Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
When networks fail, hams to the rescue
Alliance to promote Windows-managed Macs in enterprise
Lockheed Martin gets $89 million to converge DoD distribution networks
Clothes don't make this man: Sweatshirt helps nail Citibank card scammer
Microsoft readies new try for Yahoo
Gartner: Seven cloud-computing security risks
Autonomy, Endeca rate among top enterprise search vendors
Barracuda countersues Trend Micro in patent case
Mozilla's Firefox 3 sets geeky world record
Microsoft SharePoint popularity comes with issues
IBM mainframe acquisition raises antitrust concerns
Diary of a deliberately spammed housewife
Report: Tech giants forming 'patent troll' alliance
Trojan lurks, waiting to steal admin passwords
California enacts cell-phone driving ban
Net/Systems Management /

Security services becomes part of the fabric

Related linksToday's breaking news
Send to a friendFeedback

Sign up to receive this and other networking newsletters in your inbox.

Regular readers of this column will recall two cardinal rules I believe frequently go a long way in determining the success or lack thereof of a new management product. The first rule is that, unless there is a compelling reason to do so, separate standalone boxes that exist solely for the purposes of management are generally to be avoided. Whenever possible, it's always more effective to leverage comparable management functionality that is supported within the network, if such is the case. Support staff training and implementation complexity are often two of the primary reasons.

The second rule is that, whenever possible, new management products should be integrated with the existing transport and management products that are already in place. In this context, the term "integrated" generally means that the new product should be able to perform some subset of useful management functions on the existing boxes and should be able to share some subset of data with products already installed at Command Central.

Recent security announcements from Cisco illustrate that the vendor understands (and often benefits) from these two rules. New enhancements to IOS include intrusion-detection features acquired through last year's purchase of the Wheel Group. Fifty-nine attack signatures from the former Wheel Group's NetRanger ID system have been built into the IOS Firewall, which is supported on 1700, 2600, 3600 and 7200 class routers. Using this approach, the IOS Firewall can then detect hacker attacks directly within the router itself.

This functionality appears to support both the first (i.e. utilize the management functionality that is embedded within the network) and second (ensure that the new management system can effectively integrate with what is already running at Command Central) cardinal rules.

However, one important thing to realize is that, much like the management system itself, security management is made up of a number of separate components. One size definitely does not fit all when data traffic encryption, authentication, access control, accounting and logging are taken into consideration. This clearly applies to both vendors as well as products.

Therefore, while embedded firewall and attack detection support functionality within the network infrastructure makes a great deal of sense for many good reasons, by no means does it constitute the total security picture. Users are well advised to apply the same two cardinal rules to the complete systems and network security picture that they should apply to the network management system.

RELATED LINKS

Renaissance Worldwide, Inc. (www.rens.com) is a leading provider of integrated business and technology. The Network Business Practice of Renaissance Worldwide has a unique advisory service, InvestmentHealth (tm) that enables companies to make complex network investment decisions simple and quantifiable.

More information from Cisco

Hacker group Cult of the Dead Cow tries to convince world its Back Orifice tool is legit
Network World, 07/12/99

Review: eNTrax Security Suite
Network World, 03/22/99

Intrusion-detection tools to stop hackers cold
Network World, 02/15/99

Net Resources: VPNs - primers and more
Network World Fusion

Archive of Network World on Network Systems Management newsletters


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.