Portnox, Extreme lead NAC pack

Reviews
Mar 30, 201526 mins

Remember when network access control (NAC) was all the rage? Remember the competing standards from Microsoft, Cisco, and the Trusted Computing Group? Back around 2006, there were dozens of NAC products, many of which turned out to be buggy and difficult to implement.

Over time, other network-based security products – mobile device management (MDM), intrusion prevention systems (IPS) and next-generation firewalls – came along and squeezed NAC into a narrower part of the market.

But NAC hasn’t disappeared. In fact, NAC products have evolved and improved as well. For this review, we were able to bring the following five vendors together: Enterasys/Extreme Networks Mobile IAM, Hexis Cyber Solutions NetBeat NAC, Impulse Point SafeConnect NAC, Pulse Policy Secure, and Portnox NAC. (Cisco, ForeScout, Auconet, and Aruba declined our invitation.)

+ ALSO ON NETWORK WORLD: Next-gen NAC designed to facilitate BYOD +

Overall Portnox was the best NAC unit we tested, with Extreme coming in a close second. Portnox had better reporting than Extreme, while Extreme had better device detection capabilities. 

In general, we found that today’s NAC products are better constructed, easier to install, and easier to manage. But NAC still isn’t a complete cakewalk either. The challenge is being able to understand your network in ways that complement your knowledge about exploits, so you can identify problem areas quickly and still keep false positives and frustrated users to a minimum. That isn’t easy, even with the best NAC products.

In addition, deploying NAC across a large and complex network infrastructure can be a challenge. For NAC to work, it has to cover a wide range of endpoints, servers, and switches. We found, however, that some NAC products look more closely at switch ports, some look at endpoint devices, and some look at users.

In the early days of NAC, most of their magic was accomplished by installing agents on your endpoints. But agentless operation is more the norm today, and some products now work with both. Also, today’s NAC tools use a combination of probes including NMAP, Windows Management Instrumentation (WMI), Radius authentication, remote access to log files via SSH and SNMP queries.

We were amazed at how much information these tools could suss out from the mixed bag of endpoints that we assembled on our test network. Perhaps that is the biggest story of the progress of these NAC tools, and how their detection prowess has improved.

Where NAC fits In

Since their inception, NAC products promised to do four things to protect your network:

  1. Coherent policy definition. You should be able to set and maintain a variety of security policies for different user populations, locations and network equipment, and be able to easily modify them from a central management console. Typical security policies would include looking for new endpoints that are added to a network, or when an endpoint has multiple network interfaces, or when a device is moved from a wired to a wireless network.
  2. Security posture detection and assessment. Your NAC system should be able to scan the endpoint and determine compliance with your policies. The system should be able to assess what isn’t up to snuff, and why, and report on this in near-real time.
  3. Enforcement. Once you detect something amiss, your policies should determine how they are enforced. Should you quarantine or refuse network access entirely? Or just flag the violation and send appropriate notification to a network administrator?
  4. Remediation. Finally, the ideal NAC system should indicate what is broken or non-compliant or missing from a particular device.

General impressions

All five of the products could benefit from hiring UX designers and scrapping their aging interfaces, and in some cases consolidating multiple screens and interface methods to something more modern. All came up short in some capacity and this is perhaps NAC’s biggest frustration. Think of how firewalls were managed 10 years ago and you know what to expect with these products. None of the products did very well on reporting, which is another challenge for NAC.

Also, none of the products caught every possible test case, although Extreme came the closest at figuring out what was on our small test network. We realize that is somewhat of a testing construct: in the real world, you will deploy these products across very busy networks that are living entities with endpoints coming and going.

This is why reporting and auditing is so critical; sadly, all of these products could do a far better job with these features. This is perhaps one of the reasons why you don’t hear of NAC as often as you once did back in their heyday.

If you have a large portion of your infrastructure virtualized, you will want to take a closer look at either Portnox or Extreme, which is another reason why they are both top-rated. Both handled VMware virtual switch fabrics as well as they did with physical switches; and Extreme can also cover Hyper-V and Xen hypervisors. The others don’t really understand VMs and in some cases misreport their particular situations.

And if you use an MDM tool, you will want to look at either Extreme or Pulse Secure for their integration with leading MDM vendors. The combination can be a potent one if you want to track what is happening with mobile devices when not connected to your network and have a unified set of policies to cover what its posture should be when these mobile devices return to your office.

NetBeat and SafeConnect lagged behind the others in terms of their detection abilities.

Here are the individual reviews:

Extreme Networks Mobile IAM

Extreme Networks has a complex NAC solution and ended up sending us three pieces of hardware: a ESX server containing several VMs, including their NAC software and VMs of their management tools, one of their managed SSA-130 class switches, and a WS-AP3750 wireless access point.

+ 6 tips for selecting the right all-in-one NAC product +

Extreme depends on RADIUS to discover and control network access and can manage large networks with ease: they currently have several customers with more than 100,000 nodes on their networks. The company incorporated technology it purchased from Enterasys into its product line.

Extreme’s management tool is called NetSight; we ran it from a VM. It handles one or more NAC appliances that can run on either dedicated hardware or inside other VMs. And its wireless access points also makes use of a controller that runs on a hardware appliance, a separate VM or can be placed in the cloud.

That is a lot of moving parts, and we were glad that we didn’t have to configure each one, but had an Extreme engineer at our side to handle issues. All of this gear was connected to our lab network, where we had Juniper, Cisco, and Linksys switches. It correctly identified each of these devices.

NetSight has two different management interfaces: a Web UI (called OneView) and a series of Java modules, each with a different and somewhat confusing series of functions. If you stick to the Web UI you can accomplish most of what you need to do for the reporting and monitoring functions; the Java client is more for setting up policies and adding NAC controls.

+ ALSO:  Extreme Networks CEO touts open SDN strategy, robust wireless as key assets in changing net market +

Extreme was the only vendor that could handle self-remediation and it comes with lots of options, as you would expect with a NAC product with several years’ worth of history. To set this up you need to be running the Java client. The product is very flexible, for example, each assessment rule can kick off different profiles and actions. You can also have guest networks that make use of Facebook login credentials, for example.

Extreme, along with Juniper, also integrates with a number of MDM vendors, so you can share policy and control information with AirWatch, MobileIron Fiberlink and several others.

Extreme was also the most widely integrated in handling a virtual switch fabric of VMware, Hyper-V and Citrix Xen hypervisors: you can pull up information on all of these environments and understand how which VMs are connected to the switch and assign vLANs and policies to them. We did find a small bug where it didn’t correctly report a Windows VM running on our Mac connecting over a wireless network, but no one else figured this out either.

Extreme has Windows and Mac agents that are optional: it will operate without agents too. The agents can be setup to dissolve after a reboot or persist. Before you decide whether you want to install them you need to check out its “fingerprint” screen that shows you how it discovers what is going on across the network. It correctly figured out a dual-NIC Mac and identified both of its interfaces properly with the same host name. It also figured out that we had switches attached to the test network and could find PCs hiding behind them.

Extreme’s biggest weakness is its reports, which are scattered among various tabs within the Web UI. There is the ability to create custom dashboards, and reports can be exported as PDFs too. Clearly this is still a work in progress. It does a better job of summary dashboards than some of the other products, but again, these need to be tied together in a consistent manner and made easier to execute.

Extreme costs $10,000 for 500 devices that appear over any 24-hour period, which is in the middle of the pack.

Hexis NetBeat (formerly NetClarity)

Hexis sent us a 1U hardware box that is managed with a Web browser that we connected to our test network. NetBeat is based on technology Hexis acquired from Netclarity last summer. NetBeat comes with two built-in Ethernet ports: the first one is used to connect to a switch access port; the second is used to monitor vLANs. It excels at understanding Layer 2 traffic across your network.

The Web screens had some minor display errors in Firefox or Chrome, but ran fine with Safari. There are no agents to install on the endpoints with one exception noted below. The appliance has a series of menus on the left side that are somewhat haphazardly organized.

+ RELATED: Hawkeye G battles malware so you don’t have to +

When you first connect to the device from your browser, you are presented with an overall risk profile with three dials that show threats, vulnerabilities, and assets. At the top of the Web-based console is a thermometer showing “overall network risk profile” in a line from 0 to 100. It is hard to understand what this means, and watching the needle move across this gauge is probably not something most network administrators will find very useful. You can adjust what is shown in these charts with various weighting factors that can emphasize rogue virtual LANs over spoofed IP addresses, for example, but again that seems like more trouble than the effort is worth.

Once the appliance is connected to your network, it will attempt to discover network resources. Untrusted devices are highlighted in yellow bars, making them easy to spot. NetBeat had a harder time than its competitors figuring out our unmanaged switches and VMs running on our test network. But it does support managed switches from Extreme, Cisco, 3Com and HP.

For example, it misidentified a Mac running OS X 10.9 as a mobile device running iOS, and couldn’t identify an HP laptop other than it was running some version of Windows (it was using Windows 8). It uses NMAP to scan your network and SSH to communicate with your managed switches. It also listed our Mac’s wired and wireless interfaces separately and couldn’t identify them as coming from the same computer.

The one agent-based piece of software available is for Windows Servers 2003 or 2008 (but not 2012). This sends Active Directory information to NetBeat to get better user information. You can obtain this information by sending Active Directory log information from your server without installing any agent; it is a matter of preference.

There are also two different user interfaces for asset discovery, one called “classic” that is somewhat terser than the other. On either list you can mark particular endpoints as trusted, move them to particular vLANs, or edit their descriptions if you recognize them.

NetBeat also wants to perform frequent signature updates, and because of a bug we had to go through a few steps to get these started on our test box. You also have to sequentially install its service packs, so you don’t want to miss any of them. This was somewhat annoying.

When NetBeat finds a vulnerability, it can generate a support ticket, and this ticket can be routed to a network administrator to escalate and resolve. It comes with three different pre-set access right levels: manager, IT staffer, or ordinary NAC user.

It has a very interesting assembly of 26 pre-set best practice compliance documents. You can use these as starting points to compose your own documents, which is a nice reminder that NAC can help define compliance (although the documents don’t have any effect on overall NAC operations).

Reports are this product’s biggest weakness. Reports can be scheduled to run periodically, and can be exported in PDF format. But they contain far too much information to be useful to security managers: a relatively healthy Mac running OS 10.9.5 produced a series of warnings about vulnerabilities that weren’t relevant, such as one for Windows XP’s IP stack.

There is also a confusing array of menu choices for reporting formats and content, such as more graphical information geared at management, that could use some cleaning up.

Ironically, a better alternative to any of these reports is its logging section, where you can assemble reports for specific network activities, such as IP addresses that disappear or MAC addresses that have been spoofed. This is probably where you will spend more time understanding what is happening on your network. One of our test use cases, having a PC with dual NICs, was hard to find in either logs or reports, and, as we said earlier, NetBeat doesn’t do well with figuring out VMs.

At $5,500 plus another $600 a year for a support contract NetBeat was the least expensive unit we tested, half what the next pricier unit went for.

Impulse Point SafeConnect NAC

Impulse Point has several components, including a hardware management device that sits on your local network and a series of software tools that are accessed through a Web browser. There are four separate Web interfaces: one for the dashboard and device reporting, one for system and network configuration, one for support and documentation and one for policy setup and management. Finding the appropriate series of menu commands is initially confusing until you understand how Impulse Point has split its controls among these interfaces. They work with Firefox or Chrome browsers and IE from v9 onwards.

For our tests, the vendor sent us a managed wireless access point and login information to access their test network in its cloud of thousands of devices. Once we connected to their dashboard, we were able to add and manage our own Windows and Mac clients that resided in our test lab. In normal use, you would place their hardware on your on-premises network and connect it to various authentication servers and set up links to your managed network switches.

To discover your endpoints, they make use of a variety of tools, including Netflow, syslogs from DHCP servers, and RADIUS accounting information. They do not tap into WMI, and do not have agents on each endpoint. They can discover a wide range of routers and switches, but not VMware virtual ones. However, as part of the login process, they do install a piece of executable software that is the policy and crypto key for that endpoint. This key auto provisions and identifies the endpoint to the management console. They do a decent job of discovery, and are tied with Portnox in terms of figuring out what is running on each system.

When you first login, you have a choice to access your network from a new endpoint to install a 802.1X certificate to identify yourself, or login using a guest account. They support a wide variety of mobile and desktop devices, including Windows XP and Macintosh OS 10.5 and more recent desktops, and various mobile devices and even Kindle, Roku and Xbox. They do not support server OS versions. Impulse claims this is a feature because they don’t operate inline but enforce their policies across the entire network and don’t need to interfere with any server operations. You may or may not agree with this.

Once you have logged in and installed your certificate, your security posture is checked. If you don’t meet the policy requirements, you have to remediate. We had our enforcement policy set to “immediate quarantine,” which meant we had to self-remediate by downloading patches or bringing our antivirus up to date. Other choices are to send a stream of periodic warning messages, or to just audit the system and still allow network access.

The policy engine is the heart of SafeConnect and you can choose from a wide variety of policies on authentication, NAT, antivirus, OS patching, or create a custom policy. The policy creation process is somewhat dense and difficult and the company admitted it is working on several wizards to make things easier. Nonetheless, you can assemble a quite complex policy and workflow steps if you need one, with each policy having its own enforcement action and identity provider for example.

New to this version is a series of “End of Life” policies where you can set up blocks on devices running particular older OS versions. That could be handy, depending on what kind of legacy desktops you still have to deal with.

For our test use cases, we had mixed results. It was easy to figure out when we added new devices to the network through its canned reports, but not as easy as some of the other products tested. The dual NIC task was difficult to accomplish and hard to detect, and the company is working on a better reporting scheme for the future to handle this situation. And when we added a new wireless access point to our configuration, SafeConnect figured out what was happening within a few minutes, and flagged the situation accurately.

Searching for particular clients is easily and quickly accomplished with a search box on the left side of the interface, and there is also a strip down that side showing you real-time network statistics: which endpoints are compliant, which are still needing remediation, and so forth. That is handy but ultimately difficult to parse if you have a large complex network with lots of device movement.

SafeConnect has copious reports; the hard part is getting them setup to show you meaningful information. One option is to export historical information to either a syslog or MySQL server for some more advance reporting.

Impulse Point can be pricey at $24,000 per year to secure 500 users.

Juniper/Pulse Policy Secure

Pulse Secure sent us three devices: a Juniper SRX UTM box, a low-end managed Juniper switch, and its Pulse Policy Secure NAC device. Having all three was cumbersome but an illustration of how each works together to provide a fully featured protection solution that operates from Layer 2 outwards. Each has its own Web and command-line interfaces and in the usual tradition of Juniper you’ll need to use both methods on all three boxes to get started.

Pulse Secure, formerly known as Junos Pulse, was spun out of Juniper to the Siris Capital private equity firm last summer. It comes either as an appliance or a VM in a variety of sizes: we tested the smallest version called MAG-2600 which is about the size of a paperback book and can handle up to 250 users. Note this differs from Pulse Connect Secure products, which are SSL VPNs.

Pulse Secure can integrate with a variety of Juniper equipment, including managed switches and unified threat appliances, along with AirWatch and MobileIron mobile device management tools. You can connect Pulse Secure to a variety of authentication sources, including LDAP and RADIUS servers and SiteMinder, as well as Windows and Mac agents. That’s great, but like many of the other products here, getting things setup is a long process, hampered by the use of a variety of Web and command-line user configuration interfaces.

One good thing is that online help was nicely hyperlinked to specific sections in the manuals, which is a plus given that said manuals go for longer than 1,000 printed pages. If you don’t have a lot of Juniper network infrastructure you probably should hold off purchasing this product, although they are working with integrating their NAC with other networking vendors. We did test it with a Cisco low-end managed switch, and once we set up our RADIUS information, it was able to pass 801.X information back to the Pulse Secure.

Agents were optional and we tested the Windows ones to see how they worked. They will report on the security posture of your endpoint and via its host checker tool you can remediate to bring your device into compliance. This involves two steps: manual remediation for adding an anti-virus client (if needed), and automatic remediation for most other activities; these are set via NAC policies.

Pulse Secure accomplished some of our test cases, including the ability to see endpoints that didn’t meet our security policies. However, it fails to recognize VM sessions, and couldn’t determine when a dual network endpoint was attached, although if you run its Windows agent, you can disable the wireless NIC if the wired network is attached.

Reports could be more useful. There are six basic ones that show devices and users but they have the least amount of information of any of the vendors tested. You can download them in CSV format. The log files are so dense that you will quickly make use of the query box to try to find a specific issue, although there are a number of options to cut down on the log messages if you are trying to troubleshoot a specific problem.

The Pulse Secure solution for 500 user licenses lists at $26,000, but discounts can cut this to nearly half this price.

Portnox

The Portnox product consists of software that runs on a Microsoft Windows Server with both Web and native Windows interfaces to manage it. The software installs IIS and SQL Express along with .Net framework, so it is deeply Microsoft-based. We added it to our lab network; Portnox supplied an ESXi server running a series of VMs, both the Windows Server 2008 R2 that ran its own software and several Mac and Windows clients.

+ Portnox NAC offers complete control, including over BYOD and cloud +

We also used a Linksys access point that had been rooted into running PolarCloud’s Tomato firmware so that Portnox could obtain its logs, along with our own unmanaged switches in the lab network. Portnox supports both managed and unmanaged switches and wired and wireless networks and Windows and non-Windows clients (the latter with some limitations).

We had problems with adding our flat, unmanaged network to the test bed, which mirrored a scenario where someone would bring in a small switch or consumer-grade router to work and plug it into the corporate network. Displaying our devices connected to this unmanaged network was less than satisfactory: if you don’t have a very high proportion of managed switches in your environment, this isn’t the product for you. However, Portnox also was one of the best products at figuring out what was on our network. One nice feature is being able to see inside VMware’s vSwitches and operate directly on the virtual ports that makeup that switch fabric. Only Extreme could best this particular feature with support for other hypervisors.

Another nice feature is to be able to search for particular text strings—this can come in handy in very large installations. The strings can be located anywhere, not just in the device name. It comes with two automated tasks, to turn off unused ports every day on a particular schedule and to close ports after they have been inactive for a period of time.

Once we got everything up and running, Portnox was able to figure out all of our use cases with ease, although Extreme had slightly more information about network posture.

There are no agents used, which is impressive given how much information it can collect about the various endpoints and network infrastructure. Instead, Portnox has an interesting “fingerprint” feature where you can build up a profile of particular endpoints, such as IP-connected cameras or printers, to aid in their future discovery and control. The fingerprints are composed of things such as ARP responses, IP address, Mac vendor ID, occupied IP ports, and other information that it figures out. It wasn’t completely flawless: it labeled my Virtual Box sessions as Cadmus Computers, and doesn’t have 10.9 Mac OS listed yet. It also had some bugs when we used Firefox v35 in how endpoint information was displayed. Other browsers worked fine.

Portnox’ user interface could be snappier and clearer. Menus are somewhat confusing, as the active menu choice is placed to the right side of the choices across the top, which is more of a design decision than anything functional. Speaking of design, another poor decision was to bury the view of your entire network in a submenu; other products have this as their default view.

Reports are less than illuminating and more akin to log files. There are about 10 pre-defined ones that come by default, and you can create others. A positive is that there are a variety of export formats including PDF, CSV or as a web page, along with a database interface specification where you can write your own if you are so inclined.

You can create different policies for each vLAN quite easily. The actions on each policy can be to disable a particular port, quarantine it (which Portnox calls “phasing”), run an NMAP scan, or DIY. The latter means you can set up particular workflows that kick off after a port exception pops up, which could be quite powerful if you can figure out the sequence of commands.

The product comes with multiple access roles and the ability to define your own role as well. That is a nice feature, particularly if the administrative duties will be split across different departments.

Portnox charges per port for its product, 500 ports is $13,500.

How we tested NAC products

While we would have liked to use the same network configuration to test all five products, but given their different packaging this wasn’t possible. We began with a small test network that mixed managed and unmanaged switches connecting various Windows and Mac desktops on both wired and wireless networks as a start.

Our tests consisted of adding new endpoint devices of different vintages (such as Windows XP, and old iPhones and Macs running older OS X versions) and using both physical and virtual machines. We then observed what was reported to each NAC, and created and modified policies to force various actions such as quarantining or allowing the device to connect on a limited-access guest network. Under each individual review we note the differences in the actual test network setup.

We scored each product on three metrics:

1)    Endpoint detection

The core of any NAC product is the ability to detect when something is wrong. We looked at the following sample use cases:

  • Can the NAC check for a second (or third) network interface on each endpoint? Can it determine that all interfaces belong to the same endpoint?
  • Can the NAC see who has local admin rights on each endpoint?
  • What happens when a rogue wireless access point connects to your enterprise network?
  • Can the NAC detect when a user brings their personal laptop to work? Does this guest get assigned to the appropriate limited-access network?
  • Does the NAC account for a non-PC endpoint, such as a print server?

2) Reports and auditing

Next, we looked at the usefulness of various logs, auditing tools and reports from each product. We were looking at outright reporting errors, such as misidentifying a machine with the wrong OS, or providing too much or too little information to be actionable. We were also looking for how an enterprise could use these reports for compliance purposes.

3)    Policy creation and management

The last aspect was how easy it was to create and modify policies that focused on both devices and particular end users and how the NAC works with existing security infrastructure such as anti-malware and firewalls. As part of this we looked at ease of installation and configuration. We assumed that these products would be installed in larger networks of several hundred nodes.