RSS

NAC Panel Discussion: What is the state of NAC?

Wed, Oct 29, 2008

NAC

This morning at work I moderated a panel discussion on Network Access Control. The audience was made up of IT Security staff from several research and development organizations. There were representatives from 3 vendors in attendance as well. The audience represented a good cross section of NAC adopters. Some have had it for 2 years, some deploying this year while others had future or no plans to deploy NAC.

There was good audience participation so I only had to pull out 1 or 2 “canned” questions in the time allotted. I’ve tried to summarize the points and information that we learned from this exercise below. These are in no particular order.

1. No clear definition of NAC
One of the first questions from the audience was about barriers to NAC adoption. One of the vendors replied with the question “what does NAC mean to you?” This person wanted NAC to do machine based authentication with no posture assessment. The next speaker wanted user authentication and posture assessment. A third was looking for post-connect NAC, *cough* IPS *cough*. Yet another wanted machine based authentication followed by user authentication. There was also discussion of machine provisioning on the network based on an HR event. As we have heard before, the definition of NAC is a moving target.

2. Lack of executive buy-in kills
No big revelation here. Without proper senior management participation, understanding and approval almost any initiative will fail. What is interesting is the fact that within this group the challenge of selling NAC to upper management seemed to be more of a barrier to deployment than cost or complexity, the ones usually cited. My guess is that NAC may be an organizational or cultural challenge that is more common in “academic” environments where people may be used to doing what they want with less oversight. That is just a guess on my part. Cost was not mentioned once as an issue.

3. 802.1x is still a long way out for wired deployments
Most security professionals will agree that 802.1x authentication is the preferred enforcement mechanism for NAC. IP’s can be changed, MAC’s can be spoofed but digital certificates pose a formidable challenge to forge. All 3 vendors said that in their experience 90% of wireless NAC deployments use 802.1x. The reason cited was ease of configuration on the client side and general wider acceptance of the protocol. On the wired side that equation was reversed with only 10% deploying 802.1x. Supplicant issues and the prevalence of devices that may not be able to have a supplicant (printers, VOIP phones, etc.) were said to be big issues.

4. Support for non-Windows clients still developing
The majority of the audience organizations have significant numbers of non-Windows clients, specifically Mac’s. We get it. Windows is on 90 something percent of the enterprise desktops. That number is changing. More and more companies are offering choices on the desktop / laptop. The NAC vendors present had different levels of support for non-Windows. Some could do authentication only and some could do posture checking if the NAC device was in-line. Note to NAC vendors: Mac support is not a nice to have any more. Mac will have an ever increasing presence on the desktop. The NAC options should be the same for Windows and non-Windows. I do recognize that Linux is a little more of a challenge due to the variants and much further behind Mac in the desktop OS race.

Some of the other take-aways were:
Make sure you have an accurate inventory of network connected devices
Do not underestimate the increased help desk utilization
Automated remediation is not as common as self-remediation in deployments

Those were the ones worth mentioning. Let me know if any of these jump out at you.

–Chris

Technorati Tags: ,

Print Friendly
, , ,

This post was written by:

- who has written 180 posts on InfoSecPodcast.com.


Contact the author

6 Comments For This Post

  1. alan shimel Says:

    Chris – I am crushed! You had a NAC panel and discussion and didn't even invite me? Whats up with that! I hope you have a good excuse

    alan

    Like or Dislike: Thumb up 0 Thumb down 0

  2. Chris Harrington Says:

    Alan,

    Nothing personal. Sometimes you have to work with what you are handed :) I would like to have had a little more involvement in that piece of the process. It would have been good to have you and your perspective there.

    –Chris

    Like or Dislike: Thumb up 0 Thumb down 0

  3. chrisb Says:

    I was lurking in the audience at this discussion. There were some questions asked of the audience that I found interesting. When asked how many were planning to roll out NAC, I saw two or three hands. When asked how many were planning to roll out 802.1X, I saw none. Which means, either they already rolled out .1X (doubtful) or they plan on doing NAC without it.

    Sorry I did not get a chance to come and meet you in person, I did not stay through the end.

    Like or Dislike: Thumb up 0 Thumb down 0

  4. Chris Harrington Says:

    Hi Chris,

    Thanks for the comment. I think you may be thinking of a different discussion. This was a closed door meeting at a federal facility with only 3 vendors in attendance. You are correct in that few are doing .1x. Nobody in this meeting were using it on the wired and about 1/3 were using it on wireless.

    –Chris

    Like or Dislike: Thumb up 0 Thumb down 0

  5. chrisb Says:

    heh, indeed you are right.

    Well, I guess it is a good sign when there are two NAC panels taking place on the same day…

    Like or Dislike: Thumb up 0 Thumb down 0

  6. Matt Says:

    Paul Roberts of The 451 Group is doing a webinar next week on "What's New, What's Next in NAC?" Subject will include what's new and what's next in the network access control (NAC) market?

    Do you wonder if Cisco, Microsoft, Juniper and Symantec are delivering on their NAC promise? Or if NAC appliances are finding more "traction" than framework, software or virtual solutions?

    Register to attend – http://tinyurl.com/6p9n5p

    Live Webinar: What's New, What's Next in NAC?

    Date: Tuesday, May 19, 2009

    Time: 8:00AM(PST), 11:00AM (EST)

    Presented by: Gord Boyce, President, ForeScout Technologies and Paul Roberts, Senior Analyst/Enterprise Security, The 451 Group

    Like or Dislike: Thumb up 0 Thumb down 0

Leave a Reply

Bad Behavior has blocked 1577 access attempts in the last 7 days.

Rodney's 404 Handler Plugin plugged in.