Who’s the right partner for endpoint security?

Opinion
Nov 30, 20042 mins

* Endpoint compliance: A discipline up for grabs

It’s a positive that enterprises now have many choices for protecting their corporate networks from malware and intruders. However, the dizzying array of alternatives could eventually confound enterprises. Who is the appropriate vendor partner for keeping infections and intruders off your network?

Among the players: Firewall vendors, routing companies, remote-access network-service aggregators, mobile management software providers, and, as of last week, even wireless LAN switching companies.

One question is how many special clients will enterprises be willing to run on user devices?

For example, the remote-access network-service aggregators (such as Fiberlink, GoRemote and iPass) require special client software with a common interface for connectivity. The software from these players, in addition to providing remote-access connectivity over an array of connection types and unified billing, also provides optional endpoint policy checks and enforcement.

Meanwhile, the Cisco Network Admission Control (NAC) initiative involves leaders in the anti-virus client software space. In this scenario, Cisco WAN access routers check for infections and software version compliance before granting admission to remote devices attempting to access the corporate network.

Firewall maker Check Point offers a similar capability via client software it acquired when it bought Zone Labs earlier this year.

In case a remote laptop should come back to the office and plug right into the LAN, LAN-side vendors are also getting into the act.  WLAN mobile management company Wavelink now teams with Funk Software to put a Funk Odyssey client on mobile user laptops for endpoint policy control.

Similarly, WLAN switch vendor Aruba Wireless last week said it has built a wireless/wired security overlay that involves a policy engine in the data center checking LAN-connected mobile devices (whether connected wirelessly or directly via an Ethernet port) for infections and software compliance. The solution is said to eliminate needing expensive firewalls in every wiring closet to do the job.

Meanwhile, data center firewall makers such as Fortinet and iPolicy, which also scan for malware and check for software compliance, support LAN connections and can screen LAN traffic before granting access.

Ultimately, it’s our belief that that multifunction intrusion-fighting devices generically known as firewalls will remain in the data center, and a version of them will also get integrated into wiring closet switches.

Our advice? Check with a security consultant, at least initially, to sort out the various options so that you don’t find yourself with too much overlap and ultra-heavy clients.

joanie_wexler
Writer

Joanie Wexler is an independent writer and editor who has spent 20+ years writing about computer networking technologies, their business potential, and implementation considerations. She serves clients at technology companies and industry publications writing educational materials on all aspects of IT.

More from this author