[26512] in resnet
Re: NAC solution removal
daemon@ATHENA.MIT.EDU (GD)
Tue Jun 14 12:03:53 2011
MIME-version: 1.0
Content-type: multipart/alternative; boundary="Boundary_(ID_Cws35Gml/9X9iANUAOKGvw)"
Message-ID: <4DF7865D.1000506@wmich.edu>
Date: Tue, 14 Jun 2011 12:03:41 -0400
Reply-To: Resnet Forum <RESNET-L@listserv.nd.edu>
From: GD <gaurav.dave@wmich.edu>
To: RESNET-L@listserv.nd.edu
In-Reply-To: <648355A0EA9BCE4C8E867D496C8F41B54AC5670E@Abel.stmartin.edu>
This is a multi-part message in MIME format.
--Boundary_(ID_Cws35Gml/9X9iANUAOKGvw)
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT
Jordan,
Thank you for your insight. We are currently using the Bradford NAC in conjunction with a legacy home-brew registration
system that we are phasing out; essentially moving in the opposite direction from you! We also have a Perfigo NAC that
we are replacing with the Bradford appliances. I do agree that the UI could be better, however I find that the ability
to locate a MAC address on any port and change it's VLAN in itself is quite useful (our network is about 59,000 ports,
not counting the circa 1500 wireless APs).
Gaurav
--
On 6/14/2011 11:47 AM, Boland, Jordan wrote:
>
> Gaurav,
>
> There are a few reasons why we decided to remove this completely. In no particular order:
>
> The NAC is simply unnecessary given other tools that are available. This appliance was purchased primary due to the
> Blaster virus outbreak. Since that time, operating systems are much more secure by default, users are more educated
> about Internet risks (if only marginally), and the attack vector has changed. The purpose of the NAC truly is to
> protect the /network infrastructure/ and /the institution/, not necessarily the student. The fact that a student has
> updated virus definitions is a side effect of the strategy employed to protect the network. I don't want to give the
> impression that I don't want my students to be protected from virus threats, but I see my charter as providing good
> advice, and then allowing them to make their own mistakes (so long as it does not put my equipment at risk).
>
> I am the first network specialist at this institution, and I have a large mess to clean up....over the years, the
> network here wasn't so much "designed" as it was "grown". Without going into too much detail, I am in the middle of a
> top-to-bottom re-engineering. The NAC is installed on the 'legacy' network, but I need a solution for our new network
> while I build it out. I can homebrew our 802.1X/RADIUS/DVA just as easily as I could reconfigure the NAC for the new
> environment, but what would I do in the meantime? I still need to manage both networks.
>
> I need(/desire) to deploy 802.1X/RADIUS anyway for wireless and VPN access. Adding DVA and a client registration
> portal is low-hanging fruit. I'm excited about the synergy with so many systems running on the same (open) servers,
> with one management interface.
>
> The user experience with the NAC is abysmal. We hired a new CIO right about the time that I started, and the reports
> that he heard from students as well as his own experience with the NAC resulted in his mandating that something be
> done with it. He doesn't like the client software required, as downloading, installing, and running it proves
> troublesome for many of our students. It fails classification more often than we would like. I don't like the client
> software much either.
>
> The management experience (at least that we experience here) is abysmal. The web interface leaves many things to be
> desired, not the least of which is a UI design that was.....I think 'designed' is the word I am looking for. It is
> awful. The number of screens it takes to get to the port management view is outrageous. This is exacerbated by the
> fact that we manually flip VLANs more than we should have to. Our ports get stuck in incorrect VLANs sometimes, which
> is probably caused by the fact that the infrastructure management paradigm is backwards. That isn't Bradford's
> fault. Our switches are so ancient that they cannot poll the controller for dynamic port configuration, so instead
> the controller logs into switches individually and reconfigures ports as events are triggered. Icky. Obviously these
> switches are being replaced to support the new system.
>
> Our NAC isn't EOL yet, but that day is near. When we started thinking about replacing this device, we talked with
> Impulse Point about their product. The cost was ~$30,000 for the client policy enforcement, plus some new hardware
> that we needed. The problem was, their product as spec'ed only enforces policies on the clients: who has what
> antivirus, make sure they don't have P2P software installed, etc. etc. It didn't have any way of doing dynamic VLAN
> assignment. Anyway, I was told that it is easy to build their system on top of an 802.1X/RADIUS/DVA infrastructure.
> ..... After building the same deployment that I had proposed, pay and additional $30,000 to enforce client policies,
> despite my stated belief that it is unnecessary? Thanks, but no. This experience ended our desire to look at other
> vendors.
>
> -Jordan
>
___________________________________________________
You are subscribed to the ResNet-L mailing list.
To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________
--Boundary_(ID_Cws35Gml/9X9iANUAOKGvw)
Content-type: text/html; charset=ISO-8859-1
Content-transfer-encoding: 7BIT
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<meta content="text/html; charset=ISO-8859-1"
http-equiv="Content-Type">
</head>
<body bgcolor="#ffffff" text="#000000">
Jordan, <br>
<br>
Thank you for your insight. We are currently using the Bradford NAC
in conjunction with a legacy home-brew registration system that we
are phasing out; essentially moving in the opposite direction from
you! We also have a Perfigo NAC that we are replacing with the
Bradford appliances. I do agree that the UI could be better, however
I find that the ability to locate a MAC address on any port and
change it's VLAN in itself is quite useful (our network is about
59,000 ports, not counting the circa 1500 wireless APs).<br>
<br>
Gaurav<br>
--<br>
<br>
On 6/14/2011 11:47 AM, Boland, Jordan wrote:
<blockquote
cite="mid:648355A0EA9BCE4C8E867D496C8F41B54AC5670E@Abel.stmartin.edu"
type="cite">
<meta http-equiv="Content-Type" content="text/html;
charset=ISO-8859-1">
<meta name="Generator" content="Microsoft Word 14 (filtered
medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Tahoma;
panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman","serif";
color:black;}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p
{mso-style-priority:99;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:12.0pt;
font-family:"Times New Roman","serif";
color:black;}
tt
{mso-style-priority:99;
font-family:"Courier New";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
{mso-style-priority:99;
mso-style-link:"Balloon Text Char";
margin:0in;
margin-bottom:.0001pt;
font-size:8.0pt;
font-family:"Tahoma","sans-serif";
color:black;}
span.apple-tab-span
{mso-style-name:apple-tab-span;}
span.EmailStyle20
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.EmailStyle21
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.BalloonTextChar
{mso-style-name:"Balloon Text Char";
mso-style-priority:99;
mso-style-link:"Balloon Text";
font-family:"Tahoma","sans-serif";
color:black;}
span.EmailStyle24
{mso-style-type:personal-reply;
font-family:"Calibri","sans-serif";
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
<div class="WordSection1">
<p class="MsoNormal"><span style="font-size: 11pt; font-family:
"Calibri","sans-serif"; color: rgb(31,
73, 125);">Gaurav,
<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family:
"Calibri","sans-serif"; color: rgb(31,
73, 125);"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family:
"Calibri","sans-serif"; color: rgb(31,
73, 125);">There are a few reasons why we decided to remove
this completely. In no particular order:<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family:
"Calibri","sans-serif"; color: rgb(31,
73, 125);"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family:
"Calibri","sans-serif"; color: rgb(31,
73, 125);">The NAC is simply unnecessary given other tools
that are available. This appliance was purchased primary
due to the Blaster virus outbreak. Since that time,
operating systems are much more secure by default, users are
more educated about Internet risks (if only marginally), and
the attack vector has changed. The purpose of the NAC truly
is to protect the /network infrastructure/ and /the
institution/, not necessarily the student. The fact that a
student has updated virus definitions is a side effect of
the strategy employed to protect the network. I don’t want
to give the impression that I don’t want my students to be
protected from virus threats, but I see my charter as
providing good advice, and then allowing them to make their
own mistakes (so long as it does not put my equipment at
risk).<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family:
"Calibri","sans-serif"; color: rgb(31,
73, 125);"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family:
"Calibri","sans-serif"; color: rgb(31,
73, 125);">I am the first network specialist at this
institution, and I have a large mess to clean up….over the
years, the network here wasn’t so much “designed” as it was
“grown”. Without going into too much detail, I am in the
middle of a top-to-bottom re-engineering. The NAC is
installed on the ‘legacy’ network, but I need a solution for
our new network while I build it out. I can homebrew our
802.1X/RADIUS/DVA just as easily as I could reconfigure the
NAC for the new environment, but what would I do in the
meantime? I still need to manage both networks.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family:
"Calibri","sans-serif"; color: rgb(31,
73, 125);"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family:
"Calibri","sans-serif"; color: rgb(31,
73, 125);">I need(/desire) to deploy 802.1X/RADIUS anyway
for wireless and VPN access. Adding DVA and a client
registration portal is low-hanging fruit. I’m excited about
the synergy with so many systems running on the same (open)
servers, with one management interface.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family:
"Calibri","sans-serif"; color: rgb(31,
73, 125);"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family:
"Calibri","sans-serif"; color: rgb(31,
73, 125);">The user experience with the NAC is abysmal. We
hired a new CIO right about the time that I started, and the
reports that he heard from students as well as his own
experience with the NAC resulted in his mandating that
something be done with it. He doesn’t like the client
software required, as downloading, installing, and running
it proves troublesome for many of our students. It fails
classification more often than we would like. I don’t like
the client software much either.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family:
"Calibri","sans-serif"; color: rgb(31,
73, 125);"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family:
"Calibri","sans-serif"; color: rgb(31,
73, 125);">The management experience (at least that we
experience here) is abysmal. The web interface leaves many
things to be desired, not the least of which is a UI design
that was…..I think ‘designed’ is the word I am looking for.
It is awful. The number of screens it takes to get to the
port management view is outrageous. This is exacerbated by
the fact that we manually flip VLANs more than we should
have to. Our ports get stuck in incorrect VLANs sometimes,
which is probably caused by the fact that the infrastructure
management paradigm is backwards. That isn’t Bradford’s
fault. Our switches are so ancient that they cannot poll
the controller for dynamic port configuration, so instead
the controller logs into switches individually and
reconfigures ports as events are triggered. Icky.
Obviously these switches are being replaced to support the
new system.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family:
"Calibri","sans-serif"; color: rgb(31,
73, 125);"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family:
"Calibri","sans-serif"; color: rgb(31,
73, 125);">Our NAC isn’t EOL yet, but that day is near.
When we started thinking about replacing this device, we
talked with Impulse Point about their product. The cost was
~$30,000 for the client policy enforcement, plus some new
hardware that we needed. The problem was, their product as
spec’ed only enforces policies on the clients: who has what
antivirus, make sure they don’t have P2P software installed,
etc. etc. It didn’t have any way of doing dynamic VLAN
assignment. Anyway, I was told that it is easy to build
their system on top of an 802.1X/RADIUS/DVA infrastructure.
….. After building the same deployment that I had
proposed, pay and additional $30,000 to enforce client
policies, despite my stated belief that it is unnecessary?
Thanks, but no. This experience ended our desire to look at
other vendors.<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family:
"Calibri","sans-serif"; color: rgb(31,
73, 125);"><o:p> </o:p></span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family:
"Calibri","sans-serif"; color: rgb(31,
73, 125);">-Jordan<o:p></o:p></span></p>
<p class="MsoNormal"><span style="font-size: 11pt; font-family:
"Calibri","sans-serif"; color: rgb(31,
73, 125);"><o:p> </o:p></span></p>
</div>
</blockquote>
</body>
</html>
___________________________________________________
You are subscribed to the ResNet-L mailing list.
<p>
To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________
--Boundary_(ID_Cws35Gml/9X9iANUAOKGvw)--