« Less Then Zero, Part 1 | Main | SC Magazine review of Strata Guard Free IDS/IPS »

October 19, 2006

There is more than one way to skin a NAC

My friend Chris Harrington from Infosecpodcast tracked back to my article on Insightix and has an article up on his take of things.  Chris is a good guy and pretty security savvy, especially with IDS/IPS stuff.  I half agree with him and half disagree with Chris on this one though.  First why I agree.  Your right Chris, 802.1x is a pain to put in place, especially if the only reason to do it is for NAC.  Your also right, that if it is deployed, it is probably the best way to do NAC as securely as possible.  Your also right that 802.1x is not being adopted as quickly as some of us would like.  I still think massive 802.1x adoption is 12 to 24 months away.  But make no mistake about it, it is coming. Finally, you are right that a successful NAC solution needs to offer some other options besides 802.1x to be successful.

Chris you are wrong on a few things though.  First of all MS NAP is going to use several enforcement technologies, including DHCP, but their recomended is I believe IPSec.  Next you would be surprised that some NAC vendors who claim to support 802.1x, actually just ride on top of it and don't truly support it.  Without pointing fingers, I think some of the other vendors you mention fall into that category.  But Chris the biggest thing I disagree with you on is the history here.  I did not get up in front of us all at Black Hat and chide everyone that all of the other NAC solutions could be bypassed, some rather easily and that my company was going to have something bullet proof.  Ofir Arkin did.  Then they come out with ARP spoofing and SNMP.  That is the issue here.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d83451e4d369e200d8356b9d2369e2

Listed below are links to weblogs that reference There is more than one way to skin a NAC:

Comments

My Photo

Subscribe to my blog

Enter your email address:

Delivered by FeedBurner

Lijit Search

Blog Networks

Creative Commons License
This work is licensed under a Creative Commons Attribution-Share Alike 2.5 License.

Search

Lijit Search

Attend a Computer Forensics Boot Camp to better your skills and become a better worker
Blog powered by TypePad
Member since 10/2005