by Paul Desmond

Whirlpool takes Cisco NAC for a spin

News
May 14, 20077 mins

Test of Cisco wares proves network access control works, but you have to make the business case

After a pilot lasting more than three months, Whirlpool is confident that network-access-control technology will not only help keep its global network more secure, but also play a role as the company implements a new generation of Web services applications.

Alex Petrov, global principal network architect for the Benton Harbor, Mich., home appliances company, presented his NAC findings at the recent Network World IT Roadmap Conference & Expo in Chicago. Whirlpool’s tests of Cisco NAC products verified that they performed their basic functions as advertised, disallowing network access to client machines that were not sufficiently secure. While the technology may cause a temporary increase in help-desk and desktop-support costs, longer-term the Whirlpool tests indicate NAC will reduce overall security costs and risks by introducing more self-service and automation.

Perhaps more importantly, however, Petrov expects NAC, together with other network security technologies, will position Whirlpool to take advantage of Web services internally and externally. “We’re talking years away,” he said in a follow-up interview. “But we absolutely think this is where enterprise architecture is headed, and we need to know what kind of security mechanisms we need to have in place to support it.”

In pursuit of NAC

Before embarking on its NAC test, the $18 billion company explored alternative technologies, but fairly quickly decided that NAC would be fundamental to its multitiered security strategy, Petrov says. Whirlpool then explored NAC products from Cisco, Microsoft and others. “To us, it was really important to have two things: compatibility with existing infrastructure, and futureproof technology, something that would not require fork-lifting,” he says.

Whirlpool gives NAC a spin

Key to going with Cisco was the fact that Whirlpool already was standardized on Cisco equipment for its LAN and WAN infrastructure. “It wasn’t that hard of a decision,” Petrov says.

For its pilot test, Whirlpool sought to simulate multiple environments, including its 1,500-user headquarters, 800 users at a major plant and 100 users at a regional distribution center. “Essentially it was a scaled-down version of our production network with NAC elements added to it,” Petrov says. Specifically, those elements were Cisco NAC software on switches and routers, Cisco Security Agent on clients and the Cisco Monitoring, Analysis and Response System to identify and isolate potential security threats.

The pilot, which the Whirlpool engineering team ran with Cisco and Cisco partners in the spring and summer of 2006, tested the overall NAC process, with emphasis on validating that user devices had all the most current antivirus software and operating system patches. The tests also validated how the quarantine process would work when a client system was out of compliance, and how it would go through the NAC process again once it was remediated.

“It was important for us to see how the Clean Access server and clients would talk to each other and to validate the admission process,” Petrov says.

Figuring the finances

As it turned out, deploying and testing the technology was “not the most challenging part,” Petrov says. “It took us longer to develop the financial justification vs. running the lab portion.”

For starters, Whirlpool’s tests indicated that after going live with NAC, the company would have to budget more for desktop support and help-desk services to deal with an increase in calls and requests from users. “It will create some pain points for users when they realize they don’t have all the required patches and so on,” Petrov says.

In its presentation to management, Whirlpool had to make assumptions about the additional workload for the help desk. That would depend on the complexity of the calls, which would be driven by how far out of compliance each user’s PC was. The team came up with some estimates on the workload and call duration, but Petrov did not disclose them.

The biggest economic driver was reducing the probability and economic costs of a major security breach. The trick was coming up with a number for how much NAC would reduce that probability.

“The only thing you know when you have just one number is, it’s the wrong number,” Petrov says. “So you have to come up with a range of numbers, say between 10% and 30%, and see what your business case would look like for that range.” For its business case, Whirlpool considered the best- and worst-case scenarios, along with what-if scenarios in the middle.

Another factor in the financial discussion was the need to upgrade a number of Cisco routers and switches to support NAC. “We looked at all sites and evaluated the upgrades that would be required, whether hardware upgrades or IOS upgrades, and associated costs,” Petrov says. That analysis gets complicated because those upgrades bring benefits that extend beyond just NAC, but the costs were nonetheless included in the NAC business case.

On the plus side, Whirlpool estimates that NAC will reduce overall security costs in the long term. Once users get familiar with the technology, Petrov expects the volume of help-desk calls will decrease because of various self-service and automated features, such as operating system patches and antivirus updates, and prevention of security-related problems.

Tallying the benefits

Also on the plus side are the benefits that Whirlpool expects from NAC, which fall into two general groups. The first is reduced security risk and prevention of a major security breach, which is the fundamental benefit of NAC.

The other benefit is a long-term, but crucial one for Whirlpool. NAC will be one of several security technologies, along with enhanced digital certificates and XML-based VPNs, that let the company employ Web services applications inside the company and with business partners and external IT services and libraries.

Whirlpool is a big SAP shop, for example, and SAP is creating libraries of Web services for its users. “We’re looking at the open source community as well, because we think it will be a valuable source of Web services,” Petrov says.

The trick is being able to authenticate that these services are valid and secure before employing them. In practice, that typically will happen on a machine-to-machine basis, with no user involved.

“We’d have to manage the relationships, not just beyond our perimeter but also inside our perimeter,” Petrov says. “And at some point it will merge — there will be no perimeter. So we need to validate those flows based on the user, machine, application, port, behavior and so on.”

Sound advice

With its pilot behind it, Whirlpool has a road map for implementing NAC but is keeping it close to the vest for security reasons.

Based on his experience with the technology, however, Petrov likes what he sees thus far from Cisco, although he is looking forward to the results of the company’s collaboration with Microsoft in enabling their respective NAC technologies to play together. “We are using Microsoft operating systems and PCs, so we want to know how this will work, what it will do, how it will impact the business case,” he says.

Petrov advises other would-be NAC implementers to be mindful of their own business cases. “Every organization has some metrics that are important to their business case and whether it makes financial sense,” he says. “You have to plug in your own parameters, not base it on somebody else’s calculations.”

Desmond is events editor for Network World and president of PDEdit, an IT publishing company in Southborough, Mass. Reach him at paul@pdedit.com.