Our Clear Choice Test of A10 Networks’ IDSentrie shows this software package bucks both trends: It provides a simple tool for provisioning accounts and synchronizing passwords across multiple repositories and enables user self-service, with relatively low associated deployment costs.
How we tested IDSentrie
Archive of Network World tests
Subscribe to the Network Product Test Results newsletter
Overall, we found A10’s IDSentrie to be a good fit for small to midsize businesses looking for core provisioning functionality. Core provisioning includes account management — the ability to create, delete and modify user accounts — across multiple repositories, password synchronization across several repositories and user account self-service. At this juncture, IDSentrie does not provide much in the way of more-advanced provisioning features, for example, a workflow system that helps manage approvals, or fully automated end-to-end provisioning processes.
| ID MANAGEMENT IDSENTRIE 1000 A10 Networks | |||||||||||||||||||||||
| |||||||||||||||||||||||
| |||||||||||||||||||||||
IDSentrie’s strength lies in its ability to define aggregate business roles, such as sales manager or HR consultant, and provision system accounts to multiple target repositories based on role assignments. Another area where A10 stands out is in its IP-to-ID technology, which quickly lets an administrator map IP addresses to the users owning those addresses at any point in time. This is not a standard feature of provisioning systems overall, and many administrators spend hours researching and mapping IP addresses when the information is required.
We configured the IDSentrie 1000 appliance for the test network and started provisioning for our specific configurations in less than 30 minutes.
Management is accomplished through a Web-based console. We were pleased to have the option to redirect all HTTP traffic to Secure-HTTP for more secure access to the management process.
How we did it
We installed the IDSentrie appliance in our test lab, comprised of Active Directory running on Windows 2003, Fortinet Fortigate-60 firewall, Snort intrusion-detection system and a Cisco switched network.
We configured account provisioning to the Windows 2003 Active Directory containing 25 users running in the environment. We performed an extract from Active Directory to create a CSV file for initial import into IDSentrie.
We created roles and provisioning forms for each role, creating new users and moving existing users between roles. We also setup an OpenLDAP server to provision multiple accounts as part of a single role.
We used Snort and Fortinet logs to test the IP to ID mapping technology.
Once we completed the basic setup and created several system-administrator accounts, we configured the device to work with our implementation of Active Directory. The initial configuration of the Active Directory Data Source was very straightforward. We performed an import process from Active Directory to populate existing user accounts into IDSentrie, and then started managing Active Directory accounts from IDSentrie in about 10 minutes.
To manage account provisioning, we set up what A10 refers to as Forms for administrative and self-service provisioning tasks. Forms are the pages viewable by the administrator or user that can be configured in any number of ways based on the attributes (such as Active Directory fields) of the target system. Forms are tied to data stores and can be configured to require certain fields from each user. They also let the user update certain fields. We defined several Forms for various roles in our testing organization — manager, system administrator and HR manager. Each Form contained different required attributes and could be updated by users assigned to the role. Our test results were exactly what was expected.
For the self-service pages, we set up a Form where users could change their password based on a set of challenge questions, which are configured by users the first time they access the portal. We then logged into the system as a self-service user to go through the initial process, and everything worked smoothly.
The access control enabled by the IDSentrie system is fairly detailed, letting administrators provide read, read/write or no access rights to the product’s different modules. For
|
| ||||||||||||||
| ||||||||||||||
IDSentrie’s strength lies in its ability to define aggregate business roles, such as sales manager or HR consultant, and provision system accounts to multiple target repositories based on role assignments. Another area where A10 stands out is in its IP-to-ID technology, which quickly lets an administrator map IP addresses to the users owning those addresses at any point in time. This is not a standard feature of provisioning systems overall, and many administrators spend hours researching and mapping IP addresses when the information is required.
We configured the IDSentrie 1000 appliance for the test network and started provisioning for our specific configurations in less than 30 minutes.
Management is accomplished through a Web-based console. We were pleased to have the option to redirect all HTTP traffic to Secure-HTTP for more secure access to the management process.
How we did it
We installed the IDSentrie appliance in our test lab, comprised of Active Directory running on Windows 2003, Fortinet Fortigate-60 firewall, Snort intrusion-detection system and a Cisco switched network.
We configured account provisioning to the Windows 2003 Active Directory containing 25 users running in the environment. We performed an extract from Active Directory to create a CSV file for initial import into IDSentrie.
We created roles and provisioning forms for each role, creating new users and moving existing users between roles. We also setup an OpenLDAP server to provision multiple accounts as part of a single role.
We used Snort and Fortinet logs to test the IP to ID mapping technology.
Once we completed the basic setup and created several system-administrator accounts, we configured the device to work with our implementation of Active Directory. The initial configuration of the Active Directory Data Source was very straightforward. We performed an import process from Active Directory to populate existing user accounts into IDSentrie, and then started managing Active Directory accounts from IDSentrie in about 10 minutes.
To manage account provisioning, we set up what A10 refers to as Forms for administrative and self-service provisioning tasks. Forms are the pages viewable by the administrator or user that can be configured in any number of ways based on the attributes (such as Active Directory fields) of the target system. Forms are tied to data stores and can be configured to require certain fields from each user. They also let the user update certain fields. We defined several Forms for various roles in our testing organization — manager, system administrator and HR manager. Each Form contained different required attributes and could be updated by users assigned to the role. Our test results were exactly what was expected.
For the self-service pages, we set up a Form where users could change their password based on a set of challenge questions, which are configured by users the first time they access the portal. We then logged into the system as a self-service user to go through the initial process, and everything worked smoothly.
The access control enabled by the IDSentrie system is fairly detailed, letting administrators provide read, read/write or no access rights to the product’s different modules. For example, one administrator could work only on user-account provisioning, while a second administrator could be limited to system-administration tasks, such as setting up high-availability synchronization or shutting down or upgrading the system. While adequate for the current focus of the product, access control could be improved by its having an greater level of detail that would let administration roles and/or repositories be separated. For example, one administrator could handle only HR roles, and a second administrator could support only sales roles.
We did encounter a number of spelling and grammatical errors within the administrative console and in the documentation. We continue to be disappointed by products that seem to miss the mark on content.
The bottom left side of the administrative console contains a countdown to show how much time is left until the idle timeout disconnects the user from the system. We found this to be very distracting. We definitely prefer the standard pop-up warning to the consistent countdown. We did like the flashing red icon that prompts the user to save a configuration change.
While we did not test these features, A10 does support a separate management network interface to keep management traffic separate from provisioning traffic. This would be useful if users wanted to separate network segments or ensure that they have the highest availability for identity management functions and synchronization processes among multiple appliances.
Reports track logon activity, which is not common in most provisioning systems. A10 also offers reports for basic activities, such as inactive accounts, locked accounts and provisioning activity.
As noted above, the best reporting tool shipping with IDSentrie is the Find by IP feature, which lets the user enter an IP address and identify who was accessing a system with that IP address during a given time period. IDSentrie supports this feature for several well-known products out of the box, such as Check Point, Fortinet and Snort. The Universal Identity Parser is a free tool from A10 that lets the user take any text-based log file containing IP addresses and map them to individuals.
We performed our testing with a Fortinet Fortigate-60 and Snort logs configured to log instant messaging (IM) activity. Using IDSentrie, we were able to identify quickly which user was logged into the system and transmitting IM traffic at the time the Snort log event was generated.
Conclusion
IDSentrie is a strong identity-management product that is quick to deploy and easy to use, ideal for SMBs that want to deploy a tool to improve provisioning processes. The IP-to-ID reporting tool is unique and can easily provide the justification for purchasing the product based on the amount of time that can be saved by automating a very manual analysis process.
Andress is president of ArcSec Technologies, a security company focusing on product reviews and analysis. She can be reached at mandy@arcsec.com.
Andress is also a member of the Network World Lab Alliance, a cooperative of the premier reviewers in the network industry, each bringing to bear years of practical experience on every review. For more Lab Alliance information, including what it takes to become a member, go to www.networkworld.com/alliance.




