tgreene
Executive Editor

NAC’s dirty little secrets revealed by early adopters

Feature
Nov 14, 20078 mins

NAC Early adopters say the security technology is much more than endpoint scanning

Early network access control adopters are attracted to the technology for very specific reasons that often don’t include the main reason NAC technology was brought about in the first place: endpoint checking.

When it was first defined in 2004, NAC was intended as a means for determining whether the security posture of network endpoints — laptops, desktops, servers — lived up to policies, but many users of NAC buy it for something else.

For example, the Massachusetts Department of Housing and Community Development, which has used Mirage Networks NAC gear since 2005, has about 250 desktops attached to two Extreme Black Diamond 1Gbps switches that are connected by a 10Gbps fiber link. The Mirage box is plugged into a monitoring port on one of the switches where it can see all network traffic, says John Kupchaunis, the department’s director of IT.

The department uses the Mirage device for two reasons, Kupchaunis says. The first is to keep unauthorized users who are allowed into the building from gaining network access, a form of identity-based access control. The second is to make sure devices that are allowed access don’t misbehave once they are on the network.

“I know from personal experience that I can go anywhere [within organizations] with a laptop and plug into a data jack, and I have access to their entire network,” he says. “I don’t want somebody coming into my network and having the keys to the kingdom.” NAC is helping with that goal, he says.

As for ongoing monitoring of device behavior, he wants to track what services desktops run and what activities they engage in. “Are they doing scans of the network? Do people have Web servers, FTP servers running, SMPT servers up and running, instant messaging that I don’t know about?” Kupchaunis asks.

“I’m less concerned about patches and antivirus because I manage the desktops more tightly” he says. “But I don’t want somebody to download some mass-mail virus. This [NAC] device will prevent that because they’re not allowed to have a mailer on their desktop. It will see it, and it will isolate their traffic.”

Baylor College of Medicine in Houston employs Cisco’s NAC appliance, but uses endpoint scanning only as a backup to other tools, says Baylor’s IT project manager Eric Johnson.

The school has a network with more than 20,000 ports and 16,000 devices, so with all those potentially vulnerable open ports, it needed a way to control who gained network access, he says. The campus has also been hit by viruses, so it hoped to check devices for compliance with virus-scanning software policies as well as Windows patches that block repair vulnerabilities. “That’s some of the largest exposure we face,” Johnson says.

School-owned wired desktops are scanned by NAC software agents only once every 28 days because he believes automated updates to security software and operating system patches keep these devices compliant. “Eighty-five percent of the college uses Altiris [systems management software], so we know the machines are compliant before we push the agents,” he says.

Similarly Managed Health Care Associates in Florham Park, N.J., uses Vernier NAC gear not for endpoint compliance of its 125 wired machines, but to authenticate guest users and the laptops of MHC salespeople, says Gregory Thomas, vice president of the firm. THe desktops access ProCurve 1Gbps Ethernet switches that aggregate into a 10Gbps core.

Thomas says customers need to be focused on what NAC does and doesn’t do. Checking whether devices are running security software has some benefits, but having them running doesn’t man the devices are clean. “We like the Vernier equipment and trust it, but we still run antivirus and antispyware,” he says.” “You really need to manage your systems and make sure you get what you need security-wise.”

Thomas says the firm may make further use of the Vernier appliance, but not for endpoint checking. The device can monitor and log network traffic as a way he says can help show compliance with health industry regulations. As the firm does more work that falls under the Health Insurance Portability and Accountability Act, it may use the Vernier gear to block access to certain data and to log who access what resources, he says.

One reason these early adopters avoid endpoint checking is that it can involve distributing an agent, something that can be automated or done as a per-session download, but they prefer avoiding one more application on desktops. . “I think agentless NAC is the only way to go,” Kupchaunis says. “Otherwise you have to go visit all these desktops and install these agents and configure rule sets for all the agents. It seems to me that’s a lot of work.”Even if they don’t mind distributing gents, some early adopters are concerned that the endpoint scan will slow down user login, which is a major concern.

For instance, Dale Badore, the systems administrator for the Rancho California Water District in Temecula, Calif., says he fears a flood of help desk calls if he turns on endpoint checking.

The network consists of 115 workstations spread out among four buildings built on Extreme Networks switches.“I have not even thought about putting it into place yet,” Badore. “There’s a lot of sensitivity to latency any kind of slowness. If a user perceives any type of slowness or difficulty logging on immediately it’s a call to our help desk or a call directly to me. Although there’s no client, personally I’m not sure that endpoint verification wouldn’t slow down the log on process.”

He is moving cautiously, using a ConSentry NAC appliance in monitoring mode for a year as a way to determine what access policies to set. Badoree says he likes that the NAC device can block specific traffic types to and from specific machines. If the device sees suspicious traffic, it can stop it at a particular TCP port. “So the user’s workstation doesn’t have to be shut down,” he says. “They can continue to work. If the malware is working on port 161, we put a rule in place, and it shuts that down.”

In the meantime, he gets value from data on the NAC console about what traffic is actually running on the network. “The amount of information I get just in monitor mode has easily paid for the product already. I know what’s going on all the time,” he says.

The NAC appliance has been a troubleshooting tool that tracked down the cause of a network slowdown. A geographic information system application the water agency uses broadcasts several hundred requests every hour from each participating work station, he says, and he was able to identify it then block the traffic using a NAC policy that shut down port 712 to broadcasts.

But the gear requires initial tuning to avoid misidentifying allowable traffic as malicious. “I have PCAnywhere [remote control] connections from some of my user PCs into their particular server, but [the ConSentry box] determines that it’s malware. I had to declassify that and then it doesn’t show up on my alert screen,” he says.

Kupchaunis says his Mirage appliance learned the network automatically, compiling a list of all devices. He then had to manually classify them so the NAC gear could decide whether to admit them. “You tell it if they are known devices or unknown devices,” he says. Since the initial setup, maintenance on the device has been minimal.

Thomas says he would like to expand his use of Vernier’s NAC, extending it from guests and wireless users to all users, but that would mean an appliance for each access switch, and he is concerned about having to pay for it. “The problem with it is it’s not cheap. We would need two more appliances, and it does get pricey really quickly. We’re evaluating the cost benefit of it,” he says.

Early adopters recommend minimizing the impact NAC has on the user login experience. At Baylor College of Medicine, someone from IT met with each department for about half an hour to describe how NAC would affect them.

They followed up with e-mails when the NAC agent was being deployed by Altiris, describing what the login process would be like when NAC was turned on, he says. He says he sent these e-mails to managers and asked them to forward them to their employees so they would feel invested in the project.

The school used an integrator to help with the deployment, and he suggests that others do the same to avoid potential glitches. “The key is to get someone who’s done it before and understands the impact,” he says.