[26512] in resnet

home help back first fref pref prev next nref lref last post

Re: NAC solution removal

daemon@ATHENA.MIT.EDU (GD)
Tue Jun 14 12:03:53 2011

MIME-version: 1.0
Content-type: multipart/alternative; boundary="Boundary_(ID_Cws35Gml/9X9iANUAOKGvw)"
Message-ID:  <4DF7865D.1000506@wmich.edu>
Date:         Tue, 14 Jun 2011 12:03:41 -0400
Reply-To: Resnet Forum <RESNET-L@listserv.nd.edu>
From: GD <gaurav.dave@wmich.edu>
To: RESNET-L@listserv.nd.edu
In-Reply-To:  <648355A0EA9BCE4C8E867D496C8F41B54AC5670E@Abel.stmartin.edu>

This is a multi-part message in MIME format.

--Boundary_(ID_Cws35Gml/9X9iANUAOKGvw)
Content-type: text/plain; charset=ISO-8859-1; format=flowed
Content-transfer-encoding: 7BIT

Jordan,

Thank you for your insight. We are currently using the Bradford NAC in conjunction with a legacy home-brew registration 
system that we are phasing out; essentially moving in the opposite direction from you! We also have a Perfigo NAC that 
we are replacing with the Bradford appliances. I do agree that the UI could be better, however I find that the ability 
to locate a MAC address on any port and change it's VLAN in itself is quite useful (our network is about 59,000 ports, 
not counting the circa 1500 wireless APs).

Gaurav
--

On 6/14/2011 11:47 AM, Boland, Jordan wrote:
>
> Gaurav,
>
> There are a few reasons why we decided to remove this completely.  In no particular order:
>
> The NAC is simply unnecessary given other tools that are available.  This appliance was purchased primary due to the 
> Blaster virus outbreak.  Since that time, operating systems are much more secure by default, users are more educated 
> about Internet risks (if only marginally), and the attack vector has changed.  The purpose of the NAC truly is to 
> protect the /network infrastructure/ and /the institution/, not necessarily the student.  The fact that a student has 
> updated virus definitions is a side effect of the strategy employed to protect the network.  I don't want to give the 
> impression that I don't want my students to be protected from virus threats, but I see my charter as providing good 
> advice, and then allowing them to make their own mistakes (so long as it does not put my equipment at risk).
>
> I am the first network specialist at this institution, and I have a large mess to clean up....over the years, the 
> network here wasn't so much "designed" as it was "grown".  Without going into too much detail, I am in the middle of a 
> top-to-bottom re-engineering.  The NAC is installed on the 'legacy' network, but I need a solution for our new network 
> while I build it out.  I can homebrew our 802.1X/RADIUS/DVA just as easily as I could reconfigure the NAC for the new 
> environment, but what would I do in the meantime?  I still need to manage both networks.
>
> I need(/desire) to deploy 802.1X/RADIUS anyway for wireless and VPN access.  Adding DVA and a client registration 
> portal is low-hanging fruit.  I'm excited about the synergy with so many systems running on the same (open) servers, 
> with one management interface.
>
> The user experience with the NAC is abysmal.  We hired a new CIO right about the time that I started, and the reports 
> that he heard from students as well as his own experience with the NAC resulted in his mandating that something be 
> done with it.  He doesn't like the client software required, as downloading, installing, and running it proves 
> troublesome for many of our students.  It fails classification more often than we would like.  I don't like the client 
> software much either.
>
> The management experience (at least that we experience here) is abysmal.  The web interface leaves many things to be 
> desired, not the least of which is a UI design that was.....I think 'designed' is the word I am looking for.  It is 
> awful.  The number of screens it takes to get to the port management view is outrageous.  This is exacerbated by the 
> fact that we manually flip VLANs more than we should have to.  Our ports get stuck in incorrect VLANs sometimes, which 
> is probably caused by the fact that the infrastructure management paradigm is backwards.  That isn't Bradford's 
> fault.  Our switches are so ancient that they cannot poll the controller for dynamic port configuration, so instead 
> the controller logs into switches individually and reconfigures ports as events are triggered.  Icky.  Obviously these 
> switches are being replaced to support the new system.
>
> Our NAC isn't EOL yet, but that day is near.  When we started thinking about replacing this device, we talked with 
> Impulse Point about their product.  The cost was ~$30,000 for the client policy enforcement, plus some new hardware 
> that we needed.  The problem was, their product as spec'ed only enforces policies on the clients:  who has what 
> antivirus, make sure they don't have P2P software installed, etc. etc.  It didn't have any way of doing dynamic VLAN 
> assignment.  Anyway, I was told that it is easy to build their system on top of an 802.1X/RADIUS/DVA infrastructure.  
> .....   After building the same deployment that I had proposed, pay and additional $30,000 to enforce client policies, 
> despite my stated belief that it is unnecessary? Thanks, but no.  This experience ended our desire to look at other 
> vendors.
>
> -Jordan
>

___________________________________________________
You are subscribed to the ResNet-L mailing list.

To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________

--Boundary_(ID_Cws35Gml/9X9iANUAOKGvw)
Content-type: text/html; charset=ISO-8859-1
Content-transfer-encoding: 7BIT

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
  <head>
    <meta content="text/html; charset=ISO-8859-1"
      http-equiv="Content-Type">
  </head>
  <body bgcolor="#ffffff" text="#000000">
    Jordan, <br>
    <br>
    Thank you for your insight. We are currently using the Bradford NAC
    in conjunction with a legacy home-brew registration system that we
    are phasing out; essentially moving in the opposite direction from
    you! We also have a Perfigo NAC that we are replacing with the
    Bradford appliances. I do agree that the UI could be better, however
    I find that the ability to locate a MAC address on any port and
    change it's VLAN in itself is quite useful (our network is about
    59,000 ports, not counting the circa 1500 wireless APs).<br>
    <br>
    Gaurav<br>
    --<br>
    <br>
    On 6/14/2011 11:47 AM, Boland, Jordan wrote:
    <blockquote
      cite="mid:648355A0EA9BCE4C8E867D496C8F41B54AC5670E@Abel.stmartin.edu"
      type="cite">
      <meta http-equiv="Content-Type" content="text/html;
        charset=ISO-8859-1">
      <meta name="Generator" content="Microsoft Word 14 (filtered
        medium)">
      <style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";
	color:black;}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";
	color:black;}
tt
	{mso-style-priority:99;
	font-family:"Courier New";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";
	color:black;}
span.apple-tab-span
	{mso-style-name:apple-tab-span;}
span.EmailStyle20
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle21
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";
	color:black;}
span.EmailStyle24
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext="edit">
<o:idmap v:ext="edit" data="1" />
</o:shapelayout></xml><![endif]-->
      <div class="WordSection1">
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">Gaurav,
            <o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">There are a few reasons why we decided to remove
            this completely.&nbsp; In no particular order:<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">The NAC is simply unnecessary given other tools
            that are available.&nbsp; This appliance was purchased primary
            due to the Blaster virus outbreak.&nbsp; Since that time,
            operating systems are much more secure by default, users are
            more educated about Internet risks (if only marginally), and
            the attack vector has changed.&nbsp; The purpose of the NAC truly
            is to protect the /network infrastructure/ and /the
            institution/, not necessarily the student.&nbsp; The fact that a
            student has updated virus definitions is a side effect of
            the strategy employed to protect the network.&nbsp; I don&#8217;t want
            to give the impression that I don&#8217;t want my students to be
            protected from virus threats, but I see my charter as
            providing good advice, and then allowing them to make their
            own mistakes (so long as it does not put my equipment at
            risk).<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">I am the first network specialist at this
            institution, and I have a large mess to clean up&#8230;.over the
            years, the network here wasn&#8217;t so much &#8220;designed&#8221; as it was
            &#8220;grown&#8221;.&nbsp; Without going into too much detail, I am in the
            middle of a top-to-bottom re-engineering.&nbsp; The NAC is
            installed on the &#8216;legacy&#8217; network, but I need a solution for
            our new network while I build it out.&nbsp; I can homebrew our
            802.1X/RADIUS/DVA just as easily as I could reconfigure the
            NAC for the new environment, but what would I do in the
            meantime?&nbsp; I still need to manage both networks.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">I need(/desire) to deploy 802.1X/RADIUS anyway
            for wireless and VPN access.&nbsp; Adding DVA and a client
            registration portal is low-hanging fruit.&nbsp; I&#8217;m excited about
            the synergy with so many systems running on the same (open)
            servers, with one management interface.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">The user experience with the NAC is abysmal.&nbsp; We
            hired a new CIO right about the time that I started, and the
            reports that he heard from students as well as his own
            experience with the NAC resulted in his mandating that
            something be done with it.&nbsp; He doesn&#8217;t like the client
            software required, as downloading, installing, and running
            it proves troublesome for many of our students.&nbsp; It fails
            classification more often than we would like.&nbsp; I don&#8217;t like
            the client software much either.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">The management experience (at least that we
            experience here) is abysmal.&nbsp; The web interface leaves many
            things to be desired, not the least of which is a UI design
            that was&#8230;..I think &#8216;designed&#8217; is the word I am looking for.&nbsp;
            It is awful.&nbsp; The number of screens it takes to get to the
            port management view is outrageous.&nbsp; This is exacerbated by
            the fact that we manually flip VLANs more than we should
            have to.&nbsp; Our ports get stuck in incorrect VLANs sometimes,
            which is probably caused by the fact that the infrastructure
            management paradigm is backwards.&nbsp; That isn&#8217;t Bradford&#8217;s
            fault.&nbsp; Our switches are so ancient that they cannot poll
            the controller for dynamic port configuration, so instead
            the controller logs into switches individually and
            reconfigures ports as events are triggered.&nbsp; Icky.&nbsp;
            Obviously these switches are being replaced to support the
            new system.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">Our NAC isn&#8217;t EOL yet, but that day is near.&nbsp;
            When we started thinking about replacing this device, we
            talked with Impulse Point about their product.&nbsp; The cost was
            ~$30,000 for the client policy enforcement, plus some new
            hardware that we needed.&nbsp; The problem was, their product as
            spec&#8217;ed only enforces policies on the clients:&nbsp; who has what
            antivirus, make sure they don&#8217;t have P2P software installed,
            etc. etc.&nbsp; It didn&#8217;t have any way of doing dynamic VLAN
            assignment.&nbsp; Anyway, I was told that it is easy to build
            their system on top of an 802.1X/RADIUS/DVA infrastructure.&nbsp;
            &#8230;..&nbsp;&nbsp; After building the same deployment that I had
            proposed, pay and additional $30,000 to enforce client
            policies, despite my stated belief that it is unnecessary?
            Thanks, but no.&nbsp; This experience ended our desire to look at
            other vendors.<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);">-Jordan<o:p></o:p></span></p>
        <p class="MsoNormal"><span style="font-size: 11pt; font-family:
            &quot;Calibri&quot;,&quot;sans-serif&quot;; color: rgb(31,
            73, 125);"><o:p>&nbsp;</o:p></span></p>
      </div>
    </blockquote>
  </body>
</html>
___________________________________________________
You are subscribed to the ResNet-L mailing list.
<p>
To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________

--Boundary_(ID_Cws35Gml/9X9iANUAOKGvw)--

home help back first fref pref prev next nref lref last post