tgreene
Executive Editor

Bradford’s NAC Director gives pipeline firm more control

News
Feb 20, 20094 mins

Enbridge Gas Distribution chooses Bradford Networks' NAC Director to control outside contractors.

Mark MacDonald was looking for NAC because he had trouble controlling outside contractors that need to connect to the Enbridge Gas Distribution corporate network in Ontario, Canada.

“They bring their own devices and a lot of times something on them – a BitTorrent client, malware, a virus,” says MacDonald, the technical services project manager for the Canadian pipeline firm, and that would show up as a switch port sending or receiving an inordinate amount of traffic.

Someone on the IT staff would have to identify the port, figure out where the device was located and track down the user to explain why their connection had been disabled. “It was wasting too much resource time,” he says.

NAC, he knew, could identify which machines belong to guests and could control where they went on the network and shut them off if they behaved badly. He researched as many varieties of NAC as he could and chose Bradford Networks‘ NAC Director.

He says he was leery of inline NAC devices that all network traffic has to pass through because they might create delay and possibly block traffic if they fail. “I looked at the risk of inline devices, and it was too great for my comfort zone,” he says.

MacDonald was equally concerned about software NAC products that rely on endpoints to enforce whether they gain access and how much. The gas-distribution company has mobile field devices with software for checking gas lines that he didn’t want to mess with. “It takes a lot of configuration to get them to work,” he says of the mobile devices. They use both Radia software-deployment and -configuration tools from HP and PointSec encryption from Check Point, both of which might be susceptible to interference from a NAC client.

“If you add something new, it doesn’t like it at all. The guys who work outside do critical stuff and adding another client didn’t seem like a risk to take.”

He narrowed the choices down to Bradford and Nortel, whose switches Enbridge uses in its network. He found nothing wrong with Nortel’s NAC gear, but was concerned about the company’s financial troubles, which have culminated in a recent bankruptcy filing. “I don’t want to be that guy who selected a solution and in two years find we can’t get any support,” MacDonald says.

Enbridge will use the NAC to check that antivirus signatures are updated even though theoretically Radia would take care of updates. But he knows that workers don’t always comply with the requirement that they run the software weekly to get patches and updates.

With the Bradford gear, he envisions issuing warnings if updates are tardy to give users the chance to remediate the problem. On the third failure, it would block access. He says he is still deciding whether to include a check of Microsoft patches on endpoints as part of the NAC compliance process.

As for contractors, Enbridge will force them to use a dissolvable agent via their browsers to check for updated antivirus software and for applications that might clog the guest segment of the corporate network, MacDonald says.

The Bradford gear enforces at Enbridge’s switches, which required upgrading the switch software to a version supported by Bradford, he says.

Another upside of Bradford gear is that it can block a PC that fails compliance without disrupting the IP phone it might share an Ethernet jack with, he says. Other NAC gear he tried forced a phone reboot that could take 5 minutes, he says.

He was concerned about Bradford being a relatively small company that focuses only on NAC, but based on the gear, he’s betting that it will be around for years to support his purchase.