Alan Stevens

Is NAC a solution looking for a problem?

Network access control is laudable but it adds further complexity and cost to firms’ security measures

Written by Alan Stevens

I attended a Microsoft briefing recently that showcased the vendor’s new Network Access Protection (NAP) technology due to be included in Windows Server 2008. I wasn’t impressed. Furthermore, I couldn’t help but wonder whether it was something customers wanted or just another solution searching for a problem.

What Microsoft refers to as NAP others tend to call network access control (NAC). Whatever the name, however, the aims are the same, the idea being to check the “health” of client systems before they’re allowed a network connection. Those that don’t match a basic minimum security profile – in terms of installed patches, firewall setup, antivirus protection and so on – are then either quarantined or have the requisite elements updated before being allowed access.

NAC is all very laudable but it’s not an easy concept to deploy, requiring major network infrastructure changes, which can be both hugely expensive and disruptive. In the case of NAP, you have to deploy additional health validation and remediation servers – running Windows Server 2008 – plus an agent on each PC, which is included in Vista but extra for XP. NAP software only provides a basic security framework, and Microsoft is expecting third parties to supply plug-ins to provide the really detailed functionality.

These third-party add-ins look to be really crucial, a point brought home in the Microsoft demo I saw. For example, we were shown how NAP could be configured to check for the presence of the Windows firewall before allowing clients onto the LAN – the NAP software automatically turning the firewall back on if it had been disabled. What you couldn’t do, however, was get the software to drill down any deeper to check up on how the firewall was configured, leaving open the possibility that users could still configure exception rules to let traffic through.

Of course, third-party security vendors will want to be part of the NAP party, but that will take time. Also most have their own take on NAP/NAC, and products to sell, which could limit what they’re prepared to support.

One final thought. In the past few years companies have already become accustomed to taking pre-emptive measures to make sure clients are properly configured. As such, most have tools and procedures in place to ensure antivirus software is installed and up to date, firewalls are correctly configured and suchlike, in which case another layer of protection (and complexity) could be seen as superfluous. OK, it helps automate the process, but at a cost, and I wonder whether NAC will make it to the mainstream.

Tags:

reader comments

related articles

 

GroundWork aims at enterprise network monitoring

Open source monitoring firm launches enterprise grade products 26 Mar 2008

Network Instruments touts nanosecond apps troubleshooting

Observer 13 offers upgraded performance and forensic network analysis 14 Oct 2008

Spammers exploit heightened interest in the economy and US election

Attackers are increasingly using legitimate sites to host their malware 27 Oct 2008

related whitepapers

today's top stories

CIOs must embrace collaboration tools

Author Don Tapscott gives Angelica Mari his reasons for promoting social networking tools and says transparency is the key to security 04 Dec 2008

On a quest to build a connected society

BT Design’s JP Rangaswami talks to Gareth Morgan about his pivotal role in the telecoms giant’s efforts to deliver universal broadband and his plans to tap into the creativity of the open source community 04 Dec 2008

IT leaders must stand by India

A sense of perspective is the most important response from IT leaders to the attacks in Mumbai 04 Dec 2008

Case study: Clifford Chance

Law firm implements Sun platform and reduces datacentres to gain efficiency and cost synergies 03 Dec 2008

Should CRM be more sociable?

As vendors rush to add more social networking bells and whistles to their CRM products, some experts warn that users must tread carefully when venturing into online communities 03 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Doctors looking at a computerAnalysis

Watchdog wants IT to cure privacy woes

Information Commissioner Richard Thomas is urging organisations to put privacy protection at the top of their procurement and development criteria 04 Dec 2008

Colin McDonaldComment

Web 2.0 has potential to transform staff training

Employees can sharpen their IT skills through using the latest interactive training tools, writes Colin McDonald 04 Dec 2008

Advertisement

Primary Navigation