Skip Links

DNSstuff.com
Get information about your IP
IP Information
50+ On-demand DNS and network tools

Security

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library.  Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Audio

Crackin' the Kraken bot. Listen now!

Network World's Newsmaker of the Week

Wireless dangers at airports. Listen now!

Network World Panorama

Additional Resources

RSS

FEATURED WHITEPAPERS

Enterprise Linux: How Oracle Support Differentiates Itself in a Commodity Market Oracle

Linux has proven itself to be a versatile solution across a variety of hardware architectures to support workloads ranging from basic infrastructure services to enterprise-class database deployments. Today, Linux is commonly found operating in some capacity within most larger organizations, and over time, it has captured many of the same workloads that previously were deployed aboard RISC platforms running Unix operating systems. Read IDC's report on how Oracle support differentiates itself in a commodity market.

RSS

FEATURED REPORTS

Executive Guide: Storage Heats Up HP

Get the latest on storage technologies that allow IT professionals to better cope with new IT demands. Learn how storage technologies can help you successfully tackle e-Discover, regulatory compliance, green data center initiatives and the data explosion. Get all the details now.

RSS

FEATURED WEBCASTS

Discover how to Create an Orchestrated Data Center through Virtualization Novell

IT professionals like the idea of consolidating hundreds of servers into only a few, but it takes a lot more to cost effectively consolidate and virtualize servers. Watch this six-chapter webcast, "Reduce Complexity and Cost - Windows Server Consolidation with Virtualization" to learn how to effectively consolidate your Windows environment. One of the themes explored includes the characteristics of an orchestrated data center, which includes: Resource management, dynamic provisioning, job management, policy management, accounting and auditing and real-time availability. Learn more about orchestration and much more today. Register below to learn more and be entered to win an Archos 605 Portable Media Player.

IT Buyer's Guides

View All Buyer's Guides

Free Newsletters

Sign up and receive the latest news, reviews and trends on your favorite technology topics

Save The Date!
What They Are Saying

We need more like him, people who point our bugs rather than use it agains others. If he can find it,...- Anonymous

Join the Discussion

Linux and Mac OS X need NAC support too

Interop Labs test shows lack of endpoint checking support for users running Linux or Mac OS X
Security: Network Access Control Alert By Tim Greene , Network World , 05/01/2008
Tim Greene
Sign up for this newsletter now!
  • Social Web 
  • Email 
  • Feedback 
  • Close

The Interop Labs test of NAC interoperability showed little participation by vendors that support checking endpoints running Linux and Mac OS X.

This is a continuing problem for businesses that want to deploy NAC but have users whose machines are run by these operating systems. They can make accommodations to whitelist these machines, but that pretty much defeats the purpose of NAC, which is to assure that endpoints first pass health checks and only then gain network access.

Whitelisting them gets them on the network, but abandons the goal of having all network devices in the proper security state, the idea being that if they are compliant with the health policy, they are less likely to bring malware onto the network.

If they can’t find a suitable vendor that can support inspection of Mac OS X and Linux machines, they should look to alternatives that monitor the behavior of all devices and that tosses those that violate behavior policies into quarantine. The example used at Interop Labs is Great Bay Software’s Beacon Profiler, which can determine that a Mac OS X device, or Linux device or even and IP phone behaves like these devices ought to behave.

Of course it’s better to have the NAC system perform the endpoint check in the first place rather than trusting that post-connect monitoring can trigger a timely shutdown of badly behaving machines.

Support of all operating systems used on network endpoints is a feature that potential NAC customers should look for.

Comments (3)
Login
Forgot your account info?

I always find responses likeBy Anonymous on May 2, 2008, 7:15 pmI always find responses like Todd's bizarre. Do you guys only sell to the US or something?

Reply | Read entire comment

And Linux tooBy Michael Fine on May 1, 2008, 10:14 pmYes, Linux is supported too. Avenda Systems has a Linux NAP agent that checks numerous "health attributes" on Linux systems including firewall status and anti-virus...

Reply | Read entire comment

Macintosh yes, Linux maybe notBy toddhooper on May 1, 2008, 5:26 pmTim Interesting point re Mac and Linux deployments. We looked hard at this and talked to customers. Yes, there are a lot of Mac's out there, so we developed a...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to moderator approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.
First Name
Last Name
E-mail
Zip Code