tgreene
Executive Editor

Nevis NAC gear introduces cloaking

News
Jul 30, 20073 mins

Nevis' NAC application firewalling helps tighten access policies.

Nevis Networks is adding to its NAC gear cloaking – the ability to enforce security policies at Layer 7 by virtue of an application-layer firewall. Cloaking will be introduced to its LANenforcer and Secure Access Switch products.

Nevis Networks has new software that makes it easier for its NAC hardware to block any user on a network from seeing another device, making it possible to prevent rogue equipment or malicious users from accessing resources they shouldn’t or from probing the network for vulnerabilities.

The company calls the capability cloaking, and it is the byproduct of an application-layer firewall that has been added to Nevis’s LANenforcer and Secure Access Switch NAC hardware.

This gives the NAC gear the ability to set access policies based on individual applications. The company says it was possible to get this functionality before but it was complex to configure.

The new software allows tying in policies to existing directory systems such as Active Directory, connecting individual users – not just individual machines – to policies, says Lawrence Orans, an analyst with Gartner. “I think of this as similar to what Verneer and ConSentry do,” he says about two Nevis competitors. “They are all inline, interact with directories for policies and don’t require network changes.”

Another way of looking at cloaking is implementing a per-user or user group, application firewall, says Phil Hochmuth, an analyst with the Yankee Group. “It’s a step beyond carving up the network into VLANs,” he says.

This expands the ability of the equipment to restrict access more tightly than by assigning rights to a VLAN, the company says, and it reduces the number of VLANs needed on a network in order to restrict access according to NAC policies.

So an end user and device could be allowed access to certain resources on a VLAN and not to others. If it tries to reach others, those attempts would be picked off by the Nevis gear on the network. Packets that violate policy are dropped, so the device cannot reach unauthorized resources.

Before, parameters that Nevis gear could use to restrict access to resources included source/destination addresses, IP and MAC addresses and protocols. The new software adds application layer intelligence.

Cloaking can be linked to protocols as well. So all the VoIP phones on a network can be restricted to sending and receiving only those protocols used for VoIP. If a VoIP phone tried to download an FTP file, for example, the request would be blocked.

The software upgrade that adds the application firewall to Nevis gear is available now.