University Business - March 2008 - (Page 58)

Network Security Appliance-Based NAC at The University of North Carolina at Chapel Hill THE IT FOLKS AT UNC DESCRIBE NAC AS which provides centralized a logical extension of many things they administration of Trusted Access were already doing—not something Gateways, all switches, all users, they added to solve a certain problem. and all things pushed out to “We’ve been heading toward NAC and control traffic. UNC purchased understood its implications long before 20 Enterasys NAC Trusted Access it ever hit the market,” says Mike Gateway appliances that can talk Hawkins, UNC’s associate director of to 400 to 500 switches on campus. networking. “It’s really identity more The program was deployed in the than anything else—who are you, what late spring and early summer of are you doing nasty, and how can we 2007 across 4,000 switches, which keep you out of the network.” took about three months. UNC’s As a large campus with 28,000 network access control solution Big savings: IT leaders at UNC estimate saving millions of students and 10,000 faculty and dollars with NAC tools, since keeping a network of its size safe cost around $120,000, which staff members, everything runs on covered the Trusted Access Gateway would normally require a much larger staff. the network—door locks, medical appliances. equipment, power devices, vending machines—not just users who Once the hardware was installed, the challenge was touching log in to the network. As a result, the networking group selected every switch and configuring every port a user would be on, Media Access Control (MAC)-based authentication versus 802.1x says Hawkins. Many of UNC’s older generation switches are not authentication because it’s a richer way to get a handle on who is scriptable, so that required manually setting them up rather than on the network. running a script. One component that differentiates access control technologies The results to date have proven extremely successful. Networking is where that control takes place. Different vendors have different folks in the university can pinpoint the exact location of users and types and different places. UNC has NAC at the edge of the network their connection history in less than two minutes, which enables on all switches that users are attached to. UNC to ensure compliance and accelerate the mean time to repair. “If you don’t check at the edge in a big network like ours, They can script and isolate hundreds of users off the network in you risk it getting out of control,” Hawkins says. “It’s actually a less than five minutes, which used to take half a day for the entire design philosophy we had before NAC. I think that’s an important staff in the past. Hawkins believes UNC is way ahead of the curve in criterion if you’re talking about a big network—and one of the big identifying threats on campus and handling them quickly. motivating factors we had for getting network access control.” “I can find devices on my network—at the very edge of my The institution was one of the first beta testers of the hardware network,” Hawkins says. “When I can find devices, I can control and software that make up Enterasys’ NAC solution. The beta and what these devices are doing. Our security folks love this. And by pilot in production led to deployment of NAC Manager Software, the way, I do sleep well at night!” • Disadvantages: This approach adds the additional cost and complexity of installing software and adding another management console, according to Gartner. Resources Bradford Networks, www.bradfordnetworks.com Cisco, www.cisco.com Enterasys, www.enterasys.com ForeScout, www.forescout.com Identity Engines, www.idengines.com Juniper Networks, www.juniper.net Lockdown Networks, www.lockdownnetworks.com Microsoft, www.microsoft.com Mirage Networks, www.miragenetworks.com Nortel Networks, www.nortel.com StillSecure, www.stillsecure.com Sophos, www.sophos.com Symantec, www.symantec.com Trusted Computing Group, www.trustedcomputinggroup.org Vernier Networks, www.verniernetworks.com Network Security Appliance-Based NAC According to the October 2006 Gartner report “Network Access Control Decision Framework,” appliance-based solutions are often the best choice for universities and other “loosely-managed, highly distributed, heterogeneous, budget-constrained environments.” Guest machine access tends to drive the short-term need for NAC in these institutions, and these products can limit exposure with a low-level of investment. A few of the players in this space include ForeScout, Bradford Networks, StillSecure, Mirage Networks, Enterasys, and Lockdown Networks. • Advantages: Appliance-based NAC products offer ease of deployment and potential cost savings over infrastructure-based deployment. • Disadvantages: These solutions can be the least robust and don’t offer as many features, according to industry experts. Vicki Powers is a freelance writer based in Houston who often covers technology issues. 58 | March 2008 Links to additional companies that offer network access control products can be found in the online version of this article. universitybusiness.com http://www.miragenetworks.com http://www.bradfordnetworks.com http://www.cisco.com http://www.nortel.com http://www.enterasys.com http://www.stillsecure.com http://www.forescout.com http://www.sophos.com http://www.idengines.com http://www.symantec.com http://www.juniper.net http://www.trustedcomputinggroup.org http://www.lockdownnetworks.com http://www.verniernetworks.com http://www.microsoft.com http://universitybusiness.com

Table of Contents for the Digital Edition of University Business - March 2008

University Business - March 2008
Contents
College Index
Company Index
Advisory Board
Editor's Note
Stats Watch
Sense of Place
Viewpoint
EduComm Insert
Financial Aid
Money Matters
Human Resources
Higher One Insert
Community College
Cadets on Campus
Keeping an Eye on the Network
Sizing Up Second Life
Endowment Management
What's New
Calendar of Events
End Note

University Business - March 2008

https://www.nxtbook.com/pmg/UB/UB_0520
https://www.nxtbook.com/pmg/UB/UB_0320
https://www.nxtbook.com/pmg/UB/UB_0120
https://www.nxtbook.com/pmg/UB/UB_1119
https://www.nxtbook.com/pmg/UB/UB_1019
https://www.nxtbook.com/pmg/UB/UB_0819
https://www.nxtbook.com/pmg/UB/UB_0719
https://www.nxtbook.com/pmg/UB/UB_0619
https://www.nxtbook.com/pmg/UB/UB_0419
https://www.nxtbook.com/pmg/UB/UB_0319
https://www.nxtbook.com/pmg/UB/UB_0119
https://www.nxtbook.com/pmg/UB/UB_1218
https://www.nxtbook.com/pmg/UB/UB_1118
https://www.nxtbook.com/pmg/UB/UB_1018
https://www.nxtbook.com/pmg/UB/UB_0918
https://www.nxtbook.com/pmg/UB/UB_0818
https://www.nxtbook.com/pmg/UB/UB_0718
https://www.nxtbook.com/pmg/UB/UB_0618
https://www.nxtbook.com/pmg/UB/UB_0518
https://www.nxtbook.com/pmg/UB/UB_0418
https://www.nxtbook.com/pmg/UB/UB_0318
https://www.nxtbook.com/pmg/UB/UB_0218
https://www.nxtbook.com/pmg/UB/UB_0118
https://www.nxtbook.com/pmg/UB/UB_1217
https://www.nxtbook.com/pmg/UB/UB_1117
https://www.nxtbook.com/pmg/UB/UB_1017
https://www.nxtbook.com/pmg/UB/UB_0917
https://www.nxtbook.com/pmg/UB/UB_0817
https://www.nxtbook.com/pmg/UB/UB_0717
https://www.nxtbook.com/pmg/UB/UB_0617
https://www.nxtbook.com/pmg/UB/UB_0517
https://www.nxtbook.com/pmg/UB/UB_0417
https://www.nxtbook.com/pmg/UB/UB_0317
https://www.nxtbook.com/pmg/UB/UB_0217EPUB
https://www.nxtbook.com/pmg/UB/UB_0217
https://www.nxtbook.com/pmg/UB/UB_0117
https://www.nxtbook.com/pmg/UB/UB_1216
https://www.nxtbook.com/pmg/UB/UB_1116
https://www.nxtbook.com/pmg/UB/UB_1016
https://www.nxtbook.com/pmg/UB/UB_0916
https://www.nxtbook.com/pmg/UB/UB_0816
https://www.nxtbook.com/pmg/UB/UB_0816CG
https://www.nxtbook.com/pmg/UB/UB0716
https://www.nxtbook.com/pmg/UB/GlobalSellSheet
https://www.nxtbook.com/pmg/UB/UB_0616
https://www.nxtbook.com/pmg/UB/UB_0516
https://www.nxtbook.com/pmg/UB/UB0416
https://www.nxtbook.com/pmg/UB/UB0316
https://www.nxtbook.com/pmg/UB/UB_0216r2
https://www.nxtbook.com/pmg/UB/UBGuide
https://www.nxtbook.com/pmg/UB/UB0116
https://www.nxtbook.com/pmg/UB/UB
https://www.nxtbook.com/nxtbooks/pmg/ub201511
https://www.nxtbook.com/nxtbooks/pmg/ub201510
https://www.nxtbook.com/nxtbooks/pmg/ub201509
https://www.nxtbook.com/nxtbooks/pmg/ub201508
https://www.nxtbook.com/nxtbooks/pmg/ub201508_ConsultantsGuide
https://www.nxtbook.com/nxtbooks/pmg/ub201507
https://www.nxtbook.com/nxtbooks/pmg/ub201506
https://www.nxtbook.com/nxtbooks/pmg/ub201506_AudioVisualSolutions
https://www.nxtbook.com/nxtbooks/pmg/ub201505
https://www.nxtbook.com/nxtbooks/pmg/ub201504
https://www.nxtbook.com/nxtbooks/pmg/ub201503
https://www.nxtbook.com/nxtbooks/pmg/ub201502
https://www.nxtbook.com/nxtbooks/pmg/ub201501
https://www.nxtbook.com/nxtbooks/pmg/ub201501_FinancialServicesGuide
https://www.nxtbook.com/nxtbooks/pmg/ub201412
https://www.nxtbook.com/nxtbooks/pmg/ub201411
https://www.nxtbook.com/nxtbooks/pmg/ub201410
https://www.nxtbook.com/nxtbooks/pmg/ub201409
https://www.nxtbook.com/nxtbooks/pmg/ub201408
https://www.nxtbook.com/nxtbooks/pmg/ub201408_ConsultantsGuide
https://www.nxtbook.com/nxtbooks/pmg/ub201407
https://www.nxtbook.com/nxtbooks/pmg/ub201406
https://www.nxtbook.com/nxtbooks/pmg/ub201406_AudioVisualSolutions
https://www.nxtbook.com/nxtbooks/pmg/ub201405
https://www.nxtbook.com/nxtbooks/pmg/ub201404
https://www.nxtbook.com/nxtbooks/pmg/ub201403
https://www.nxtbook.com/nxtbooks/pmg/ub201402
https://www.nxtbook.com/nxtbooks/pmg/ub201401
https://www.nxtbook.com/nxtbooks/pmg/ub201401_FinancialServicesGuide
https://www.nxtbook.com/nxtbooks/pmg/ub201312
https://www.nxtbook.com/nxtbooks/pmg/ub201311
https://www.nxtbook.com/nxtbooks/pmg/ub201310
https://www.nxtbook.com/nxtbooks/pmg/ub201309
https://www.nxtbook.com/nxtbooks/pmg/ub201308
https://www.nxtbook.com/nxtbooks/pmg/ub201308_ConsultantsGuide
https://www.nxtbook.com/nxtbooks/pmg/ub201307
https://www.nxtbook.com/nxtbooks/pmg/ub201306_AudioVisualSolutions
https://www.nxtbook.com/nxtbooks/pmg/ub201306
https://www.nxtbook.com/nxtbooks/pmg/ub201305
https://www.nxtbook.com/nxtbooks/pmg/ub201304
https://www.nxtbook.com/nxtbooks/pmg/ub201303
https://www.nxtbook.com/nxtbooks/pmg/ub201302
https://www.nxtbook.com/nxtbooks/pmg/ub201301
https://www.nxtbook.com/nxtbooks/pmg/ub201301_FinancialServicesGuide
https://www.nxtbook.com/nxtbooks/pmg/ub1212
https://www.nxtbook.com/nxtbooks/pmg/ub1112
https://www.nxtbook.com/nxtbooks/pmg/ub1012
https://www.nxtbook.com/nxtbooks/pmg/ub0912
https://www.nxtbook.com/nxtbooks/pmg/ub_cg12
https://www.nxtbook.com/nxtbooks/pmg/ub070812
https://www.nxtbook.com/nxtbooks/pmg/ub0612
https://www.nxtbook.com/nxtbooks/pmg/ub_avguide0612
https://www.nxtbook.com/nxtbooks/pmg/ub0512
https://www.nxtbook.com/nxtbooks/pmg/ub0412
https://www.nxtbook.com/nxtbooks/pmg/ub0312
https://www.nxtbook.com/nxtbooks/pmg/ub0212
https://www.nxtbook.com/nxtbooks/pmg/ub_financeguide0112
https://www.nxtbook.com/nxtbooks/pmg/ub1211
https://www.nxtbook.com/nxtbooks/pmg/ub1011
https://www.nxtbook.com/nxtbooks/pmg/ub0911
https://www.nxtbook.com/nxtbooks/pmg/ub_cg11
https://www.nxtbook.com/nxtbooks/pmg/ub0711
https://www.nxtbook.com/nxtbooks/pmg/ub0611_av
https://www.nxtbook.com/nxtbooks/pmg/ub0611
https://www.nxtbook.com/nxtbooks/pmg/ub0511
https://www.nxtbook.com/nxtbooks/pmg/ub0411
https://www.nxtbook.com/nxtbooks/pmg/ub0311
https://www.nxtbook.com/nxtbooks/pmg/ub0211
https://www.nxtbook.com/nxtbooks/pmg/ub0111
https://www.nxtbook.com/nxtbooks/pmg/ub_financeguide0111
https://www.nxtbook.com/nxtbooks/pmg/ub1110
https://www.nxtbook.com/nxtbooks/pmg/ub1010
https://www.nxtbook.com/nxtbooks/pmg/ub0910
https://www.nxtbook.com/nxtbooks/pmg/ub_2010financeguide
https://www.nxtbook.com/nxtbooks/pmg/ub_2010consultants
https://www.nxtbook.com/nxtbooks/pmg/ub_2010avguide
https://www.nxtbook.com/nxtbooks/pmg/ub0710
https://www.nxtbook.com/nxtbooks/pmg/ub0610
https://www.nxtbook.com/nxtbooks/pmg/ub0510
https://www.nxtbook.com/nxtbooks/pmg/ub0410
https://www.nxtbook.com/nxtbooks/pmg/ub0310
https://www.nxtbook.com/nxtbooks/pmg/ub0210
https://www.nxtbook.com/nxtbooks/pmg/ub0110
https://www.nxtbook.com/nxtbooks/pmg/ub1109
https://www.nxtbook.com/nxtbooks/pmg/ub1009
https://www.nxtbook.com/nxtbooks/pmg/ub0909
https://www.nxtbook.com/nxtbooks/pmg/ub0709
https://www.nxtbook.com/nxtbooks/pmg/ub_fg09
https://www.nxtbook.com/nxtbooks/pmg/ub0609
https://www.nxtbook.com/nxtbooks/pmg/ub0509
https://www.nxtbook.com/nxtbooks/pmg/ub0409
https://www.nxtbook.com/nxtbooks/pmg/ub0309
https://www.nxtbook.com/nxtbooks/pmg/ub0209
https://www.nxtbook.com/nxtbooks/pmg/ub0109
https://www.nxtbook.com/nxtbooks/pmg/ub1208
https://www.nxtbook.com/nxtbooks/pmg/ub1108
https://www.nxtbook.com/nxtbooks/pmg/ub1008
https://www.nxtbook.com/nxtbooks/pmg/ub0908
https://www.nxtbook.com/nxtbooks/pmg/ub0808
https://www.nxtbook.com/nxtbooks/pmg/ub0708
https://www.nxtbook.com/nxtbooks/pmg/ub0608
https://www.nxtbook.com/nxtbooks/pmg/ub0508
https://www.nxtbook.com/nxtbooks/pmg/ub0408
https://www.nxtbook.com/nxtbooks/pmg/ub0308
https://www.nxtbook.com/nxtbooks/pmg/ub0208
https://www.nxtbook.com/nxtbooks/pmg/ub0907
https://www.nxtbook.com/nxtbooks/pmg/ub0807
https://www.nxtbook.com/nxtbooks/pmg/ub0707
https://www.nxtbook.com/nxtbooks/pmg/ub0607
https://www.nxtbook.com/nxtbooks/pmg/ub0507
https://www.nxtbook.com/nxtbooks/pmg/ub0407
https://www.nxtbook.com/nxtbooks/pmg/ub0307
https://www.nxtbook.com/nxtbooks/pmg/ub0207
https://www.nxtbook.com/nxtbooks/pmg/ub0107
https://www.nxtbook.com/nxtbooks/pmg/ub1206
https://www.nxtbook.com/nxtbooks/pmg/ub1106
https://www.nxtbook.com/nxtbooks/pmg/ub1006
https://www.nxtbook.com/nxtbooks/pmg/ub0906
https://www.nxtbook.com/nxtbooks/pmg/ub0806
https://www.nxtbook.com/nxtbooks/pmg/ub0706
https://www.nxtbook.com/nxtbooks/pmg/ub0606-GG
https://www.nxtbook.com/nxtbooks/pmg/ub0606
https://www.nxtbook.com/nxtbooks/pmg/ub0506
https://www.nxtbook.com/nxtbooks/pmg/ub0406
https://www.nxtbookmedia.com