* Early adopters of NAC indicate they're not interested in the technology that brought NAC into existence
Recent interviews with some early adopters of NAC indicated they’re not interested in the technology for the endpoint checking that brought NAC into existence.
Instead, they want to get a range of functionalities from NAC gear, as is detailed in this Network World story.
One functionality early adopters want is for NAC to supply a mechanism to admit approved guests to the network and keep off anyone else who might try to log in from a machine they plugged into an open network port. The endpoint scan isn’t relevant; they just want to know that the person and machine have been authorized.
Another key utility is monitoring the behavior of authorized users and machines once they are on the network. They want a way to detect behavior such as probing and bulk e-mail that might be a virus or worm or bot, and shut it down.
These early adapters are less worried about LAN-wired desktops than laptops and other machines that connect by means of wireless or remote access. Locking down the LAN machines and use of patch management software and auto updates for security software makes them secure enough, these users say. One of these NAC adopters says he scans his wired machines just once a month.
The tracking of what machines do on networks is good enough that it can be used to help fulfill some of the requirements of HIPAA, or at least that’s what one of these users thinks.
There’s a lot more detail about these users, the gear they’ve bought and tips for first-time NAC customers in the story.




