection tools to stop hackers cold
Network World, 02/15/99

Net Resources: VPNs - primers and more
Network World Fusion

Archive of Network World on Network Systems Management newsletters


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.