* Endpoint compliance: A discipline up for grabs
It’s a positive that enterprises now have many choices for protecting their corporate networks from malware and intruders. However, the dizzying array of alternatives could eventually confound enterprises. Who is the appropriate vendor partner for keeping infections and intruders off your network?
Among the players: Firewall vendors, routing companies, remote-access network-service aggregators, mobile management software providers, and, as of last week, even wireless LAN switching companies.
One question is how many special clients will enterprises be willing to run on user devices?
For example, the remote-access network-service aggregators (such as Fiberlink, GoRemote and iPass) require special client software with a common interface for connectivity. The software from these players, in addition to providing remote-access connectivity over an array of connection types and unified billing, also provides optional endpoint policy checks and enforcement.
Meanwhile, the Cisco Network Admission Control (NAC) initiative involves leaders in the anti-virus client software space. In this scenario, Cisco WAN access routers check for infections and software version compliance before granting admission to remote devices attempting to access the corporate network.
Firewall maker Check Point offers a similar capability via client software it acquired when it bought Zone Labs earlier this year.
In case a remote laptop should come back to the office and plug right into the LAN, LAN-side vendors are also getting into the act. WLAN mobile management company Wavelink now teams with Funk Software to put a Funk Odyssey client on mobile user laptops for endpoint policy control.
Similarly, WLAN switch vendor Aruba Wireless last week said it has built a wireless/wired security overlay that involves a policy engine in the data center checking LAN-connected mobile devices (whether connected wirelessly or directly via an Ethernet port) for infections and software compliance. The solution is said to eliminate needing expensive firewalls in every wiring closet to do the job.
Meanwhile, data center firewall makers such as Fortinet and iPolicy, which also scan for malware and check for software compliance, support LAN connections and can screen LAN traffic before granting access.
Ultimately, it’s our belief that that multifunction intrusion-fighting devices generically known as firewalls will remain in the data center, and a version of them will also get integrated into wiring closet switches.
Our advice? Check with a security consultant, at least initially, to sort out the various options so that you don’t find yourself with too much overlap and ultra-heavy clients.




