- BlackBerry Storm vs. the iPhone
- Digg's Kevin Rose: "We have to do better"
- Blogger warns: "Nortel doesn't make it out alive"
- Financial quagmire bringing out the scammers
- Verizon plays with the wrong e-mail addresses
Newsletters | Podcasts | Chats | Opinions | RSS Feeds | This Week In Print | IT Careers | Community | Reports | Downloads | Slideshows | New Data Center
Partner Sites:Application Performance Solutions | App Performance | Networking Solution | SafeGuard Enterprise Solution Center | SOA | Test your Web Filter | Value of WDS
Senior Editor Tim Greene clarifies issues surrounding the evolving NAC security architecture.
By the end of the month, Microsoft will release Windows Server 2008 which contains native support for its NAC scheme called network access protection (NAP).
NAP support is already in Vista clients and certain versions of XP clients so now with NAP support in Server 2008, customers will finally have all the elements they need to actually try out NAP - something they’ve not been able to do since Microsoft started talking about NAP in 2004.
The combination of the client and server give Microsoft customers the ability to communicate endpoint security status to the NAP policy server to determine what, if any, network access the client should receive.
With NAP turned on, customers can use 802.1x switches, DHCP servers,VPN gateways, and wireless access points as places to enforce NAP policies. Theoretically, NAP could be implemented with little investment beyond the cost of upgrading to Windows Server 2008.
In a larger view, this is the start of finding out how large Microsoft’s influence will be in NAC. For those who have put off NAC this long and who are upgrading to Server 2008 anyway, it probably makes sense to wait a bit longer and see whether NAP can meet their network access needs.
Some who have already rolled out NAC may find value in plugging some or all of NAPs components into their NAC architecture. Having the NAP policy server as part of the plan or using the NAP client as a health reporting agent may make administrative or financial sense.
In any case, once NAP is available at the end of the month, its pending arrival can no longer be cited as a reason that NAC uptake is delayed. If NAC uptake doesn’t accelerate over the course of this year, it will be for more fundamental reasons that would question whether NAC is as burning a need as its proponents claim.
Tim Greene is senior editor at Network World.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comments (2)
Yes, perhaps another attemptBy Michael Fine on February 21, 2008, 5:45 pmYes, perhaps another attempt by Microsoft at a bundling effort. But, interestingly, it turns out this is likely not to be the case for a couple of reasons. First,...
Reply | Read entire comment
RE: With Windows Server 2008 there's no more NAPpingBy Glen Merrick on February 21, 2008, 10:50 amLooks like another MS bundling attempt. It might even work well, if you live in a Microsoft-centric environment. I bet as soon as you introduce a Mac or a linux...
Reply | Read entire comment
View all comments