tgreene
Executive Editor

Taco Bueno taps ConSentry for more than switching

News
Aug 13, 20084 mins

LANShield gear has NAC, aspects of content filtering

When restaurant chain Taco Bueno ran out of access ports it decided to buy ConSentry switches in part because they helped fill security and access control needs that other switches couldn’t.

The company can block access to Web sites with the switches, partially filling the role of content filtering gear that the company would like to use, but for which IT money is too tight, says John Rowe, network administrator for the Farmers Branch, Texas-based restaurants. (Compare access switches.)  

“The content filtering always got knocked off the budget,” he says, despite the fact that department managers complained that some employees accessed the Internet too much or visited sites they shouldn’t.

The two LANShield switches add 100 ports to the network, including uplinks. They enforce access controls for visitors who try to use the network, as well as block access to certain types of applications and traffic. Controlling banned traffic types such as streaming music, streaming video, peer-to-peer and instant messaging has reduced traffic on the on the network by a quarter, Rowe says. “We had policies written up for it but no way to enforce it,” he says.

Taco Bueno’s network has about 300 users divided among headquarters and 165 restaurants that connect via Cisco PIX 800 series routers over DSL or partial T-1 lines to a Cisco 7204 WAN router. About 30 stores have Check Point VPN-1 gateways for tunneling WAN traffic. (Rowe is considering using Check Point gear in all the restaurants. “I’m not sure what we’re going to do,” he says.)

The individual restaurants access the headquarters data center for SQL, DNS and application servers. Sophos antivirus updates are pushed out over the WAN to the remote sites, as are Windows updates via Windows Server Update Services. The central site also pushes updates to the point-of-sales systems in individual restaurants.

Headquarters was served by a three-switch Cisco 3750 core stack with 216 ports that is the backbone of the network, but they were tapped out for access ports, Rowe says. With more users and need for powering VoIP phones, the company had to have more access switch ports.

He considered additional Cisco switches and HP switches, but they didn’t offer significantly expanded features vs. the Cisco switches he already had. “There wasn’t much additional value for what we were looking for,” he says.

The IT department was eyeing content filtering to restrict what Internet sites were reachable as well as network access control, Rowe says. The ConSentry switches he chose don’t do comprehensive content filtering, but they can block access to sites. The switches can block domains per port, URLs, sites that contain certain keywords, he says.

“It’s helped us cut down on bandwidth just through [blocking] streaming music, streaming video, peer-to-peer and IM,” he says. “I know it’s not as granular as a box that just does content filtering, but it gave us an opportunity to upgrade our switch environment plus… be a little bit more secure.”

They use the switches to control guests’ network access, which is one feature the LANShield switches are best known for. (Compare NAC products.)  If someone logging in has no Lightweight Directory Access Protocol match, they are not allowed on without a guest user name and password. Issuing the guest credentials requires an administrator, but Rowe says it’s not often that someone needs them.

When it has the funds, the company would like to replace its Cisco VoIP 7961 phones that have 100Mbps ports. “They’re the bottleneck no matter what,” Rowe says. The ConSentry switches have Gigabit Ethernet ports, so the phones and switches have to negotiate down to fast Ethernet. “That’s another project to upgrade the phones, but we want to have the switch infrastructure in place,” he says.

Taco Bueno has turned on malware protection that comes with the ConSentry switches, scanning for infections before devices are admitted to the network, then monitoring traffic once devices are admitted and taking action to contain malicious outbreaks.

The new switches also give a view of what files are being accessed by users, visibility Rowe didn’t have before. Now he sees whether files are moved or deleted, and logs reveal who moved or altered them. “That’s a benefit we use but might not have looked for,” he says. “It gives us the ability to see things across the network that we never had before and do little things to make the network more efficient without spending a ton of money all at once.”

He is also considering replacing the Cisco 3750 switches for all ConSentry gear, but that is a decision for next year’s budget.