* Developers of open source NAC are very practical
endif; ?>Developers of open source NAC products are a very practical lot. They use existing open source software to back end the NAC-specific code they write.
So if they want to implement post-admission NAC that monitors the behavior of devices once they are admitted to networks and kicks them off if they misbehave, they often base it on Snort, the free intrusion detection platform.
The platforms run on Fedora, the Linux core. The database servers are MySQL. They are written in Perl. You get the idea.
The reasons for using these elements are more than just that they are free, although that is a big reason. They are also stable and well understood, making them trustworthy and easy to work with.
But these elements didn’t start out that way. Scrutiny and fixes over time by the open source community made them that way, and someday they may make the open source NAC platforms just as stable and reliable.
Like any software project, commercial or open source, getting the basic code to work and debugging take time. Even the commercial vendors who have been working on NAC for about the same amount of time as the open source community, are still refining their gear.
Nothing suggests that open source NAC will fall short of becoming a reliable tool that can be downloaded and built upon, but it will take time.
For now, it can prove useful in practice by providing protection in live networks for those willing to work out the kinks. Also, it can be a useful learning tool for those who want a better understanding of NAC and its potential.




