[26513] in resnet
Re: NAC solution removal
daemon@ATHENA.MIT.EDU (Boland, Jordan)
Tue Jun 14 12:07:06 2011
Content-Language: en-US
Content-Type: multipart/alternative; boundary="_000_648355A0EA9BCE4C8E867D496C8F41B54AC56753Abelstmartinedu_"
MIME-Version: 1.0
Message-ID: <648355A0EA9BCE4C8E867D496C8F41B54AC56753@Abel.stmartin.edu>
Date: Tue, 14 Jun 2011 16:06:36 +0000
Reply-To: Resnet Forum <RESNET-L@listserv.nd.edu>
From: "Boland, Jordan" <JBoland@stmartin.edu>
To: RESNET-L@listserv.nd.edu
In-Reply-To: <73B1B6A7A6FAD74AAB34CF95A097C5EA1F5061E9@MAILSRV06.cua.edu>
--_000_648355A0EA9BCE4C8E867D496C8F41B54AC56753Abelstmartinedu_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
Hi Dan,
You are correct we are not able to enforce client policies without an agent=
, as student machines are not university owned.
I'll start with guest access. I am building into the system a mechanism to=
'mint' guest accounts which can be used to register devices on the network=
. As a guest you are segregated into a private VLAN which allows internet =
access, but no on-campus resources. There are a few unanswered questions a=
t this point, of which I suspect that printing will be the most important. =
We have a web-print capability here, so I do not expect that to be an issu=
e. As a guest, I don't expect you to need access to my file shares, so I a=
m perfectly fine with providing you with Internet access and nothing more.
Next, remediation. In the NAC/Bradford model, the remediation network has =
access to anti-virus updates, windows updates, etc. In my model, this netw=
ork does not exist in the same sense because I do not enforce client polici=
es. No antivirus policies to enforce =3D no remediation necessary.
So, when you ask about remediation, you are really asking about AUP violati=
ons and "strange network traffic", i.e. malware. This is where the traditi=
onal remediation network would be helpful, and the latest software on our P=
acketLogic may be able to help me there. I haven't done any proof-of-conce=
pts on this yet, but I am relatively unconcerned with this. Let me explain=
why.
In the event of a AUP violation, such as a complaint of copyright infringem=
ent, we can "jail" a machine in a blackhole VLAN, assuming that is what you=
desire to do. My last school had an automated graduated response system w=
here you were cut off of the network for 1 or 2 weeks, followed by a meetin=
g with student affairs. SMU does not currently have such a policy in place=
(working on it). We don't get many copyright complaints.
In the event of virus infection, if we detect strange traffic we can also "=
jail" the user. We can present a helpful message to them and instruct them=
to approach our helpdesk for assistance resolving the issue, if necessary.=
This is the most difficult thing to be comfortable with, but it isn't as =
scary in practice as it sounds on paper. If a student called and told us t=
hat they had cleaned the infection (we provided local caches of several cur=
rent antivirus products, and an 'automated cleaning script' which would all=
ow them to run with zero user interaction), we would release them. Occasio=
nally, they would still be infected, so we would require their computer to =
be brought to us, or we would schedule a housecall and clean it up on-site.
This sounds like a heavy support load, but it really wasn't too bad. At my=
last school, I was responsible for the end-user support for the ResNet sys=
tem of approximately 2000 students. I was half-time, and we had a full-tim=
e administrator. There was one other student who would help with the suppo=
rt when necessary, as well as another member of the professional staff who =
again would help as time was available. So our support load was approximat=
ely 2.25 FTE. Then take into account that our netadmin had other duties, a=
nd wasn't available for virus cleaning, so our user-facing support was real=
ly closer to 1.25 FTE. At SMU, we are a much smaller school, and while we h=
ave a smaller IT shop, we also do not have the distinction of "self-funded"=
IT (like I was) vs. "state-funded" IT, so we can pool our work-study stude=
nts and other desktop support staff. Our campus is also much, much smaller=
, so I am not concerned about the support load, and if you have a handful o=
f talented student workers, I suspect that you need not be concerned about =
it either.
Of course, for this to work, you have to be able to identify "strange traff=
ic" and take action. I haven't gotten that far in my implementation yet, b=
ut there are numerous ways to go about generating data for analysis. I sus=
pect that Perl will be the key to making this part of the system work.
-Jordan
From: Resnet Forum [mailto:RESNET-L@LISTSERV.ND.EDU] On Behalf Of Foerst, D=
aniel P.
Sent: Tuesday, June 14, 2011 8:14 AM
To: RESNET-L@LISTSERV.ND.EDU
Subject: Re: NAC solution removal
While I do not disagree that the whole NAC solution can degrade the Interne=
t experience and does add some administrative overhead, what are you doing =
for remediation in regards to your clients? In our network we can enforce s=
ystem patches, anti-virus is updated since these systems are university own=
ed.
However when it comes to our students we do not have that ability as we do =
not have ownership. Instead we require installation of an agent that ensure=
s the students are complying to the AUP and keeping their own systems up to=
date. Should a system fall out of compliance after a set period of time th=
e user loses Internet access.
Similarly how to do you protect against guest access, especially if a guest=
is bringing a worm, virus, malware, etc?
In today's budget conscience world I can certainly see removal of money guz=
zling equipment if you have a cheaper means to maintain the same or close t=
o the same level of protection for your network and I too would love to sav=
e money where possible!
Thanks!
-dan
Daniel Foerst
Assistant Director, Networks & Security
The Catholic University of America
Washington, DC 20064
From: Resnet Forum [mailto:RESNET-L@LISTSERV.ND.EDU] On Behalf Of Boland, J=
ordan
Sent: Tuesday, June 14, 2011 10:35 AM
To: RESNET-L@LISTSERV.ND.EDU
Subject: Re: NAC solution removal
My last institution didn't employ a NAC, but instead used a homebrew client=
registration system to help keep order. MAC addresses were registered int=
o a database, and VMPS was used to assign machines to the correct VLAN when=
they connected. Machines showing 'interesting' behavior or subject to a p=
olicy sanction were either assigned to a jail VLAN or ignored completely (s=
witchport can be disabled remotely via VMPS as well).
At SMU, we are in the process of removing our Bradford NAC and replacing it=
with a system similar to the one described above. Because we are not a ci=
sco shop (and VMPS is deprecated) we are employing 802.1x MAC address authe=
ntication and dynamic VLAN assignment via RADIUS. The system is designed t=
o be a full-campus solution, but could be deployed to ResNet only if desire=
d.
At this time, all proof-of-concept and integration tests have been complete=
d, and I am in the process of finishing the management scripts and registra=
tion user interface. Notes and code can be made available to any intereste=
d parties.
As far as why we are doing this, I find the cost of implementing the NAC is=
too much considering what we get out of it. While the 802.1X/RADIUS/DVA s=
olution does not provide me with the same level of control that the NAC doe=
s, it also doesn't require the client software that seems to degrade our us=
er experience so much. I want to be able to identify a machine on a networ=
k as belonging to a particular student, and take enforcement measures if ne=
cessary. Since this provides me with a big "Internet kill switch" on each =
machine, it works well enough for my purposes.
-Jordan
Network Administrator
Saint Martin's University
5300 Pacific Ave SE
Lacey, WA 98503-7500
(360) 486-8838
jboland@stmartin.edu<mailto:jboland@stmartin.edu>
From: Resnet Forum [mailto:RESNET-L@LISTSERV.ND.EDU] On Behalf Of Michael P=
Hizny
Sent: Tuesday, June 14, 2011 5:29 AM
To: RESNET-L@LISTSERV.ND.EDU
Subject: NAC solution removal
After having a NAC solution in place for the last 8 years, we are re-evalua=
ting whether or not we really need to support a solution of this type anymo=
re. Have any other Universities done, or considered removing their NAC sol=
ution?
Michael Hizny
Binghamton Univeristy
___________________________________________________ You are subscribed to t=
he ResNet-L mailing list.
To subscribe, unsubscribe or search the archives, go to http://LISTSERV.ND.=
EDU/archives/resnet-l.html ________________________________________________=
___
___________________________________________________ You are subscribed to t=
he ResNet-L mailing list.
To subscribe, unsubscribe or search the archives, go to http://LISTSERV.ND.=
EDU/archives/resnet-l.html ________________________________________________=
___
___________________________________________________ You are subscribed to t=
he ResNet-L mailing list.
To subscribe, unsubscribe or search the archives, go to http://LISTSERV.ND.=
EDU/archives/resnet-l.html ________________________________________________=
___
___________________________________________________
You are subscribed to the ResNet-L mailing list.
To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________
--_000_648355A0EA9BCE4C8E867D496C8F41B54AC56753Abelstmartinedu_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable
<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
{font-family:"Cambria Math";
panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
{font-family:Calibri;
panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
{font-family:Tahoma;
panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
{margin:0in;
margin-bottom:.0001pt;
font-size:12.0pt;
font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
{mso-style-priority:99;
color:blue;
text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
{mso-style-priority:99;
color:purple;
text-decoration:underline;}
p
{mso-style-priority:99;
mso-margin-top-alt:auto;
margin-right:0in;
mso-margin-bottom-alt:auto;
margin-left:0in;
font-size:12.0pt;
font-family:"Times New Roman","serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
{mso-style-priority:99;
mso-style-link:"Balloon Text Char";
margin:0in;
margin-bottom:.0001pt;
font-size:8.0pt;
font-family:"Tahoma","sans-serif";}
span.BalloonTextChar
{mso-style-name:"Balloon Text Char";
mso-style-priority:99;
mso-style-link:"Balloon Text";
font-family:"Tahoma","sans-serif";}
span.apple-tab-span
{mso-style-name:apple-tab-span;}
span.EmailStyle21
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.EmailStyle22
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.EmailStyle23
{mso-style-type:personal;
font-family:"Calibri","sans-serif";
color:#1F497D;}
span.EmailStyle24
{mso-style-type:personal-reply;
font-family:"Calibri","sans-serif";
color:#1F497D;}
.MsoChpDefault
{mso-style-type:export-only;
font-size:10.0pt;}
@page WordSection1
{size:8.5in 11.0in;
margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">Hi Dan,<o:p></o:p></span>=
</p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">You are correct we are no=
t able to enforce client policies without an agent, as student machines are=
not university owned.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">I’ll start with gue=
st access. I am building into the system a mechanism to ‘mint&#=
8217; guest accounts which can be used to register devices on the network.&=
nbsp; As
a guest you are segregated into a private VLAN which allows internet acces=
s, but no on-campus resources. There are a few unanswered questions a=
t this point, of which I suspect that printing will be the most important.&=
nbsp; We have a web-print capability here,
so I do not expect that to be an issue. As a guest, I don’t ex=
pect you to need access to my file shares, so I am perfectly fine with prov=
iding you with Internet access and nothing more.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">Next, remediation. =
In the NAC/Bradford model, the remediation network has access to anti-virus=
updates, windows updates, etc. In my model, this network does
not exist in the same sense because I do not enforce client policies. =
; No antivirus policies to enforce =3D no remediation necessary.<o:p></o:p>=
</span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">So, when you ask about re=
mediation, you are really asking about AUP violations and “strange ne=
twork traffic”, i.e. malware. This is where the traditional rem=
ediation
network would be helpful, and the latest software on our PacketLogic may b=
e able to help me there. I haven’t done any proof-of-concepts o=
n this yet, but I am relatively unconcerned with this. Let me explain=
why.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">In the event of a AUP vio=
lation, such as a complaint of copyright infringement, we can “jail&#=
8221; a machine in a blackhole VLAN, assuming that is what you desire
to do. My last school had an automated graduated response system whe=
re you were cut off of the network for 1 or 2 weeks, followed by a meeting =
with student affairs. SMU does not currently have such a policy in pl=
ace (working on it). We don’t get many copyright
complaints.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">In the event of virus inf=
ection, if we detect strange traffic we can also “jail” the use=
r. We can present a helpful message to them and instruct them to appr=
oach
our helpdesk for assistance resolving the issue, if necessary. This =
is the most difficult thing to be comfortable with, but it isn’t as s=
cary in practice as it sounds on paper. If a student called and told =
us that they had cleaned the infection (we provided
local caches of several current antivirus products, and an ‘automate=
d cleaning script’ which would allow them to run with zero user inter=
action), we would release them. Occasionally, they would still be inf=
ected, so we would require their computer to be brought
to us, or we would schedule a housecall and clean it up on-site.<o:p></o:p=
></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">This sounds like a heavy =
support load, but it really wasn’t too bad. At my last school, =
I was responsible for the end-user support for the ResNet system of
approximately 2000 students. I was half-time, and we had a full-time=
administrator. There was one other student who would help with the s=
upport when necessary, as well as another member of the professional staff =
who again would help as time was available.
So our support load was approximately 2.25 FTE. Then take into accou=
nt that our netadmin had other duties, and wasn’t available for virus=
cleaning, so our user-facing support was really closer to 1.25 FTE. At SMU=
, we are a much smaller school, and while we
have a smaller IT shop, we also do not have the distinction of “self=
-funded” IT (like I was) vs. “state-funded” IT, so we can=
pool our work-study students and other desktop support staff. Our ca=
mpus is also much, much smaller, so I am not concerned about
the support load, and if you have a handful of talented student workers, I=
suspect that you need not be concerned about it either.<o:p></o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">Of course, for this to wo=
rk, you have to be able to identify “strange traffic” and take =
action. I haven’t gotten that far in my implementation yet, but=
there
are numerous ways to go about generating data for analysis. I suspec=
t that Perl will be the key to making this part of the system work.<o:p></o=
:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">-Jordan<o:p></o:p></span>=
</p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt;font-family:"=
;Tahoma","sans-serif"">From:</span></b><span style=3D"font-s=
ize:10.0pt;font-family:"Tahoma","sans-serif""> Resnet F=
orum [mailto:RESNET-L@LISTSERV.ND.EDU]
<b>On Behalf Of </b>Foerst, Daniel P.<br>
<b>Sent:</b> Tuesday, June 14, 2011 8:14 AM<br>
<b>To:</b> RESNET-L@LISTSERV.ND.EDU<br>
<b>Subject:</b> Re: NAC solution removal<o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">While I do not disagree t=
hat the whole NAC solution can degrade the Internet experience and does add=
some administrative overhead, what are you doing for remediation
in regards to your clients? In our network we can enforce system patches, =
anti-virus is updated since these systems are university owned.
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">However when it comes to =
our students we do not have that ability as we do not have ownership. Inste=
ad we require installation of an agent that ensures the
students are complying to the AUP and keeping their own systems up to date=
. Should a system fall out of compliance after a set period of time the use=
r loses Internet access.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">Similarly how to do you p=
rotect against guest access, especially if a guest is bringing a worm, viru=
s, malware, etc?<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">In today’s budget c=
onscience world I can certainly see removal of money guzzling equipment if =
you have a cheaper means to maintain the same or close to the
same level of protection for your network and I too would love to save mon=
ey where possible!<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">Thanks!<o:p></o:p></span>=
</p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">-dan<o:p></o:p></span></p=
>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">Daniel Foerst<o:p></o:p><=
/span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">Assistant Director, Netwo=
rks & Security<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">The Catholic University o=
f America<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">Washington, DC 20064<o:p>=
</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt;font-family:"=
;Tahoma","sans-serif"">From:</span></b><span style=3D"font-s=
ize:10.0pt;font-family:"Tahoma","sans-serif""> Resnet F=
orum [mailto:RESNET-L@LISTSERV.ND.EDU]
<b>On Behalf Of </b>Boland, Jordan<br>
<b>Sent:</b> Tuesday, June 14, 2011 10:35 AM<br>
<b>To:</b> RESNET-L@LISTSERV.ND.EDU<br>
<b>Subject:</b> Re: NAC solution removal<o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">My last institution didn&=
#8217;t employ a NAC, but instead used a homebrew client registration syste=
m to help keep order. MAC addresses were registered into a database,
and VMPS was used to assign machines to the correct VLAN when they connect=
ed. Machines showing ‘interesting’ behavior or subject to=
a policy sanction were either assigned to a jail VLAN or ignored completel=
y (switchport can be disabled remotely via VMPS as
well).<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">At SMU, we are in the pro=
cess of removing our Bradford NAC and replacing it with a system similar to=
the one described above. Because we are not a cisco shop
(and VMPS is deprecated) we are employing 802.1x MAC address authenticatio=
n and dynamic VLAN assignment via RADIUS. The system is designed to b=
e a full-campus solution, but could be deployed to ResNet only if desired.<=
o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">At this time, all proof-o=
f-concept and integration tests have been completed, and I am in the proces=
s of finishing the management scripts and registration user
interface. Notes and code can be made available to any interested pa=
rties.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">As far as why we are doin=
g this, I find the cost of implementing the NAC is too much considering wha=
t we get out of it. While the 802.1X/RADIUS/DVA solution
does not provide me with the same level of control that the NAC does, it a=
lso doesn’t require the client software that seems to degrade our use=
r experience so much. I want to be able to identify a machine on a ne=
twork as belonging to a particular student,
and take enforcement measures if necessary. Since this provides me w=
ith a big “Internet kill switch” on each machine, it works well=
enough for my purposes.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">-Jordan<o:p></o:p></span>=
</p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">Network Administrator<o:p=
></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">Saint Martin's University=
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">5300 Pacific Ave SE<o:p><=
/o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">Lacey, WA 98503-7500<o:p>=
</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">(360) 486-8838<o:p></o:p>=
</span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><a href=3D"mailto:jboland=
@stmartin.edu">jboland@stmartin.edu</a><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"><o:p> </o:p></span><=
/p>
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt;font-family:"=
;Tahoma","sans-serif"">From:</span></b><span style=3D"font-s=
ize:10.0pt;font-family:"Tahoma","sans-serif""> Resnet F=
orum [mailto:RESNET-L@LISTSERV.ND.EDU]
<b>On Behalf Of </b>Michael P Hizny<br>
<b>Sent:</b> Tuesday, June 14, 2011 5:29 AM<br>
<b>To:</b> RESNET-L@LISTSERV.ND.EDU<br>
<b>Subject:</b> NAC solution removal<o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p> </o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D">After having a NAC soluti=
on in place for the last 8 years, we are re-evaluating whether or not we re=
ally need to support a solution of this type anymore. Have
any other Universities done, or considered removing their NAC solution?</s=
pan><o:p></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:"Ca=
libri","sans-serif";color:#1F497D"> </span><o:p></o:p><=
/p>
<p class=3D"MsoNormal"><i><span style=3D"font-size:10.0pt;font-family:"=
;Arial","sans-serif";color:#1F497D">Michael Hizny</span></i>=
<o:p></o:p></p>
<p class=3D"MsoNormal"><i><span style=3D"font-size:10.0pt;font-family:"=
;Arial","sans-serif";color:#1F497D">Binghamton Univeristy</s=
pan></i><o:p></o:p></p>
<p class=3D"MsoNormal">___________________________________________________ =
You are subscribed to the ResNet-L mailing list.
<o:p></o:p></p>
<p>To subscribe, unsubscribe or search the archives, go to <a href=3D"http:=
//LISTSERV.ND.EDU/archives/resnet-l.html">
http://LISTSERV.ND.EDU/archives/resnet-l.html</a> _________________________=
__________________________
<o:p></o:p></p>
<p class=3D"MsoNormal">___________________________________________________ =
You are subscribed to the ResNet-L mailing list.
<o:p></o:p></p>
<p>To subscribe, unsubscribe or search the archives, go to <a href=3D"http:=
//LISTSERV.ND.EDU/archives/resnet-l.html">
http://LISTSERV.ND.EDU/archives/resnet-l.html</a> _________________________=
__________________________
<o:p></o:p></p>
<p class=3D"MsoNormal">___________________________________________________ =
You are subscribed to the ResNet-L mailing list.
<o:p></o:p></p>
<p>To subscribe, unsubscribe or search the archives, go to <a href=3D"http:=
//LISTSERV.ND.EDU/archives/resnet-l.html">
http://LISTSERV.ND.EDU/archives/resnet-l.html</a> _________________________=
__________________________
<o:p></o:p></p>
</div>
</body>
</html>
___________________________________________________
You are subscribed to the ResNet-L mailing list.
<p>
To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________
--_000_648355A0EA9BCE4C8E867D496C8F41B54AC56753Abelstmartinedu_--