Network Access Protection aims to keep your network healthy

Opinion
Mar 28, 20074 mins

* NAP to be one of the most talked about enhancement in Longhorn

Burton Group VP and Network World columnist Dan Blum seems to agree with me that Vista belongs on your desktops. Not immediately, he thinks, but following your normal deployment schedule of new machines. Perhaps even slowing that deployment down. He especially thinks you should wait until Vista is “playing nicely” with all of your third-party security tools.

But his column did remind me that one of the new security features in Vista – Network Access Protection (NAP) – will also be one of the more talked about enhancements in Longhorn when the new server operating system ships, which should occur within the next 12 months.

NAP is a “policy enforcement platform”, according to Microsoft, built into the Windows Vista and Longhorn Windows Server code that allows you to better protect network assets by enforcing compliance with system health requirements. With NAP, you can create customized health policies to validate computer health before allowing access or communication, automatically update compliant computers to ensure ongoing compliance, and optionally confine noncompliant computers to a restricted network until they become compliant.

“Health,” by the way, appears to be a euphemism for “running the most up-to-date software,” at least as I read the marketing materials from Microsoft. But if you can get past the cuteness factor (one press release talked about non-NAP protected computers being “…at higher risk of infection from Web sites, e-mail, files from shared folders, and other publicly accessible resources”), this is an important new tool. It will allow you to specify minimum requirements in terms of software and versions installed before allowing a computer to access your network.

You can also set limits on the connection based on a specific amount of time, or the access could be limited to a restricted network, a single resource, or to no internal resources at all. If you do not configure health update resources, the limited access will last for the duration of the connection. But if you do configure health update resources, the limited access will last only until the computer is brought into compliance. You could use both monitoring and health policy compliance in your networks and configure exceptions.

Microsoft has set up a Web site with lots of details about NAP which you should check out.

One important thing to remember is that NAP, by itself, does nothing. It will monitor other components, known as system health agents (SHA) and system health validators (SHV), to provide health policy validation and health policy compliance. Windows Vista and Windows Server Longhorn include an SHA and an SHV that provides health policy validation and health policy compliance for health attributes monitored by the Windows Security Center. Third-party vendors will supply other SHAs and SHVs for their systems or for others you might want to monitor. Almost 100 third-party companies (most in the security arena, but many also in patch management, networking, and system integration) have already announced their support for NAP, including:

* A10 Networks

* AEP Networks

* ALAXALA Networks Corporation

* Alcatel

* Altiris

* Apani Networks

* Applied Identity

* AppSense

* Aruba Wireless Networks

* Avanade

* Avenda Systems

* Aventail

* BigFix

* Bluesocket

* Bradford Networks

* Broadcom Corporation

* CA

* Caymas Systems

* Centennial Software

* Check Point Software Technologies

* Citadel Security Software

* Citrix Systems

* Configuresoft

* ConSentry Networks

* CounterStorm

* Cybertrust

* D-Link

* eEye Digital Security

* Enforce

* Enterasys

* Extreme Networks

* F5

* Fiberlink

* ForeScout

* Foundry Networks

* F-Secure

* Huawei-3Com

* Impulse Point

* Infoblox

* InfoExpress

* Innerwall

* Insightix

* Internet Security Systems

* iPass

* iPolicy Networks

* Juniper Networks

* LANDesk Software

* LG N-Sys

* Lockdown Networks

* ManageSoft

* McAfee

* MetaInfo

* Meru Networks

* Mirage Networks

* Nevis Networks

* Nortel

* OPSWAT

* Panda Software

* PatchLink

* Pedestal Software

* Permeo

* phion

* PortWise

* ProCurve Networking

* Reflex Magnetics

* Roving Planet

* RSA

* Safend

* Samsung

* Secure Elements

* SecureWave

* Shavlik

* Siemens Communications

* SignaCert

* SkyRecon Systems

* SmartLine

* SoftRun

* Soliton Systems

* Sophos

* St. Bernard Software

* StillSecure

* Symantec

* TippingPoint

* Trapeze Networks

* Trend Micro

* Trust Digital

* UNETsystem

* VeriSign

* Vernier Networks

* Vision Power

* WatchGuard

* Websense

* Whale Communications

* WINS Technet

You’ll recognize some from previous mentions here, recognize others that you’re already using applications and services from, and – most likely – see a number that are new to you. Investigate them now, before beginning to test Longhorn, to see which might benefit your organization best: which ones will help keep you “healthy.”