With NAC, small vendors rule, expert says

Feature
Aug 28, 200729 mins

In this Network World Chat transcript, security guru Joel Snyder reveals the truth about NAC, including which vendors to watch.

In this Network World Chat, security guru Joel Snyder reveals the truth about Network Access Control technology. Smaller vendors rule and TCG/TNC, which now includes Microsoft’s NAP, is the camp to watch, even without Cisco.

Moderator-Julie

Welcome to Network World Chats. Our guest today is security guru Joel Snyder who is going to reveal “The Truth about NAC.” Joel will answer your questions about NAC, security, or anything else on your mind.

joel_snyder

Heya folks! Welcome to NAC-land.

arp

Can the NAC solution be deployed with a wireless access point from one vendor and a RADIUS server from another vendor? Or is it an end-to-end solution? Thanks.

joel_snyder

Definitely you shouldn’t be locked into a single vendor. Of course, this is going to depend on the choice of NAC solution, but in our test lab we use Aruba and Airespace (cough cough) Cisco wireless stuff, and have great success with other policy decision point vendors, including Microsoft and Juniper. I don’t see a huge requirement to get it all from a single vendor, and, in fact, with the exception of Cisco, I don’t think that any NAC vendor really covers both wireless and the PDP (RADIUS) side. So multi-vendor is very much a reality. You’re not from Cisco, are you? 🙂

Moderator-Julie

PRE-SUBMITTED QUESTION: What’s the biggest shortcoming you see with NAC implementations?

joel_snyderif you look at Mandy’s test a few weeks ago, you’ll see that she got really different products with really different designs. This makes it hard to know what’s right for you.

That’s hard to say. I think that the lack of standardization of NAC approaches and strategies is really holding us back. We want to have different products for different requirements, but NAC products are so different across the board that it makes it difficult for people to know what will solve their needs. You have to be a product evaluation guru just to understand some of the subtle differences between these products. I think that this will shake out over time, but

amiller219

What is the biggest barrier to implementation in your opinion, e.g. price, complexity, infrastructure changes, etc.?

joel_snyder

Organizational. NAC requires three teams to play ball together: the desktop folks, the security folks, and the network folks. If they can’t all agree on what they want to do and why, it’s destined to fail. Deal with the politics, and all other problems become trivial.

Grumpynettech

What do you see as good aspects of NAC from a wireless client (.1x), wireless (general user), verses wired access and also for guest and / or vendor? What remediation / inspection should we be able to perform or expect to be able to perform?

joel_snyder

Well, it all depends (I hate it when people say that). I think that NAC for the “local” user (someone in your domain, like your employees) should be doing a lot of self-remediation–not just throwing a pop-up box. For guest users, I don’t see NAC as having a lot of remediation capabilities. Are you really expecting people to download random software and install it just to read their e-mail? I guess some do, but generally I think of NAC/guest as being remediation-free and focus on partitioning users and protecting things.

JMS-Maine

Joel, what are your thoughts about in-band versus out-of-band NAC solutions (pro’s/con’s each way)? Softball, but what the heck…

joel_snyder

I’ll have to throw a definition here, and see if you agree: in-band I think of as a box, like maybe a Vernier / Consentry / Nevis or even Cisco CCA (in in-line mode, which is one option), which controls all access. Out-of-band is what I like to call “edge enforcement,” more 802.1X-y. Hybrid is more half-way, like Lockd Down or CCA in that mode. Anyway, given those definitions: edge is really where I think we want to go for big enterprise deployments. It scales, it handles the load, and it doesn’t depend on a single point to do enforcement. In-band I think of more for the occasional guest access — drop one of those boxes in between your guests and let it handle that load.  BAM, problem solved, that was easy, etc.  Of course, that doesn’t mean that the in-band guys can’t handle the load, but you really want to aim for edge enforcement if it fits, and go for in-band if it doesn’t. And there are zillions of places where in-band fits better.

RRR

But isn’t the scaling excuse just another way of saying that the current NAC technology will just be replaced in a couple of years by in-band appliances?

joel_snyder

Hmmm. It depends on your definition of “in-band appliances.” I think that firewall-to-the-port is what will happen in a couple of years, where a “couple” is probably more like a decade. How long will it take for that kind of brainpower and speed to move to the switch port? Hard to say, but certainly that’s what I would like to see it happen.

Jeff_Caruso

Should users hold off on implementing any particular NAC until the vendors sort it all out?

joel_snyder

Of course not. You need to buy, buy, buy, so those poor guys can keep up payments on their Boxters. No, seriously, though, you can solve a lot of point problems with current solutions today and look to the future for better solutions with wider scope. I see a lot of people with “pain points” that need solutions — they should be going for something today. And, a little experience today will help you pick the right solution tomorrow. Should you buy a NAC solution for 50,000 enterprise users on a Windows domain in 30 buildings? Well, I’d do a test rollout for a while first if I were you.

taco2

Joel, what do you see as the challenges with Cisco’s NAC Appliance?

joel_snyderMandy dissected it (here too) and Cisco got all pissed off in her test on NWW, but honestly I don’t have a strong opinion about it. It’s been a long time since I had it in my lab, and I don’t like to offer opinions until I’ve got the boxes under my belt.

Honestly, I can’t answer that one very well because I haven’t had it in my lab.

ServerGuy42

Hi Joel – I’m studying for my CCNA and also want to move into wireless and NAC. What steps should I take to get more knowledge about this topic?

joel_snyder

Well, 802.1X is something you really need to understand. I would make sure I really “got that” to know NAC and the pros/cons of that approach (and there are both!). I’d also config up 802.1X on a switch and do some testing to be sure you know what’s easy and what’s hard — there’s a WHOLE PILE OF FUD about that.

Gleb

Hi Joel, The top two solutions from the recent Network World NAC test (Symantec and ForeScout) use two fundamentally different approaches to NAC – client vs. clientless. What are your thoughts on the client vs. clientless debate?

joel_snyder

My thinking is that there are lots of reasons people use NAC, and they may find that client-full versus client-less meets their needs. Honestly, if you’re doing NAC for employees, you want a client. If you’re doing it for guests, you want clientless. And if you want a solution that solves both, then you need a solution that has both. The SSL VPN guys figured it out; the NAC guys will too (sooner or later).

kevsull NAP and TCG come to mind.

On standards, what is your opinion on these so-called consortiums that propose to be about standards, but on a closer look you can tell they are vendor-led and self-serving.

joel_snyder

Your question reveals a certain bias, but, even with that, I think that standards are totally key. Without a good set of standards, this is a technology that will fail miserably. Think PKI and, to some extent, IPsec VPN for remote access. Too much squabbling among the vendors, and too little “put aside our differences and move forward.” I think that TCG/TNC is the one to watch; Microsoft (NAP) has joined in and is on the bus. The only one who is lagging behind TCG/TNC right now is Cisco and that’s largely a personality difference as far as I can tell.

nacnac

System scanning – if one of the major problems is ineffectiveness of A/V [anti-virus], OS patching, etc. – why all the hubbub about verifying that those things are in place? I get the mitigating risk argument, but ultimately you’re verifying tools are there that don’t solve the problem, no?

joel_snyder

Well, it’s a question of dropping reducing risk. I agree totally that knowing that A/V is in place says nothing about whether you’re infected or not. In fact, most people don’t get that and I’m glad that you did. But the answer is that if you have A/V at least the ODDS of you being infected are lower than if you don’t. So while compliance to policy is just compliance to policy, the idea is that if you’re not a total moron when you wrote the policy, the policy does actually reduce risk. Remember we can never go to zero.

FrostBe

We have a lot of contractors and we’re trying to limit their access to certain parts of the server, can NAC do that?

joel_snyder

NAC and contractors is hard. You have this situation where you want to put a lot of software on their systems, and they may not be into that. I think that you CAN find good NAC solutions that will work — you want to look for products that are more “enforcement-y” than “posture-y.” Good candidates are the in-line guys I mentioned before, and of course Juniper, which is all over that.

dougdooley

What’s your opinion of Microsoft’s willingness to partner in the NAC space? They seem to be friendly with everyone – joint demos with Juniper’s UAC, road shows with Cisco’s John Chambers? Is this a sign of desperation or doing the right thing by customer or both/neither?

joel_snyder

Doolster! MS is on the right side of the fence. Either that, or they are lying through their teeth, and I believe that they are honest. I have had some great conversations with them and some brilliant folks and I think that they are doing the right thing. Look, honestly, no ONE wants to write PC software, at least not in the network security business. Why should we be doing that when MS is offering to do that for us. Partner, rather than perish.

RRR

What’s your vision of NAC products 5 years from now?

joel_snyder

Universal “ho-hum.” Just like VPN. We all have it where we need it and it’s not so exciting. That’s what we want. Universal dullness. We have to go to Funky Town, and then move to Dullsville. That’s a good sign.

RRR

Re Gleb’s question – what do you think about post-admission as a solution for clientless NAC (also for employees)?

joel_snyder

Post-admission pisses me off. To me post-admission is an admission that your product doesn’t do what it needs. NAC is NAC. You want pre-admission, post-admission, and post-graduate. All in one product. ALL are needed for the 5-years-from-now NAC solution.

cd

Isn’t the IETF developing standards that are vendor neutral? Where all the vendors contribute?

joel_snyder

IETF is, but it’s a bit of a fiasco. I invite you to read the NEA minutes. There are a lot of egos involved. I love the IETF for what it was, but I believe that its effectiveness as a standards development organization has dropped precipitously in recent years. I would love to see IETF do it, and there are a bunch of smart folks there who are participating, but they are being dragged down by the “everyone has a voice, even if they shouldn’t talk so much” crowd. My money’s on the TCG/TNC, at least this year. I would love to be proven wrong, though.

Moderator-Keith

PRE-SUBMITTED QUESTION: Any open-source NAC projects out there that are interesting?

joel_snyderTim Greene wrote a great article a few months ago about open-source NAC that really covered the market and projects well. It’s one of the best unbiased discussions of the available options. The only project that I’ve heard of that Tim missed in that article was FirePipes.

Lots of action on this front, some of it stretching the imagination a bit. The Open1X people (now the main driver of OpenSEA, Secure Edge Access) are primarily interesting to Linux clients, based on the Xsupplicant work that Chris Hessing has been leading lately. That’s incredibly cool, except of course that the penetration of Linux desktops and laptops into the world is basically zip today. But the work that they’re doing has huge relevance in the Mac world, where Apple has left the enterprise high-and-dry, and will help in embedded devices, most of which are based on Linux nowadays. Those guys are scary smart and worth watching.

ServerGuy42

What are your thoughts about putting NAC on endpoints like printers, PDAs, etc.?

joel_snyder

You absolutely have to have some way of dealing with these guys; it’s the corner case that is a killer in NAC. People don’t think about it very much, but any NAC solution (at least for enterprise users) that doesn’t adequately deal with “stupid clients” (printers, PDAs, smart phones, cameras with Wi-Fi, etc.) is leaving a huge security hole. Of course, it all depends on why you’re doing NAC in the first place — maybe printers aren’t part of the picture if you’re focusing on guests, for example.

Moderator-Keith

PRE-SUBMITTED QUESTION: When it comes to NAC, product performance isn’t the only reason to choose a vendor. What other factors should I be considering before I buy?

joel_snyder

In fact, performance is generally not critical for NAC products unless you’re doing in-line enforcement. The Consentry / Nevis / Vernier clan have to keep their numbers up, but folks like Cisco that are doing edge enforcement or hybrid enforcement just have to be sure their policy engines are fast enough, which is way easier. To me, the main issue in deciding on the right NAC solution is figuring out why you’re doing NAC in the first place. You do that, then the right product will begin to reveal itself. I’ve written a little presentation I did as part of NAC Day at Interop where I give 9 “hard questions” on NAC. I know you’re asking “give me some purchase criteria” here, but my answer has to be “find the product that meets your needs.” Most people are so confused by the NAC buzz-wagon that they have no idea what they want or why they want it. Except that everyone is talking about it, so maybe they should have one. It’s like a blog 🙂

Dotondo

What are the best practices for Fortune 50?  What vendor should they be picking?

joel_snyder

Well, that’s a tough one. You know that there are no Fortune 50s who have done full NAC or if they have, then I haven’t heard about it yet. Best Practice comes out of years of experience and hundreds of deployments. I think that some points you need to think about, though, are the following: (a) you MUST have vendor independence. Without that, you’re destined to hate your solution (b) you must have a solution that can scale up properly and that takes a LOT of thinking about stuff, and most NAC vendors haven’t done that yet (c) you must think through why you want to do NAC. It’s not just a question of “Fortune 50 have NAC,” anymore than “Fortune 50 have dynamic routing.” Yeah, they all do or will in any case, but NAC is more of a technology that supports your business goals and security restrictions than a “must have because everyone in our club does.”

nacnac

I believe NAC has a real place in the security spectrum but have trouble building an ROI that gets it prioritized above other projects. Any advice for building a business case for NAC? “Reducing risk” is hard to quantify, which translates to “hard for me to get budget.”

joel_snyder

You hit the nail on the head. NAC ROI is way harder than most everything to budget. You can always use the FUD approach (have the purchase requisition ready, and run into the CEO’s office next time TJX is on the front page of the WSJ). OK, just kidding. No special advice other than the obvious stuff you’ve already thought off. This is one of the reasons, by the way, why NAC may not make it in the long run.

Moderator-Keith

PRE-SUBMITTED QUESTION: Do mobile phones need to be included in a NAC scheme? How would I do that?

joel_snyder

It depends: are your mobile phones on your network? If the answer is “yes,” then there are a couple of strategies. (If the answer is “no,” then howdy from the 21st century, come join us all soon) First of all, you’re probably not as worried about end-point security posture, because the access you’re going to give to the phone is limited: probably basic groupware functions (email, calendar, etc.) and maybe intranet browsing. Because of that, you want to focus on access control, probably by creating a VLAN just for these phones that strictly limits where they can go, and figure that if you handle access control properly, then end-point posture checking is probably not as important.

SuperStar Bradford surviving with the big boys???

How do you see

joel_snyder

Absolutely. Bradford has a number of the big boys VERY frightened. Plus, they have their niche (edu) which they serve beautifully and everyone in that niche seems to love them. The greatest threat to their survival would be if they were to get bought, especially by CA or Symantec.

taco2

If NAC is “ho-hum” in 5 years, what in security is exciting in 5 years?

joel_snyder

Dude. I’m going to be running a BBQ stand in 5 years. You call me up and tell me.

big_boy

I’m curious about your position on 802.1x vs. the proprietary NAC solutions out there … keeping in mind it’s like apples-to-oranges.

joel_snyder

I’m an 802.1X purist. Actually, I like to use the “switch when you can, route when you have to” analogy. I think that 802.1X is definitely the way to go, but obviously there are places where it doesn’t work, and that’s when I turn to proprietary. So I start with 802.1X as my “starting point” for any design, and then back off if it won’t work. I know that my buds at Nevis are going to get mad for me saying that, but that’s just the way I think.

Moderator-Keith

PRE-SUBMITTED QUESTION: Can NAC do anything to help protect sensitive information from leaving the premises?

joel_snyder

Conceptually, yes, but practically, no. You really need specific technology to handle that; we’ve got a good market already called “leak protection” that’s handling this. Again, NAC can be helpful in some ways by providing authentication information to the leak protection device, but these guys have their act together and I don’t think that you want to start tying NAC to leak protection at this stage of the game. Wait until the next inning, OK?

Seabee2000

Do you believe scanning of clients before network access is too time-consuming or is it worth it? I can only assume you thinks its a good idea if all parties are for it, Network, Security, etc.

joel_snyder

If it’s done right, it shouldn’t take too long. For example, let’s say you’ve got a good patch discipline program in place, like a Patchlink or BigFix. Those guys know the instant you connect whether you’re good or bad. So it’s not like you’re waiting for 45 minutes for a sector-by-sector scan of the hard drive. I totally agree that anything over maybe 15 to 30 seconds is a show-stopper, at least for the ADD Internet generation nowadays.

AAsDC IPS and true clientless NAC? i.e. if I theoretically had a gateway IPS that could interface with an auth directory and could monitor all protocols, doesn’t that achieve the same goal as NAC without all the mess?

Joel, where do you draw the line between extremely thorough application-layer

joel_snyder

Well, yes and no. I can’t agree that it’s “without all the mess.” There’s a lot of mess behind every IPS deployment I’ve ever seen. However, I think that the architecture you propose is basically what I think of as the end-game, except it’s not an IPS; it’s a combo IPS/firewall at the port level where the user connects. So we’re on the same page, except that you’re missing the posture assessment part. Can’t do that without a client, and if you want it (maybe you’re collecting stats for your compliance audit), you have to get it somehow.

Gleb Bradford question, what do you think of similar sized players like ForeScout and Lockdown being in the top 5 solutions in the NWW test?

Following up on the

joel_snyder

You’re referring to the scorecard when you say “top 5,” and I hate scorecards. However, I think that there is a lot of innovation going on in the NAC space and I don’t have any problem with good products coming from small companies. They spur the big guys on to do better, and may have great ideas that are worth stealing … or acquiring 🙂

Moderator-Keith

PRE-SUBMITTED QUESTION: How are NAC hardware and other security appliances working together?

joel_snyder

This is one of the most interesting parts of NAC, the idea that you can get all your security awareness devices like IDS/IPS and SIM and NAC talking to each other. The NAC stuff can tell everyone who the user at a particular IP really is, which is incredibly valuable information that’s also incredibly difficult to gather. And the IPS/IDS/SIM/firewall can give NAC information about how the user is actually behaving, which can be used to modify access. I hear a lot of talk, especially from the startups, about doing this kind of stuff, which is great. That’s going to put pressure on the big guys to incorporate those ideas, either by development or acquisition. For example, it’s no big secret that Juniper’s in the market for a SEM/SIM vendor. Why? Not for the revenue, at least not to start. It’s because they see NAC and security as needing that kind of integration to build the big picture. Or at least that’s my guess.

rain

Speaking of 802.1X, are there vendors who can offer out-of-band NAC without going through the .1X route?

joel_snyder

Lots. I call those the “hybrid” guys. There are huge drawbacks, but still some people like that approach better. The big guys in that game are probably Lockdown; they have a huge press presence. But even Cisco does that — think CCA! It’s not that unusual of an approach and solves some problems that linger around 802.1X deployments today.

Moderator-Keith

PRE-SUBMITTED QUESTION: How are NAC schemes and other identity management schemes merging?

joel_snyder

There are some wild-eyed crazies that have the vision that once you authenticate, you’re done for the day: those credentials get carried into the local system, the network, and up to every application in the enterprise. Never tell anyone who you are again, and everyone knows who you are and what you should have access to. I’d love that and so would every end user. Will it happen? Hard to say. People haven’t been successful with SSO in the past, but the growing monoculture in the enterprise plus Microsoft’s interest in NAC suggest that we’re going to have more parts that fit together than we ever have before. To me, the biggest problem is that it’s way too cross-functional and the organizational barriers are almost as significant as the technical ones. But if you want to be buzzword compliant, make sure your NAC has SOAP/SAML hooks, or at least they’re floating around on the PowerPoint somewhere.

Wiz

There is a lot of talk about blocking vulnerable end points, but it has been my experience that it is more important to block threats and find some remediation capabilities for the identified vulnerabilities. What is the best approach to blocking threats while still addressing the vulnerable systems?

joel_snyder

Hard one to answer when you use the word “best.” I think that one important part of a good NAC deployment is the ability to turn the IPS up to 11 and block these things. The reality of most “bad behavior” is that it shows up pretty easily.

Moderator-Keith

Nigel Tufnel: We’ve got Armadillos in our trousers. It’s really quite frightening.

joel_snyder

Spinal Tap. Keith is the man!

RRR

What are your thoughts on NAC in the branch?

joel_snyder

That’s hard. No one has come up with a great solution, because things like VLAN separation are very hard. I think that you’re going to end up backhauling the traffic and using a stateful firewall before you emit it to the core network; that’s the only affordable way to do it today as far as I know. Obviously, you can go with a Forescout-y kind of thing in the branch, but the price is not quite right. I’d say Cisco ISR is one place to look for innovation there.

Moderator-Keith

PRE-SUBMITTED QUESTION: What about authentication and mobile phones?

joel_snyder

Mobile phones aren’t so good, and more importantly mobile phone subscribers aren’t so good with authentication. If you make someone punch in a password to their phone every time they want to hit the network, you’re going to end up pushing that traffic to the public network, which will end up increasing costs and opening up other security holes. In the future, you’ll be able to do some sort of SIM-based authentication — there’s an EAP method for that — but for now, you should probably focus on MAC-based authentication to give the user the best experience, and handle access control behind the scenes.

corao IPS deployment that is still deploying in IDS mode as the false positives and issues for blocking are turned off – now they are asking me to try the NAC features, should I ?

I have an

joel_snyder

No, you need to get the IDS fixed first. If you are still seeing FPs in your IPS, you’ve got some serious issues where the vendor needs to get their act together with you before you move on. Baby steps, my man, baby steps.

Moderator-Keith

PRE-SUBMITTED QUESTION: What do most security managers do wrong in managing NAC devices?

joel_snyder

Well, you have to realize that we’re pretty early in the world of NAC. Folks have been doing NAC-ish things for a long time–look at SSL VPN vendors who have been NACing for 5 years almost, or vendors like Bradford who were solving specific problems before we started calling it NAC. I see long-term maintenance of the network/security/desktop separation as the biggest potential problem. NAC brings all these teams together, and all three are responsible for making sure that the NAC project is successful. But if they don’t continue, as a team, to keep things updated, then it can all fall apart or – worse — not do what you wanted. The biggest issue is the fast-moving nature of desktop threat mitigation, where the desktop guy (or girl) has to keep making sure that changes they have in their threat mitigation strategy get adequately pushed into the NAC policy. That smells like a moldy cheese in a lot of the deployments I’m seeing that’s going to explode sometime in the future.

todd%20k

Why not simply embed this technology into access devices? (the switches and apps and VPN head-ends) Do you think those vendors are heading in this direction ?

joel_snyder

Why not? Dude, you’re preaching to the choir. That’s where it belongs. I think that we’re on the same page. Whether the vendors are on the bus with us, I don’t know. But we can share this bottle of Kool-Aid I brought on board in the meantime.

Moderator-Keith

PRE-SUBMITTED QUESTION: Cisco and Microsoft promised interoperability between their NAC schemes. They published some documentation describing how it is possible. How important is interoperability anyway?

joel_snyder

This is so critical that you can’t possibly understate how important it is. Look, no one wants vendor lock-in, even if Cisco is the vendor. You know it’s going to be a pain later in life. And, no one wants to keep adding more and more software to these poor laptops that are already overburdened with eight different security products all stepping on each other’s toes. What we want is for a simple clean easy client to be built into Windows, and we want it to work with every product we buy. Microsoft should own this market; no one in the network security business wants to write software for Windows when Microsoft is saying “we can do that.” Or if they do, they’re idiots. In any case, interoperability for NAC is Microsoft’s bus to drive, and they have been making all the right motions.

Moderator-Keith

PRE-SUBMITTED QUESTION: OK, but what are your thoughts on what they’ve done?

joel_snyder

I’m going to reserve judgment (not that it’s my place to judge, of course). By the way, this isn’t just Cisco; it’s also TCG/TNC that’s just as critical for interoperability. I’ve had some great conversations with some brilliant folks like Ryan Hurst (he’s the unmitigatedrisk.com guy and a part-time BBQ chef) at Microsoft and it’s obvious that the mindset is there and the brainpower is there. Whether what comes out of the sausage grinder is what we need–I have to wait until I get it in the lab to find out. It’s just a tiny bit early to tell, but when Longhorn (Windows 2008) comes out, we’ll have a better view of the whole picture. The same’s true for TCG/TNC — Steve Hanna, another NAC guru, is leading that parade pretty well, but it’s up to the vendors to release products that match up to the marketing slides.

gmui TNC based implementation that works at the 802.1x level?

Are there any solutions out there that don’t rely on proprietary implementations –i.e. a fully

joel_snyder

It depends on your definition of proprietary. At Interop iLabs (see http://www.opus1.com/nac) we did a lot of non-proprietary stuff and a chunk of it was in 802.1X-land. Obviously, right now, proprietary is covering a lot of the marketplace, but there are lots of open things going on. If you consider TNC proprietary, or some of the MS NAP play-along with TNC to be proprietary, then the market narrows considerably. Open source-wise, we’re not very far. Chris H. and Mike M. can’t do it all on their own.

Tony

Can I learn NAC by self study or do I need a course. Which are the good self study and practice books and what all equipment I will need to practice?

joel_snyder

Bwah… Well, this is so new that you’re going to have to go off on your own. I’d start with an 802.1X switch and a couple of servers (maybe VMware with Unix & Windows), but honestly you’re going to have to see your own way here. SANS, I’m sure, will have a course on it pretty soon but that can be catch-as-catch-can until they get their act together.

rain

NAC enforcement: is there any consensus – is the endpoint itself the best place to enforce security policies or is the network infrastructure the best place to do that?

joel_snyder

Well, the consensus among guys typing in this chat is “infrastructure.” But obviously there are differing opinions.

Moderator-Keith

We’re going to wrap up in about 5 minutes — please submit any final questions to Joel as soon as possible…

amiller219

Have you heard of peer-based approaches to NAC – where end points on the network are used as enforcers to ensure that devices coming in are in compliance? If so, is it a viable option?

joel_snyder

I haven’t heard much about it, but I’m skeptical. I am a control freak, which means that I want the network to do the hard work and I want it to be done in devices that I own and control. Letting the end points bash on each other seems like a fun idea in a sort of poke-a-sharp-stick-in-your-own-eye kind of way.

RRR

What about NAC climbing into UTMs ? Do you see it happening before we start branching out NAC solutions?

joel_snyder

Is the ISR a UTM? I see lots of good stuff going into UTMs, and hopefully that will push out some of the stupid stuff. But, yeah, NAC should be in UTMs in order to serve the branch. Why do you want another box? (Unless, of course, you’re a box salesman)

gmui

Is there any discussion of the OpenSEA Alliance working on a NAC approach once they complete the 802.1X client?

joel_snyder

Don’t know. Let’s get Chris H. on the line and ask him. Chris, you out there anywhere?

corao IPS/IDS, vulnerability scanner, etc. but none are standards based – and the NAC product I am looking at can solve what I need – my endpoints, Cisco switch and SMS, why is standardization important at all?

Dumb question on standards – I have firewall,

joel_snyder

NAC is not a single product solution. You actually probably do have a standards-based firewall, if you think about it. But in terms of interoperability: NAC requires interoperability, and firewalls and IDS don’t. That’s why standards are required. NAC means a LOT of pieces coming together, and this is tough.

joel_snyder

OK, folks, my fingers are falling off.

Moderator-Julie

Thank you for attending today’s chat. Please mark your calendars for September 19, Enterprise messaging demystified with Michael Osterman; and October 1: The road to infinite capacity with Amazon.com CTO, Werner Vogels

Moderator-Keithwww.networkworld.com/chat. Thanks for joining us today!

A complete transcript of today’s chat, and all of our chats, will be available at

joel_snyder

Talk to you all later. Remember, “safety first.”