* Netmarks scans end-user machines and offers fixes if devices fail the admissions test
endif; ?>A Japanese service provider is blending VPN capabilities with network access control to offer a service that might prove useful elsewhere.
The provider named Netmarks offers a service that scans end-user machines trying to gain access to the SSL VPN service. The scan itself is done by software agents made by Netmark. The agents report back to Juniper gear, which compares the results against policies that define allowable configuration. The Juniper equipment has APIs that allow third-party software to interoperate with Juniper software.
If the device is deemed secure enough to join the network, it is admitted. If not, the Juniper device presents it with a Web page that tells the user about the nature of the rejection. The page can include a link to a separate site maintained by Netmarks where the end user can download the updates their device needs to become compliant. So if the scan determines the operating system of the device lacks required patches, the user would be directed to a site from which those patches can be downloaded.
This is the type of service that might be attractive to small and midsize businesses because they are the companies that have security needs but also might have limited technical support and limited budget to buy and maintain their own VPN equipment.
It is also an example of an NAC service that doesn’t require much up-front money from the customer. Given that NAC is a generally expensive and complex undertaking, look for providers to step in offering this type of service on a more widespread basis.




