tgreene
Executive Editor

Start-ups look to horn in on net control

News
Nov 14, 20054 mins

LAN security appliances enforce policies at access switches.

Businesses that seek more control over who and what machines access their LANs but don’t want to wait for network equipment vendors to get their plans in place have another option: appliances that impose such controls without requiring switch upgrades.

This week a start-up called Nevis is scheduled to announce its alternative, two network devices that enforce policies by allowing access to authorized resources, denying it to unauthorized resources or shuttling a non-compliant machine to a quarantined network.

This is similar to the approach taken by competitors ConSentry Networks and Vernier Networks. All three vendors’ appliances sit between LAN access switches and LAN distribution switches to exert control over individual access switches, so if a desktop starts misbehaving, it can be isolated without affecting an entire LAN segment. Nevis’ LANenforcer gear can serve as the access switch and provide per-port control of security policies.

Equipment from Nevis and Vernier also checks that computers meet network security profiles, such as having appropriate patches and virus protection in place.

Cisco’s Network Admission Control (NAC), Microsoft’s Network Access Protection (NAP) and Juniper’s Enterprise Infranet initiatives have similar goals but require software agents on every desktop and upgraded switches that can act as enforcement points for security policies.

Joel Snyder, a senior partner at Opus One, a consulting firm in Tucson, Ariz., and a member of the Network World Test Alliance, describes the new appliances as “high-density, high-performance, identity-based firewalls.” The smaller vendors may have an advantage, he says.

“I see this as a technology that will do many of the things that NAC wants to do, and in fact might be better than NAC/NAP . . . at pushing the brains into the network rather than expecting them to be at the edge, where the PC is,” Snyder says.

The main downside of NAP and NAC is that they require upgrades and overhauls across a range of equipment, says Lloyd Hession, CSO for financial networking service provider BT Radianz, which uses ConSentry gear. “We’re a huge Cisco shop, and the challenge Cisco NAC has is it typically requires a lot of upgrades. Unless you’re building from scratch or have a huge amount of money for your project, it’s going to take a very long time,” he says.

The other issue is that Cisco and Microsoft alternatives are not ready. “When everything shakes out with the Cisco and Microsoft solutions, it will be 24 months down the pike,” according to the infrastructure architect for one of the top five commercial insurance companies in the United State, who is testing Nevis gear. In the case of Microsoft, waiting for the client software and testing it before deploying could take another 12 months, he says.

But many businesses are looking for better, simpler LAN access control. For example, consultancy Financial Engines of Palo Alto, places a firewall between its corporate network and its production network – the network where customer financial information resides and where financial advice is generated.

Today, to grant access to a production network requires an Active Directory profile change, as well as a separate firewall rule change, says Matthew Todd, chief information security officer for Financial Engines. With Nevis, that could be accomplished by applying a single Active Directory rule change that shifts the user to a different firewall policy group. The Nevis gear would then enforce the new policies.

“We’d be able to allow some administrators that are able to administer groups but not firewalls to allow an employee access to customer data without having to open up a ticket with the firewall group and have to wait for that,” he says.

Accomplishing all the scanning required by these devices requires enormous processing power, says Phil Schacter, analyst with Burton Group. To that end,ConSentry and Nevis have developed high-performance chips so their devices don’t slow down LAN traffic.

Processing power also is a limitation of switch-vendor setups, and to remedy that, ConSentry has long-range plans to put its appliance on a blade that could be inserted in a switch, the company says.

Nevis is shipping two types of LANenforcer appliances. Nevis 1000 is an access switch that checks and enforces access policies, and it includes a port-based stateful inspection firewall. Desktops plug directly into it. The Nevis 2000 is a similar device that connects to groups of switches rather than to individual PCs, similar to what ConSentry’s appliances do.

There are three N 1000 models priced from $13,000 to $20,000. The N 2024 costs $35,000.