Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

NAC smorgasbord: Four ways to police the network

Enterasys, McAfee, Symantec, and Trend Micro take myriad routes to policy-based access control


The switch policies also allowed us to limit the traffic both to and from the attached devices on each port, and the TAM could optionally force a vulnerability assessment scan of the device using Nessus.


Using either VLAN assignment or port policies, the Sentinel system can appropriately limit access of the client systems based on both the identity of the user and the posture of the system. Using the network IDS to detect changes in traffic to or from a client, Sentinel could even trigger changes to the network configuration in response -- a great asset for larger organizations defending against zero-day attacks.

Furthermore, the port-level policies allowed us to configure ports to permit only the traffic that made sense for each user and device. For example, telephones could talk only to the call manager, and guests could access the Internet only on certain ports. We could also lock down the network using predefined policies based on user identity, effectively ensuring that only appropriate traffic could be sent or received.

On the downside, the policy configuration for Sentinel was quite complex, especially since it crossed the boundaries of multiple products. But once the general concepts were stored in the system, creating new policies was typically a matter of duplicating other policies and modifying the specific protocols, networks, and other traffic limitations for each policy. And in this case, the extra effort can pay off. Per-port policies are powerful, providing an extra level of protection that’s attractive in these days of nasty network surprises.

McAfee Policy Enforcer 2.0

06TCMcAfee.gif
Click for larger view.
McAfee Policy Enforcer (MPE) 2.0 is a policy management product that integrates with McAfee’s anti-virus agent and (perhaps surprisingly) other anti-virus products. A free add-on to McAfee ePolicy Orchestrator (EPO), MPE is both the user interface for configuring and managing access policies and the enforcement decision-maker. It uses EPO as the control agent for deployment, updates, notification, and other management tasks.

MPE provides an effective visual summary of the current status of compliance by systems, subnets, and switches. It allows an administrator to drill into the details but provides a color-coded picture of the current state of the environment. The system represents an intuitive and highly visual view into the compliance status of the network.

Based on host posture, the system uses VLAN assignment to move hosts onto appropriate VLANs for remediation or quarantine. The system is unique in this roundup in that it does not depend on McAfee hardware or agents. MPE can gather posture information through an amazing variety of agents, including all the leading anti-virus clients, and it handles agentless systems through guest access policies.

Steve Hultquist is a contributing editor of the InfoWorld Test Center.
Continued
« PREVIOUS PAGE | 1 | 2 | 3 | 4 | 5 | 6 | 7 | NEXT PAGE » 

 The Bottom Line

Sentinel Trusted Access 1.1
Enterasys Networks, enterasys.com

Good  7.7
criteria score weight
Manageability 7 20%
Policy Enforcement 9 20%
Scalability 9 20%
Reporting 7 15%
Setup 7 15%
Value 6 10%

Cost:
$36,000 for NAC and policy components; $125,000 for optional intrusion defense

Bottom Line:
Enterasys’ comprehensive NAC offering gives enterprises the ability to develop finely tuned policies and enforce them. The broad scope has led to some unnecessary complexity in the administrative interfaces, but integration with the Enterasys switches allows deep knowledge of network traffic to be leveraged as a component of policies.

About our Reviews and Scoring Methodology

 The Bottom Line

McAfee Policy Enforcer 2.0
McAfee, mcafee.com

Good  7.8
criteria score weight
Manageability 8 20%
Policy Enforcement 7 20%
Scalability 7 20%
Reporting 9 15%
Setup 8 15%
Value 8 10%

Cost:
$30 per host for 501 hosts

Bottom Line:
McAfee has developed a largely vendor-neutral policy enforcement product as an add-on to the company’s policy management platform. Sporting a well-designed user interface and a broad range of pre-defined policies, Policy Enforcer is a good choice for enterprises not requiring policies that rely on individual user identity or group membership.

About our Reviews and Scoring Methodology

 The Bottom Line

Symantec Network Access Control 5.1 MR2
Symantec, symantec.com

Good  7.6
criteria score weight
Manageability 7 20%
Policy Enforcement 8 20%
Scalability 8 20%
Reporting 7 15%
Setup 8 15%
Value 7 10%

Cost:
$18,000 for 1000user installation with the LAN Enforcement option and one Enforcer appliance

Bottom Line:
Symantec’s comprehensive suite supports multiple approaches to detection and enforcement. The user interface paradigm is somewhat difficult to learn, so infrequent use could lead to challenges in defining new policies or modifying current ones. Support for gateway and non-gateway enforcement expands the options for solution design.

About our Reviews and Scoring Methodology

 The Bottom Line

Trend Micro Network VirusWall Enforcer v2.0
Trend Micro, trendmicro.com

Good  7.8
criteria score weight
Manageability 8 20%
Policy Enforcement 8 20%
Scalability 7 20%
Reporting 8 15%
Setup 8 15%
Value 8 10%

Cost:
14,995 for 250 users including Trend Micro Control Manager

Bottom Line:
Trend Micro’s solution provides comprehensive traffic-based policy management in addition to standard network access approval or rejection. The limitations are those inherent in gateway solutions, including requirements on where enforcers are placed into the network and the inability to enforce policy on traffic that does not pass through them.

About our Reviews and Scoring Methodology


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





Take control of your content- leverage Microsoft SharePoint
Microsoft Office SharePoint Server (MOSS) offers core content management designed for a broad user population. Attend this webcast to learn how to implement a strategy that allows for the coexistence of both MOSS and advanced ECM solution within the same IT environment. Sponsor: IBM

»  Click here to view this Webcast
  Virtualization Solutions Guide
This comprehensive IT Strategy Guide covers Virtualization and puts you at the forefront of the discussion. You'll learn all you need to know from the cost of virtualization, how to implement it for your business, how to back it up safely and which products are best. Sponsored by Riverbed

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 09/04/2008

Sony recalls 73,000 laptops, Google to rework Chrome license after users...

 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist