Security technology targets the LAN

Opinion
Sep 19, 20052 mins

* User-based LAN access control is a new technology that redefines network admission and access

Security technology targets the LAN

By Joseph Tardo

Access-control lists, originally designed for routers to deny or admit packets entering a network from a WAN, have drawbacks in controlling a diverse group of users accessing LANs. ACLs have no knowledge of traffic-flow semantics or content, can’t adjust access rights for individual users, and suffer scalability and performance limitations.

User-based LAN access control (ULA) is a new technology that redefines network admission and access. Made possible by a new breed of high-performance ASICs, emerging ULA-capable LAN security systems sit in a network at the user-access layer or at an aggregation layer, and inspect every packet on every port for security policy compliance and malware.

The technology lets an administrator identify who is using a network, where and how he logged on, what resources he can access, and whether the LAN is still secure and malware-free once the user is admitted. It also provides automatic quarantine mechanisms to isolate problem users immediately, and to dynamically change from normal to quarantine policy when malware is detected. In effect, it works to create a personal DMZ for every user on every port.

User-based LAN access control operates transparently to end users, while providing powerful security safeguards for network or security administrators. ULA-capable systems are flexible enough to offer several mechanisms for authentication, and smart enough to understand the concepts of user identity and security policies associated with each user. For example, when a user plugs his laptop in to a network, he authenticates via 802.1X, or a captive portal Web logon page, and the system immediately applies that user’s security policies to all applications and network services he accesses.

This security technology also integrates with existing authentication databases to identify user-group memberships. A system matches group memberships from an existing RADIUS or Lightweight Directory Access Protocol database to security policies that will be applied on a LAN access port. This group-based approach guarantees scalability across a corporation, because policies are defined one time and all group members automatically inherit the policies at logon. When a user is transient (say, a contractor working on the latest SAP upgrade), policies travel with him wherever he connects to the network.

To learn more about ULA, please see: http://www.networkworld.com/news/tech/2005/091905techupdate.html?rl

Tardo is principal security architect for Nevis Networks. He can be reached at joseph.tardo@nevisnetworks.com