tgreene
Executive Editor

Juniper’s new switches have a NAC for support

Opinion
Jan 31, 20082 mins

* Juniper's EX switches support UAC and all other versions of NAC

Juniper announced its EX switches this week, and as suspected, they support Juniper’s version of NAC called Unified Access Control (UAC).

The new switches also support anybody else’s version of NAC that requires only an 802.1x-compliant switch to act as an enforcement point. UAC already supported 802.1x switches made by other vendors to act as enforcement points, and now it can return the favor.

In that standard 802.1x capacity, UAC could and still can enforce access control by imposing virtual LAN (VLAN) assignments on the switches. 

Now with the Juniper EX switches, UAC adds some features not formerly available. One of these is Layer 4 policy enforcement. In addition to assigning VLANs based on policies set in Juniper’s UAC policy store called Infranet Controller, the EX switches can enforce policies based on user roles. So the switches could impose access control lists that allow users access to particular resources but not others.

The policy could also assign degrees of QoS to a user so, for example, a guest could be assigned a lower QoS than full-time employees.

The switches can also mirror switch traffic back to a data center via GRE tunnels where an intrusion prevention system could monitor it for suspicious behavior. This enables a type of post-admission NAC that keeps users honest and discovers machines generating malicious traffic because they are infected. (Learn more about IPS products from our Host Intrusion Prevention Systems Buyer’s Guide)

To this end, Juniper says it plans to make its NetScreen Security Manager software into a central policy control platform. Users would set policies centrally and have them distributed throughout the network. This will put UAC in perspective as an element of a coordinated network security deployment.