* The implications of Microsoft and Cisco's NAC pact
Mike Schutz, group product manager of Security and Access Products at Microsoft has an interesting article up at the Microsoft TechNet Web site headlined: “Microsoft Is Committed to Interoperability with its Network Access Protection Solution.”
The article is about how Microsoft’s NAP (see Microsoft’s NAP Web site for all the details) is being built so that it can interoperate with Cisco’s Network Admission Control (NAC, see Cisco’s Web site) product, as part of what’s now generally called “Network Access Control” (also, confusingly, known as NAC).
This was also a hot topic at the recent Digital ID World conference. But even conference organizer Eric Norlin was a bit mystified going in. He wrote in his blog: “As I’m reading through the confusing acronyms (NAC, NAP, etc) – I’m wondering if it isn’t time for the group of innovative vendors in this space (ForeScout, ConSentry, TNT, Identity Engines, Apere, Caymas, Juniper, etc) to rename their offerings with a more descriptive term: ‘Network Identity Management,’ or ‘N-IdM’.”
Once Norlin had done his research and spoken to the vendors, analysts and customers, he wrote: “Identity-based NAC is a *real* market phenomenon. Customers are learning, companies have products, and analysts are beginning to pay attention.”
Microsoft touts NAP as “…a new platform to perform computer health policy validation, ensure ongoing compliance with health policies, and optionally restrict the access of computers that do not comply with system health requirements until their health state can be corrected. NAP includes a client and server architecture. Administrators can configure [IPSec] Enforcement, IEEE 802.1X Enforcement, [VPN] Enforcement, Dynamic Host Configuration Protocol (DHCP) enforcement, or all four, depending on their network needs.”
What I find extraordinary in all the material Microsoft has published on NAP and NAC (both Cisco’s NAC and the generic NAC) is the extremely limited (i.e., I couldn’t find any) references to Active Directory! But all of this is firmly based on having an up-to-date, schema-extended Active Directory forest as the basis for identifying and tracking all of the hardware that’s either on or attempting to attach to your network.
So read the article I referenced at the top, go through all the material at the NAP Web site, but before trying anything, before installing anything and before evaluating anything remember that it really should be called Identity-based NAC/NAP so your directory infrastructure had better be in good shape.
I did find one reference that offers a test to see if your Active Directory was properly provisioned for NAP, so make sure you check for yourself. NAP/NAC – especially interoperable NAP/NAC – is a great step forward in securing your network and all of its parts. But no matter how magnificent the mansion is building it on a crumbling foundation is a guarantee of failure.




