Another view on the NAC/NAP announcement
Jon Oltsik from the Enterprise Strategy Group has an excellent article up on the C/Net Corporate Security Blog, that has another view on this. Basically, Jon says that both the MS and Cisco approaches are proprietary and that they had to do something to justify them co-opting an industry wide effort. Jon says that what Cisco and MS are doing under the guise of support for IEEE 802.1x support is vintage behavior from these two. They are taking legitimate standards and under an "open" smokescreen are hiding their efforts to "embrace and extend" the client code until it is no longer the industry standard it is supposed to be. Jon calls for both Cisco and MS to work with the TNC/TCG standard (which to be fair MS has said they will support). He points out Cisco claims they don't work with industry consortiums on standards, but catches them red handed in regard to their participation in SNIA another industry consortium on standards. These are all dead on and good points by Jon. I think his best point though is that this whole thing only applies to Cisco only networks and MS only computers. In todays wired/wireless networked world where everything is logging on the network, you are going to need wider coverage than that.



Comments