October 03, 2005

Policy-based access control, no agents

ConSentry's Secure LAN Controllers enforce access control policies from the wiring closet

Endpoint security solutions from vendors such as Check Point and Sygate protect the company LAN from unauthorized users and infected clients, using a combination of client-side agents and a central management server. Now available from ConSentry Networks is a hardware-based, transparent system for monitoring and managing user access that installs in the wiring closet and requires no client software.

ConSentry’s Secure LAN Controllers are based on what the company calls its LANShield Silicon Architecture, which consists of custom traffic processing ASICs that allow incredible real-time views into network traffic. Packets are decoded from Layer 4 all the way to Layer 7, allowing IT to truly “see” what network users are doing. During a recent demonstration, I was able to view both historical and real-time traffic for a single user and also a group of users. From the protocols used to the applications launched to the Web sites accessed, everything was laid out in report form.

The Secure LAN Controller is available in two models. The CS1000 comes with 10 ports and can handle as many as 200 users and 2Gbps of traffic; the CS2400 comes with 24 ports and scales to 1,000 users and 10Gbps. The controllers install transparently between workgroup switches and the core backbone switches. 

Creating policies and generating reports is the job of the Java-based management tool ConSentry InSight. InSight hooks into existing Active Directory or RADIUS to extract user and group information. Policies are defined based on group affinity, then pushed to the Controller for enforcement. It’s a powerful way to ensure users are obeying the rules.

ConSentry Secure LAN Controller
ConSentry Networks
Cost: $17,995 for CS1000; $27,995 for CS2400
Available: Now


Keith Schultz is contributing editor of the InfoWorld Test Center.
Close

On Twitter now

Networking

Powered by Twitter

On Twitter now

White Paper

D2D Virtual Tape Library Replication Primer

This whitepaper explains the terminology and concepts behind Data Replication technologies and establishes some sizing rules through worked examples. Learn the new paradigm in disaster tolerance—protect data anywhere.

Download now »

White Paper

An Alternative to Virtualization for Datacenter Cost Savings

Server virtualization is a popular option for dealing with mounting datacenter costs. Another equally promising approach is the use of an Application Delivery Controller. Citrix NetScaler provides a low-cost way for organizations to reduce their server count and accrue cost savings from a reduction in space, cooling, power and personnel.

Download now »

White Paper

Why Your Firewall, VPN, and IEEE 802.11i Aren't Enough to Protect Your Network

The emergence of WLANs has created a new breed of security threats to enterprise networks.

Included in HP ProCurve WLAN solutions is security technology that alleviates threats from WLANs through:
* Monitoring wireless activity inside and out of the enterprise
* Classifying WLAN transmissions into harmful and harmless
* Preventing transmissions that pose a security threat to the enterprise network
* Locating participating devices for physical remediation

Download now »

White Paper

Bringing the Edge to the Data Center

Effectively address data protection challenges, implementing solutions that help store and protect business–critical data while cutting costs and improving efficiency and reliability.

Download now »

Sign up to receive Networking Resource Alerts

Subscribe to the Technology: Networking Newsletter

The one-stop resource center for IT professionals.

©1994-2009 Infoworld, Inc.