Software-based NAC security useful despite drawbacks

NAC price, scalability and reporting are all strong points

Despite some shortcomings, software-based network access control technology that enforces policies on network endpoints is often the first choice of customers who adopt the technology.

NAC endpoint client, minimizing the training and investment required, they say.

For example, Hidalgo County, Texas, looked into a Cisco NAC appliance deployment to solve its endpoint-compliance problems, says Renan Ramirez, the county's CIO. "The Cisco solution was going to cost six figures," he says, but the county chose a Sophos NAC, which cost about US$50,000.

The county was already about to buy Sophos antivirus software and the incremental cost of NAC made it worthwhile, he says. "Cost overrules everything," Ramirez says.

Ramirez and other potential customers have three basic options when picking NAC products, and endpoint-based NAC is one of them. The other two are infrastructure-based that uses switches to enforce policies, and appliance-based using a dedicated appliance to enforce policies (perhaps in conjunction with other network elements).

Each has its shortcomings. For example, NAC products that enforce policies via Dynamic Host Configuration Protocol (DHCP) proxy servers do nothing to stop machines that obtain static IP addresses and don't use DHCP to make their network connections. That makes significant portions of corporate networks invisible to the NAC access control products, says Ofir Arkin, CTO of NAC vendor Insightix. He is the author of a paper outlining NAC flaws.

Every customer must decide which architecture is best for them, says Rob Whiteley, an analyst with Forrester Research. "There is no one-size-fits-all," he says.

The upside of NAC that uses endpoint software to enforce policies is that it can provide comprehensive data about the endpoint as well as a remediation mechanism when the NAC agent is part of an endpoint security suite. It also gathers a wealth of data that can be used to prove to regulators that industry or governmental policies have been upheld.

The major downside to endpoint-enforced NAC is largely theoretical so far and one that customers seem willing to overlook. The problem is that rootkits can take over machines to make them lie about their health. This underlying endpoint problem can be mitigated by software that monitors behavior of machines to determine if they are acting badly. And lying endpoints haven't actually proven a problem for many customers.

More about: Billion, Cisco, Core Networks, EndPoints, Forrester Research, Insightix, Intelsat, IPS, McAfee, McAfee.com, Sophos, Symantec, VIA
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the Computerworld comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: nac
Whitepapers
All whitepapers
Sign up now to get free exclusive access to reports, research and invitation only events.
Featured Download
/downloads/product/170/gadwin-geforms/

Gadwin GeForms

GeForms allows you to create your own forms or fill in existing forms electronically. Using GeForms you are provided with sophisticated form design tools which ...

Computerworld newsletter

Join the most dedicated community for IT managers, leaders and professionals in Australia