Free Newsletters
Technology & Business Daily

InfoWorld
Log-in | Register

NAC smorgasbord: Four ways to police the network

Enterasys, McAfee, Symantec, and Trend Micro take myriad routes to policy-based access control


For this test, the LAN Enforcer was set up as a device on the network, while we directed traffic between an edge switch and the core via the Gateway Enforcer. The Gateway Enforcer is the primary method for controlling guest access in the Symantec Network Access Control system.


06TCSymantec.gif
Click for larger view.
Policies are configured through the Symantec Policy Management Console, a Java client running on Windows Server 2003 that communicates to the Enforcers. In the Policy Management Console, you create policies in a policy library, which divides them into firewall policies, host integrity policies, and OS protection policies.

Firewall policies are the specific connections that are allowed or disallowed based on host posture or packet inspection. For example, you could create a policy that specified, except for specific developer workstations, only port-80 traffic is allowed from all desktops to your intranet Web server.

Host integrity policies protect the host system from attack by making sure the required security applications are up-to-date and running properly; OS protection policies define the applications allowed to run on the system.

Administrators create new policies using a wizard-based interface in the Policy Management Console, by copying another policy and editing it, or by filling in a blank policy template from scratch. The policy list allows for the editing of the major policy fields through pull-downs on the screen -- a nice touch for quickly viewing options and making changes while being certain that you are choosing viable options.

Rules are defined separately from the policies and, thus, made available to the policy editor. So, for example, an “Allow VPN” rule can be applied or disabled for any of the policies independently but is easily visible when editing the policies. Rules are created, edited, and deleted from within the policy editor.

Once policies are created in the policy library, you assign them to locations where they will be applied. Within each location, the system administers policies based on user authentication status, host integrity status, and applications running on the host.

Policy enforcement is dependent upon the type of Enforcer in use. When configuring switches for the LAN Enforcer, the switch profiles include the VLANs and the VLAN assignment based on authentication status of both the host and the user as well as whether or not the system profile passed. Any combination of pass/fail for these states can cause a VLAN assignment.

Because the Gateway Enforcer manages traffic through inline filtering, and can make decisions based on active traffic, it provides more control than VLAN assignment. For example, the Gateway can detect changes in traffic patterns that could indicate a zero-day infection and isolate the traffic to keep it from spreading.

SNAC conquered all the scenarios we expected it to handle, but like McAfee Policy Enforcer, it does not support policy variation by authentication parameters such as user name or user group. It is not possible to assign policies based on those characteristics. It is, however, possible to assign policies based on whether or not the client passed authentication.

Steve Hultquist is a contributing editor of the InfoWorld Test Center.
Continued
« PREVIOUS PAGE | 1 | 2 | 3 | 4 | 5 | 6 | 7 | NEXT PAGE » 

 The Bottom Line

Sentinel Trusted Access 1.1
Enterasys Networks, enterasys.com

Good  7.7
criteria score weight
Manageability 7 20%
Policy Enforcement 9 20%
Scalability 9 20%
Reporting 7 15%
Setup 7 15%
Value 6 10%

Cost:
$36,000 for NAC and policy components; $125,000 for optional intrusion defense

Bottom Line:
Enterasys’ comprehensive NAC offering gives enterprises the ability to develop finely tuned policies and enforce them. The broad scope has led to some unnecessary complexity in the administrative interfaces, but integration with the Enterasys switches allows deep knowledge of network traffic to be leveraged as a component of policies.

About our Reviews and Scoring Methodology

 The Bottom Line

McAfee Policy Enforcer 2.0
McAfee, mcafee.com

Good  7.8
criteria score weight
Manageability 8 20%
Policy Enforcement 7 20%
Scalability 7 20%
Reporting 9 15%
Setup 8 15%
Value 8 10%

Cost:
$30 per host for 501 hosts

Bottom Line:
McAfee has developed a largely vendor-neutral policy enforcement product as an add-on to the company’s policy management platform. Sporting a well-designed user interface and a broad range of pre-defined policies, Policy Enforcer is a good choice for enterprises not requiring policies that rely on individual user identity or group membership.

About our Reviews and Scoring Methodology

 The Bottom Line

Symantec Network Access Control 5.1 MR2
Symantec, symantec.com

Good  7.6
criteria score weight
Manageability 7 20%
Policy Enforcement 8 20%
Scalability 8 20%
Reporting 7 15%
Setup 8 15%
Value 7 10%

Cost:
$18,000 for 1000user installation with the LAN Enforcement option and one Enforcer appliance

Bottom Line:
Symantec’s comprehensive suite supports multiple approaches to detection and enforcement. The user interface paradigm is somewhat difficult to learn, so infrequent use could lead to challenges in defining new policies or modifying current ones. Support for gateway and non-gateway enforcement expands the options for solution design.

About our Reviews and Scoring Methodology

 The Bottom Line

Trend Micro Network VirusWall Enforcer v2.0
Trend Micro, trendmicro.com

Good  7.8
criteria score weight
Manageability 8 20%
Policy Enforcement 8 20%
Scalability 7 20%
Reporting 8 15%
Setup 8 15%
Value 8 10%

Cost:
14,995 for 250 users including Trend Micro Control Manager

Bottom Line:
Trend Micro’s solution provides comprehensive traffic-based policy management in addition to standard network access approval or rejection. The limitations are those inherent in gateway solutions, including requirements on where enforcers are placed into the network and the inability to enforce policy on traffic that does not pass through them.

About our Reviews and Scoring Methodology


Talkback:

commentPost a Comment

 

MOST COMMENTS

 
 





What Every Enterprise Needs to Know About VDI
Today's enterprise IT environment is already complex, and replete with heterogeneous technologies. Attend this informative webcast to understand the key components for deploying and managing virtual desktop infrastructure in your environment. Sponsor: VDIworks

»  Click here to view this Webcast
  Planning For A Disaster
This new, comprehensive Solutions Guide is your one stop source for Disaster Recovery. In it you'll learn how to reduce the likelihood of a disaster and to create a rock solid business continuity plan should you face a disaster situation. Sponsored by Equallogic

»  Click here to download now

- Special Advertising Partners -
WHITE PAPERS
 

» Technology White Papers Library

Technology White Papers by Topic

Technology White Papers E-mail Alert

Find out when the latest white paper is available:
 
 
INFOWORLD MARKETPLACE
 
» BUY A LINK NOW
 
 

Video

 
 
 

Podcasts

 
IFW Daily 09/04/2008

Sony recalls 73,000 laptops, Google to rework Chrome license after users...

 
 

 

Columnists

 
 
 

Resource Center


Ads by techwords beta  [See your link here]
 




Sponsored Technology Links

 
 
 HOME  NEWS  BLOGS  PODCASTS  VIDEOS  TECHNOLOGIES  TEST CENTER  EVENTS  CAREERS   About | Advertise | Awards | RSS | Contact Us 

Copyright © 2008, Reprints, Permissions, Licensing, IDG Network, Privacy Policy, Terms of Service.
All Rights reserved. InfoWorld is a leading publisher of technology information and product reviews on topics including viruses,
phishing, worms, firewalls, security, servers, storage, networking, wireless, databases, and web services.

CIO :: ComputerWorld :: CSO :: Demo :: GamePro :: Games.net :: IDG Connect :: IDG World Expo
Industry Standard :: IT World :: JavaWorld :: LinuxWorld :: MacUser :: Macworld :: Network World :: PC World :: Playlist