cancel
Showing results for 
Search instead for 
Did you mean: 

What are your thoughts on the UAE concept? (Most Read threads copied from the old J-Net)

ac_
Occasional Contributor

What are your thoughts on the UAE concept? (Most Read threads copied from the old J-Net)

 



















inightingale


Posts: 15

Registered on:
Dec 19, 2005

What are your thoughts on the UAE concept?

Posted: Jan 21, 2006  10:18 AM 136 views

I'm interested to know people's thoughts on the Unified Access Control conept. The concept being that LAN users will have to be authenticated and their PC's security audited before gaining resource access.

Do you think it will be popular?
Do you think it will become standard to have all LAN users go through authenitcation/auditing before gaining resources?
What industries will be the first to take up the technology? Which will not consider it for some time?

What could be done to improve the technology? what is it missing?

Discuss...






dsmart

Posts: 18

Registered on:
Mar 23, 2006




RE: What are your thoughts on the UAE concept?

Posted: Apr 4, 2006  6:25 PM 139 views

In reply to: What are your thoughts on the UAE concept? „ I'm interested to know people's thoughts on the Unified Access Control...
posted by inightingale on Jan 21, 2006  10:18 AM

I have many very small sites (300) that are too small to run their own AAA.  Using Dot1X is a without a local radius could be a problem.  I like the idea of protecting the data center with the IC and firewall rules.  We are putting in two ISG2000's between our data center and our MPLS WAN that could serve as a good pinchpoint.  Seems like it would reduce all the switch management.

By the way, would love to see a combination 5GT&Router with inbuilt CSU and Frame Relay support.  Add an optional WXC accelerator module and we'd have the perfect small site security box.

-=Dan=-
Dan Smart
Enterprise Security
Vulcan Materials Company






gmiliefsky

Posts: 2

Registered on:
Apr 21, 2006




RE: What are your thoughts on the UAE concept?pt will re

Posted: Apr 22, 2006  3:59 PM 136 views

In reply to: What are your thoughts on the UAE concept? „ I'm interested to know people's thoughts on the Unified Access Control...
posted by inightingale on Jan 21, 2006  10:18 AM

The only way this concept will really work is if there is a solution for allowing 'guests' who do not have a client (thin as it may be installed).  We've cooked up a solution and have a published patent on the subject matter.  We will be showing a CLIENTLESS/AGENTLESS solution integrated with Juniper SSG at the J-Partner Summit next week so stay tuned...

Best regards,
Gary

Gary S. Miliefsky, CISSP
Founder & CTO
NetClarity
http://www.netclarity.net






dsmart

Posts: 18

Registered on:
Mar 23, 2006




RE: RE: What are your thoughts on the UAE concept?pt will re

Posted: Apr 24, 2006  7:48 AM 134 views

In reply to: RE: What are your thoughts on the UAE... „ The only way this concept will really work is if there is a solution for...
posted by gmiliefsky on Apr 22, 2006  3:59 PM

Humm...  Interesting...

My key issue is to NOT create a self inflicted denial of service event if the endpoint enforcement fails for some reason.  Yes, we may need to block access to SOX audited systems, but normal point of sale activities MUST continue.

Look forward to hearing more on your solution.

-=Dan=-






tabdallah

Posts: 9

Registered on:
Feb 14, 2006




RE: What are your thoughts on the UAE concept?

Posted: Jul 3, 2006  7:45 AM 108 views

In reply to: What are your thoughts on the UAE concept? „ I'm interested to know people's thoughts on the Unified Access Control...
posted by inightingale on Jan 21, 2006  10:18 AM

I belive the the IC is a good solution especially if you have switches, routers, etc from different vendors, but let me ask what is the IC going to do with attacks across the layer-2 switches. Imagine two pc's connected to a layer two switch and they are both in the same subnet. So the firewall will not give him access if his pc is infectect, however he will be able to infect those pc's directly connecting to his layer-2 switch without giving the firewall chance to even see such traffic. which is not the case with layer-2 NAC from other vendors.






dwessels

Posts: 3

Registered on:
Jan 23, 2006




RE: RE: What are your thoughts on the UAE concept?

Posted: Jul 10, 2006  3:56 PM 105 views

In reply to: RE: What are your thoughts on the UAE concept? „ I belive the the IC is a good solution especially if you have switches,...
posted by tabdallah on Jul 3, 2006  7:45 AM


We solve this deployment problem by providing the ability to set firewall policy on the endpoint.  We have a small firewall build in our Infranet Agent called Host Enforcer.  HE allow you to set a policy that will not allow other users on the same L2 network talk to you.  That solves the problem of controlling access between local machines.


Denzil