Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

NAC vs. NAP

Network access management locks out untrusted end points; Cisco and Microsoft are duking it out over who gets the keys

By Roger A. Grimes
September 05, 2005
 

It all started with the Blaster worm in August 2003. That disastrous epidemic proved once and for all that boundary gateway protection alone is a failed security strategy. Since then, beginning with broader adoption of host-based personal firewalls, vendors have been cooking up host-based schemes to harden the “soft, chewy” center of the network. The most interesting battle over how end-point defense should proceed is between Cisco’s NAC (Network Admission Control) and Microsoft’s NAP (Network Access Protection).

Free IT resource

TechNet: More ways to know it, share it, and keep it running.

Sponsored by Microsoft

Free IT resource

Attend the SOA Executive Forum: Breaking SOA Bottlenecks SOAExecForum.com/may2007

Sponsored by InfoWorld

Return to special report

DOWNLOAD PDF

Click here to download InfoWorld's special report Seven technology battles


Both NAC and NAP fall under the rubric of Network Access Management, aka end-node quarantining, which  assures that computer nodes are securely configured -- with a firewall, anti-virus software, up-to-date patches, and so on -- before they are given normal or continuing access to the network. Otherwise, they’re quarantined.

Cisco currently leads the field with its NAC platform. To work, NAC requires Cisco products. All NAC-compliant end point and application server solutions,    such as anti-virus, firewall, and so on, must communicate with the freely available, often embedded Cisco Trust Agent client software to determine compliance. NAC also requires NAC-aware Cisco network access point equipment and the proprietary Cisco Secure Access Control Server.

Microsoft’s NAP is at an earlier phase. The NAP server will be a core component of future Windows server versions, but cost and licensing has not been decided. NAP requires a NAP server (to be released only on the next server product release), a NAP client (XP Service Pack 2, Vista, or Server 2003), a quarantine server (Microsoft Internet Authentication Services), and one or more policy servers. NAP works by controlling access via DHCP leases, VPN quarantine, 802.1x, or IPSec with x.509 certificates. Although NAP is not yet available outside of beta testing, many vendors have already pledged support.

The risks of choosing one platform over another could be significant. NAC is potentially a more secure solution because end points can be secured at network layer 1 through layer 3, but it requires a Cisco network device (Cisco may eventually allow other network device vendors to join the NAC family). In theory, Cisco can easily extend NAC beyond Microsoft products, but only Windows clients are supported currently.

NAP could debut at minimal cost. Windows XP Service Pack 2, with an update, can be a NAP client. As with Microsoft’s current Network Quarantine Access Control offering, NAP could be offered as a free server component. NAP could come along at no additional cost as customers regularly update their Windows servers. NAP doesn’t require proprietary hardware, but at the same time, that lack of reliance means a slight increase in the possibility of malicious code being transported around a NAP-enabled network than around a network employing Cisco’s solution.

NAC and NAP are in their infancy. Many vendors support both platforms, but most network administrators will be forced to align themselves into one camp or the other to ease central management. Cisco and Microsoft have pledged interoperability and have even licensed each other APIs, but the details are not forthcoming.

During the NAC vs. NAP wars, a third option has emerged: The Trusted Computing Group TNC (Trusted Network Connect) initiative. TNC’s architecture theoretically functions in the same way the other two solutions do but without the proprietary requirements. Microsoft and Cisco have pledged support, but unless customers demand TNC compatibility, why would the two titans expend effort on an initiative that threatens their interests?

Even if you’re not considering a network access management solution now, investments now may well lock you into one scheme or the other in the future.





 


 
InfoWorld Test Center Contributing Editor Roger A. Grimes is a Foundstone Ultimate Hacking instructor/consultant teaching Windows, Linux, Unix, and Solaris security.

  More of Roger A. Grimes' column

Newsletter Check out all of our free newsletters!
Enter e-mail address:




 

TOP NEWS:


»  Update: Online encyclopedia lists internal network security threats
Promisec includes popular Web-based applications among possible data-loss threats

»  Ericsson, STMicro to form mobile chip venture
Joint venture will build guts of mobile devices for current 2G and 3G mobile networks, as well as faster, emerging LTE technology

»  Palm Treo Pro steps into the smartphone ring
Running Windows Mobile 6.1, Palm's newest release will give enterprise users an operating system they are comfortable with

»  Real time drives database virtualization
Database virtualization will enable real-time business intelligence through a memory grid that permeates an infrastructure at all levels

»  IBM commits $300 million to disaster recovery build-out
New datacenters to store data in cloud-based storage model

»  Palm plans to sell unlocked Treo Pro
Palm's decision to sell its newest smartphone could be start of a new trend or a sign of harder times to come for the company




Virtualization: A Step by Step Approach to Success
Your virtual machines can be up and running in a matter of minutes. HP and Citrix have integrated XenServer with HP ProLiant servers and management tools, powered by hardware-assisted Intel Virtualization Technology to enable high- performance, cost-savings solutions for server consolidation and disaster recovery. Sponsor: HP

»  Click here to view this Webcast
  Virtualization Solutions Guide
This comprehensive IT Strategy Guide covers Virtualization and puts you at the forefront of the discussion. You'll learn all you need to know from the cost of virtualization, how to implement it for your business, how to back it up safely and which products are best. Sponsored by Riverbed

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 

FIND PRODUCTS AND COMPANIES
» COMPLETE PRODUCT GUIDE



TECHNOLOGY INDEX
• Applications
• Application Development
• Security
• Networking
• Wireless
• Platforms
• Hardware
• Data Management
• Storage
• Web Services
• Business
• Telecom
• Professional Services
• Standards

TECH WATCH 


What's the 411 on GOOG-411?
Just as Google has become synonymous with "performing a Web search," 411 is understood to mean "information" -- as in "what's the 411?" I was thus surprised to discover, from a billboard, no less, that the king of search is taking on the ...

Apple HTML source reveals 'iPhone Extreme'
"This one's a stretch..." reports AppleInsider. Um, yeah. Reporting on HTML code sightings of product names could be called a stretch, but iPhone Extreme has a ring to it. Now, that sounds like the product Apple should have released first, rather ...

COLUMNISTS

Unified under law
Ephraim Schwartz's Column and Blog (InfoWorld) - In the litigious world we live in, deploying a unified communications platform in your enterprise could...
» MORE COLUMNISTS

MORE INFOWORLD BLOGS


Open Sources 
Product Management
When I joined MySQL four years ago, there was quite a lot of debate about product management. We didn't actually have ...

Zero Day 
Botnet herders tending smaller flocks
New research backs up the theory that botnet operators are keeping their networks smaller in a continued effort to keep ...



• Advice Line
• Database Underground
• The Deep End
• Enterprise Mac
• Geeks in Paradise
• Grid Meter
• The Gripe Line
• InfoWorld Daily
• Inside IT
• IT Troubleshooter
• ITXtreme
• Open Sources
• ProdBlog
• Real World SOA
• Reality Check
• Security Adviser
• SMB IT
• The Storage Network
• Tech Watch
• Virtualization Report
• Zero Day

ADVERTISEMENT


RESOURCE CENTERadvertisement 

GOVERNMENT IT & POLICY
'If you don't go after the network, you're never going to stop these guys. Never.'
From the State Department, All the News for Inquiring Minds
TechPresident, the Internet Citizenry's New Consensus Taker



Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist