tgreene
Executive Editor

Network discovery capabilities smooth out NAC deployment

Opinion
Jan 15, 20082 mins

* Cisco and Juniper have embraced Great Bay’s Beacon Endpoint Profiler appliances

Cisco and Juniper have enlisted Great Bay Software to supply network discovery capabilities that smooth out NAC deployment, but the software is proving to have more utilitarian uses.

The NAC vendors have embraced Great Bay’s Beacon Endpoint Profiler appliances to identify and locate all devices and help authenticate those that don’t support 802.1x, which is used by both Cisco and Juniper as well as many other NAC vendors.

Non-802.1x devices such as printers, cameras and IP phones are legitimate on the network, but without some sort of authentication, they might be denied network access. The Profiler can indicate to an 802.1x switch what category of device is trying to gain access and apply the appropriate admission policy to it.

The appliances can also support authentication for guest users that might not participate in 802.1x as well.

The company says its gear also addresses how to authenticate devices that are undergoing PXE reboots as a preliminary to re-imaging them. The gear can gain them network access that limits them to downloads from the imaging server until they can pass regular authentication. Depending on the size of an organization, this can save administrators from hours and hours per week of manually getting these devices on the network.

This time- and money-saving function is useful regardless of whether a network employs NAC, and may help get NAC projects funded. If the Great Bay gear is described to the funding officers in customer companies as a money-saving tool, it may be funded out of the general IT budget. It is then available to use in NAC deployments, but doesn’t affect the bottom line in the NAC account.

It’s something to think about if the Great Bay gear seems needed but money is tight.