My Photo

Got the NAC

« Educause SE Regional Event | Main | NAC now? NAC later? How about both? »

June 04, 2008

Silly SNACs

Tim Greene has a newsletter story on Symantec's "Peer to Peer NAC."  No, this is not using NAC for the purposes of governing Peer to Peer application usage, but rather leveraging the idea of Peer to Peer communication for the purposes of enforcing NAC policy.  Setting aside, just for the moment, whether the chickens can guard their own henhouse, this is just a silly idea.  It's a silly idea from an enforcement perspective because NAC policy enforcement (especially for managed assets capable of running a persistent agent, which is the only kind of asset Symanatec can govern in any event) will be done at the point of access (WAP, Wireless Controller, VPN Termination, Ethernet switch, etc.).  It's silly from a policy definition perspective since, again, it has no notion of unmanaged (or unmanageable) assets.  So it's purely a short term stop-gap, useful only until standards evolve that allow for ubiquitous enforcement at the point of access.  Yet, it's only a stop gap for general purpose computing assets that are tightly managed by the organization.  Pretty much by definition, these are the assets that pose the least risk to your organization.  Why would you start there?  Why implement a short term stop-gap product for assets that pose the least risk?

Silly.  Fusilli, Jerry.

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00e550a981ff883400e552c009368834

Listed below are links to weblogs that reference Silly SNACs:

Comments

Grant - though I am not a big fan of this technology, I think the point is that the peer devices only detect and test devices by querying the agent. It is still the traditional point of access that will be the "enforcement" point. I think this might be similar to what infoexpress does with DNAC, except leveraging communication among symantec agents.

Hi Alan

The disconnect is likely over my reference to SNAC, but it was alliterative so I couldn't pass it up. Per Tim's article:

"Symantec NAC enforcement is located in its endpoint software, so each endpoint contains knowledge of its own configuration-compliance status."

How this approach melds with, say, the Symantec Enforcer appliances (that at least have the ability to enforcement at the point of access) is not clear from the article. What does seem clear, though, is that in the "peer-to-peer" approach that is the subject of the article, the endpoints are enforcers. Which, of course, is what I'm picking on.

Anyhow, thanks for the comment.

My response...

http://securityuncorked.squarespace.com/security-uncorked/2008/6/30/symantecs-network-based-nac.html

-jj

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment