Skip Links

Network World

  • Social Web 
  • Email 
  • Close

The pros and cons of NAC

Bottom Line By Joel Snyder , Network World , 06/12/2006
Snyder

Network access control is a simple idea: Authenticate every user connecting to the network, then enforce an access-control policy based on who they are and other information, such as endpoint security checks and wired vs. wireless access method.

After writing an architectural overview of NAC for Network World and testing NAC products at Interop last month, I’ve been exposed to the good and bad parts of NAC.

I'm enthusiastic about NAC, but I'd like to devote some time to the devil's advocate view of the technology. Specifically, NAC has five major failings:

Endpoint security checks work only when you need them least. When you need them most, they leave you high and dry. A NAC strategy based on checking endpoint security works great for managed laptops and desktops, but (according to our testing) not so well for people coming into the organization - the folks you have the greatest security concerns about. If you're doing NAC to check that strangers have virus scanners loaded, you're doing it for the wrong reason.

Generals are always preparing to fight the last war, not the next one, and NAC is the same way. A lot of the NAC rhetoric is reactionary - worrying about last week's threats. That's useful, but in reality we haven't had a huge, networkwide virus meltdown in a couple of years. That's because we're getting better at preventing these kinds of things. Sure, it will happen again, but the frequency and severity are dropping. Which brings us to . . .

The ROI on NAC is a big unknown. NAC is a lot of work. Even if your network infrastructure is ready for NAC, getting it into place will not be cheap or easy. Is it worth it? You should probably calculate that before going down this path. There are lots of other ways to spend your security dollars. Maybe some will have a better ROI. Or maybe not.

Too much information is sometimes just too much. One of NAC's benefits is that it gives you the opportunity to set a policy for every user. The problem is organizations that are paralyzed by the concept of policy definition or don't know what is going on with their networks will not suddenly be able to come up with per-user or per-group NAC rules. You can use NAC in its most primitive, "on if you authenticate, off if you don't" mode, but if that's all you want, save yourself a lot of bother and try a simpler solution.

Partner Content

Brilliantly simple security and control solutions for email, web and endpoint

www.sophos.com

Stopping data leakage

Learn how to exploit your current security investment to control the information that flows into, through and out of your network.

Download the white paper.

Why detection rates aren't enough

Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask to prospective vendors to get the right endpoint solution.

Download the white paper.

Unauthorized applications: Taking back control

Employees installing and using unauthorized applications like IM, VoIP, games and peer-to-peer file-sharing applications cause many businesses serious concern. How do you control these applications?

Download the white paper.

Comments (1)
Login
Forgot your account info?

RE: The pros and cons of NACBy priya on February 18, 2008, 4:55 ami don get clear idea about the loopholes of NAC. can u pls explain it in detail.

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.