[26513] in resnet

home help back first fref pref prev next nref lref last post

Re: NAC solution removal

daemon@ATHENA.MIT.EDU (Boland, Jordan)
Tue Jun 14 12:07:06 2011

Content-Language: en-US
Content-Type: multipart/alternative; boundary="_000_648355A0EA9BCE4C8E867D496C8F41B54AC56753Abelstmartinedu_"
MIME-Version: 1.0
Message-ID:  <648355A0EA9BCE4C8E867D496C8F41B54AC56753@Abel.stmartin.edu>
Date:         Tue, 14 Jun 2011 16:06:36 +0000
Reply-To: Resnet Forum <RESNET-L@listserv.nd.edu>
From: "Boland, Jordan" <JBoland@stmartin.edu>
To: RESNET-L@listserv.nd.edu
In-Reply-To:  <73B1B6A7A6FAD74AAB34CF95A097C5EA1F5061E9@MAILSRV06.cua.edu>

--_000_648355A0EA9BCE4C8E867D496C8F41B54AC56753Abelstmartinedu_
Content-Type: text/plain; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

Hi Dan,

You are correct we are not able to enforce client policies without an agent=
, as student machines are not university owned.

I'll start with guest access.  I am building into the system a mechanism to=
 'mint' guest accounts which can be used to register devices on the network=
.  As a guest you are segregated into a private VLAN which allows internet =
access, but no on-campus resources.  There are a few unanswered questions a=
t this point, of which I suspect that printing will be the most important. =
 We have a web-print capability here, so I do not expect that to be an issu=
e.  As a guest, I don't expect you to need access to my file shares, so I a=
m perfectly fine with providing you with Internet access and nothing more.

Next, remediation.  In the NAC/Bradford model, the remediation network has =
access to anti-virus updates, windows updates, etc.  In my model, this netw=
ork does not exist in the same sense because I do not enforce client polici=
es.  No antivirus policies to enforce =3D no remediation necessary.

So, when you ask about remediation, you are really asking about AUP violati=
ons and "strange network traffic", i.e. malware.  This is where the traditi=
onal remediation network would be helpful, and the latest software on our P=
acketLogic may be able to help me there.  I haven't done any proof-of-conce=
pts on this yet, but I am relatively unconcerned with this.  Let me explain=
 why.

In the event of a AUP violation, such as a complaint of copyright infringem=
ent, we can "jail" a machine in a blackhole VLAN, assuming that is what you=
 desire to do.  My last school had an automated graduated response system w=
here you were cut off of the network for 1 or 2 weeks, followed by a meetin=
g with student affairs.  SMU does not currently have such a policy in place=
 (working on it).  We don't get many copyright complaints.

In the event of virus infection, if we detect strange traffic we can also "=
jail" the user.  We can present a helpful message to them and instruct them=
 to approach our helpdesk for assistance resolving the issue, if necessary.=
  This is the most difficult thing to be comfortable with, but it isn't as =
scary in practice as it sounds on paper.  If a student called and told us t=
hat they had cleaned the infection (we provided local caches of several cur=
rent antivirus products, and an 'automated cleaning script' which would all=
ow them to run with zero user interaction), we would release them.  Occasio=
nally, they would still be infected, so we would require their computer to =
be brought to us, or we would schedule a housecall and clean it up on-site.

This sounds like a heavy support load, but it really wasn't too bad.  At my=
 last school, I was responsible for the end-user support for the ResNet sys=
tem of approximately 2000 students.  I was half-time, and we had a full-tim=
e administrator.  There was one other student who would help with the suppo=
rt when necessary, as well as another member of the professional staff who =
again would help as time was available.  So our support load was approximat=
ely 2.25 FTE.  Then take into account that our netadmin had other duties, a=
nd wasn't available for virus cleaning, so our user-facing support was real=
ly closer to 1.25 FTE. At SMU, we are a much smaller school, and while we h=
ave a smaller IT shop, we also do not have the distinction of "self-funded"=
 IT (like I was) vs. "state-funded" IT, so we can pool our work-study stude=
nts and other desktop support staff.  Our campus is also much, much smaller=
, so I am not concerned about the support load, and if you have a handful o=
f talented student workers, I suspect that you need not be concerned about =
it either.

Of course, for this to work, you have to be able to identify "strange traff=
ic" and take action.  I haven't gotten that far in my implementation yet, b=
ut there are numerous ways to go about generating data for analysis.  I sus=
pect that Perl will be the key to making this part of the system work.

-Jordan

From: Resnet Forum [mailto:RESNET-L@LISTSERV.ND.EDU] On Behalf Of Foerst, D=
aniel P.
Sent: Tuesday, June 14, 2011 8:14 AM
To: RESNET-L@LISTSERV.ND.EDU
Subject: Re: NAC solution removal

While I do not disagree that the whole NAC solution can degrade the Interne=
t experience and does add some administrative overhead, what are you doing =
for remediation in regards to your clients? In our network we can enforce s=
ystem patches, anti-virus is updated since these systems are university own=
ed.

However when it comes to our students we do not have that ability as we do =
not have ownership. Instead we require installation of an agent that ensure=
s the students are complying to the AUP and keeping their own systems up to=
 date. Should a system fall out of compliance after a set period of time th=
e user loses Internet access.

Similarly how to do you protect against guest access, especially if a guest=
 is bringing a worm, virus, malware, etc?

In today's budget conscience world I can certainly see removal of money guz=
zling equipment if you have a cheaper means to maintain the same or close t=
o the same level of protection for your network and I too would love to sav=
e money where possible!

Thanks!

-dan

Daniel Foerst
Assistant Director, Networks & Security
The Catholic University of America
Washington, DC 20064


From: Resnet Forum [mailto:RESNET-L@LISTSERV.ND.EDU] On Behalf Of Boland, J=
ordan
Sent: Tuesday, June 14, 2011 10:35 AM
To: RESNET-L@LISTSERV.ND.EDU
Subject: Re: NAC solution removal

My last institution didn't employ a NAC, but instead used a homebrew client=
 registration system to help keep order.  MAC addresses were registered int=
o a database, and VMPS was used to assign machines to the correct VLAN when=
 they connected.  Machines showing 'interesting' behavior or subject to a p=
olicy sanction were either assigned to a jail VLAN or ignored completely (s=
witchport can be disabled remotely via VMPS as well).

At SMU, we are in the process of removing our Bradford NAC and replacing it=
 with a system similar to the one described above.  Because we are not a ci=
sco shop (and VMPS is deprecated) we are employing 802.1x MAC address authe=
ntication and dynamic VLAN assignment via RADIUS.  The system is designed t=
o be a full-campus solution, but could be deployed to ResNet only if desire=
d.

At this time, all proof-of-concept and integration tests have been complete=
d, and I am in the process of finishing the management scripts and registra=
tion user interface.  Notes and code can be made available to any intereste=
d parties.

As far as why we are doing this, I find the cost of implementing the NAC is=
 too much considering what we get out of it.  While the 802.1X/RADIUS/DVA s=
olution does not provide me with the same level of control that the NAC doe=
s, it also doesn't require the client software that seems to degrade our us=
er experience so much.  I want to be able to identify a machine on a networ=
k as belonging to a particular student, and take enforcement measures if ne=
cessary.  Since this provides me with a big "Internet kill switch" on each =
machine, it works well enough for my purposes.

-Jordan
Network Administrator
Saint Martin's University
5300 Pacific Ave SE
Lacey, WA 98503-7500
(360) 486-8838
jboland@stmartin.edu<mailto:jboland@stmartin.edu>


From: Resnet Forum [mailto:RESNET-L@LISTSERV.ND.EDU] On Behalf Of Michael P=
 Hizny
Sent: Tuesday, June 14, 2011 5:29 AM
To: RESNET-L@LISTSERV.ND.EDU
Subject: NAC solution removal

After having a NAC solution in place for the last 8 years, we are re-evalua=
ting whether or not we really need to support a solution of this type anymo=
re.  Have any other Universities done, or considered removing their NAC sol=
ution?

Michael Hizny
Binghamton Univeristy
___________________________________________________ You are subscribed to t=
he ResNet-L mailing list.

To subscribe, unsubscribe or search the archives, go to http://LISTSERV.ND.=
EDU/archives/resnet-l.html ________________________________________________=
___
___________________________________________________ You are subscribed to t=
he ResNet-L mailing list.

To subscribe, unsubscribe or search the archives, go to http://LISTSERV.ND.=
EDU/archives/resnet-l.html ________________________________________________=
___
___________________________________________________ You are subscribed to t=
he ResNet-L mailing list.

To subscribe, unsubscribe or search the archives, go to http://LISTSERV.ND.=
EDU/archives/resnet-l.html ________________________________________________=
___

___________________________________________________
You are subscribed to the ResNet-L mailing list.

To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________

--_000_648355A0EA9BCE4C8E867D496C8F41B54AC56753Abelstmartinedu_
Content-Type: text/html; charset="us-ascii"
Content-Transfer-Encoding: quoted-printable

<html xmlns:v=3D"urn:schemas-microsoft-com:vml" xmlns:o=3D"urn:schemas-micr=
osoft-com:office:office" xmlns:w=3D"urn:schemas-microsoft-com:office:word" =
xmlns:m=3D"http://schemas.microsoft.com/office/2004/12/omml" xmlns=3D"http:=
//www.w3.org/TR/REC-html40">
<head>
<meta http-equiv=3D"Content-Type" content=3D"text/html; charset=3Dus-ascii"=
>
<meta name=3D"Generator" content=3D"Microsoft Word 14 (filtered medium)">
<style><!--
/* Font Definitions */
@font-face
	{font-family:"Cambria Math";
	panose-1:2 4 5 3 5 4 6 3 2 4;}
@font-face
	{font-family:Calibri;
	panose-1:2 15 5 2 2 2 4 3 2 4;}
@font-face
	{font-family:Tahoma;
	panose-1:2 11 6 4 3 5 4 4 2 4;}
/* Style Definitions */
p.MsoNormal, li.MsoNormal, div.MsoNormal
	{margin:0in;
	margin-bottom:.0001pt;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
a:link, span.MsoHyperlink
	{mso-style-priority:99;
	color:blue;
	text-decoration:underline;}
a:visited, span.MsoHyperlinkFollowed
	{mso-style-priority:99;
	color:purple;
	text-decoration:underline;}
p
	{mso-style-priority:99;
	mso-margin-top-alt:auto;
	margin-right:0in;
	mso-margin-bottom-alt:auto;
	margin-left:0in;
	font-size:12.0pt;
	font-family:"Times New Roman","serif";}
p.MsoAcetate, li.MsoAcetate, div.MsoAcetate
	{mso-style-priority:99;
	mso-style-link:"Balloon Text Char";
	margin:0in;
	margin-bottom:.0001pt;
	font-size:8.0pt;
	font-family:"Tahoma","sans-serif";}
span.BalloonTextChar
	{mso-style-name:"Balloon Text Char";
	mso-style-priority:99;
	mso-style-link:"Balloon Text";
	font-family:"Tahoma","sans-serif";}
span.apple-tab-span
	{mso-style-name:apple-tab-span;}
span.EmailStyle21
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle22
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle23
	{mso-style-type:personal;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
span.EmailStyle24
	{mso-style-type:personal-reply;
	font-family:"Calibri","sans-serif";
	color:#1F497D;}
.MsoChpDefault
	{mso-style-type:export-only;
	font-size:10.0pt;}
@page WordSection1
	{size:8.5in 11.0in;
	margin:1.0in 1.0in 1.0in 1.0in;}
div.WordSection1
	{page:WordSection1;}
--></style><!--[if gte mso 9]><xml>
<o:shapedefaults v:ext=3D"edit" spidmax=3D"1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
<o:shapelayout v:ext=3D"edit">
<o:idmap v:ext=3D"edit" data=3D"1" />
</o:shapelayout></xml><![endif]-->
</head>
<body lang=3D"EN-US" link=3D"blue" vlink=3D"purple">
<div class=3D"WordSection1">
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Hi Dan,<o:p></o:p></span>=
</p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">You are correct we are no=
t able to enforce client policies without an agent, as student machines are=
 not university owned.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">I&#8217;ll start with gue=
st access.&nbsp; I am building into the system a mechanism to &#8216;mint&#=
8217; guest accounts which can be used to register devices on the network.&=
nbsp; As
 a guest you are segregated into a private VLAN which allows internet acces=
s, but no on-campus resources.&nbsp; There are a few unanswered questions a=
t this point, of which I suspect that printing will be the most important.&=
nbsp; We have a web-print capability here,
 so I do not expect that to be an issue.&nbsp; As a guest, I don&#8217;t ex=
pect you to need access to my file shares, so I am perfectly fine with prov=
iding you with Internet access and nothing more.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Next, remediation.&nbsp; =
In the NAC/Bradford model, the remediation network has access to anti-virus=
 updates, windows updates, etc.&nbsp; In my model, this network does
 not exist in the same sense because I do not enforce client policies.&nbsp=
; No antivirus policies to enforce =3D no remediation necessary.<o:p></o:p>=
</span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">So, when you ask about re=
mediation, you are really asking about AUP violations and &#8220;strange ne=
twork traffic&#8221;, i.e. malware.&nbsp; This is where the traditional rem=
ediation
 network would be helpful, and the latest software on our PacketLogic may b=
e able to help me there.&nbsp; I haven&#8217;t done any proof-of-concepts o=
n this yet, but I am relatively unconcerned with this.&nbsp; Let me explain=
 why.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">In the event of a AUP vio=
lation, such as a complaint of copyright infringement, we can &#8220;jail&#=
8221; a machine in a blackhole VLAN, assuming that is what you desire
 to do.&nbsp; My last school had an automated graduated response system whe=
re you were cut off of the network for 1 or 2 weeks, followed by a meeting =
with student affairs.&nbsp; SMU does not currently have such a policy in pl=
ace (working on it).&nbsp; We don&#8217;t get many copyright
 complaints.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">In the event of virus inf=
ection, if we detect strange traffic we can also &#8220;jail&#8221; the use=
r.&nbsp; We can present a helpful message to them and instruct them to appr=
oach
 our helpdesk for assistance resolving the issue, if necessary.&nbsp; This =
is the most difficult thing to be comfortable with, but it isn&#8217;t as s=
cary in practice as it sounds on paper.&nbsp; If a student called and told =
us that they had cleaned the infection (we provided
 local caches of several current antivirus products, and an &#8216;automate=
d cleaning script&#8217; which would allow them to run with zero user inter=
action), we would release them.&nbsp; Occasionally, they would still be inf=
ected, so we would require their computer to be brought
 to us, or we would schedule a housecall and clean it up on-site.<o:p></o:p=
></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">This sounds like a heavy =
support load, but it really wasn&#8217;t too bad.&nbsp; At my last school, =
I was responsible for the end-user support for the ResNet system of
 approximately 2000 students.&nbsp; I was half-time, and we had a full-time=
 administrator.&nbsp; There was one other student who would help with the s=
upport when necessary, as well as another member of the professional staff =
who again would help as time was available.&nbsp;
 So our support load was approximately 2.25 FTE.&nbsp; Then take into accou=
nt that our netadmin had other duties, and wasn&#8217;t available for virus=
 cleaning, so our user-facing support was really closer to 1.25 FTE. At SMU=
, we are a much smaller school, and while we
 have a smaller IT shop, we also do not have the distinction of &#8220;self=
-funded&#8221; IT (like I was) vs. &#8220;state-funded&#8221; IT, so we can=
 pool our work-study students and other desktop support staff.&nbsp; Our ca=
mpus is also much, much smaller, so I am not concerned about
 the support load, and if you have a handful of talented student workers, I=
 suspect that you need not be concerned about it either.<o:p></o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Of course, for this to wo=
rk, you have to be able to identify &#8220;strange traffic&#8221; and take =
action.&nbsp; I haven&#8217;t gotten that far in my implementation yet, but=
 there
 are numerous ways to go about generating data for analysis.&nbsp; I suspec=
t that Perl will be the key to making this part of the system work.<o:p></o=
:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">-Jordan<o:p></o:p></span>=
</p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt;font-family:&quot=
;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span style=3D"font-s=
ize:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"> Resnet F=
orum [mailto:RESNET-L@LISTSERV.ND.EDU]
<b>On Behalf Of </b>Foerst, Daniel P.<br>
<b>Sent:</b> Tuesday, June 14, 2011 8:14 AM<br>
<b>To:</b> RESNET-L@LISTSERV.ND.EDU<br>
<b>Subject:</b> Re: NAC solution removal<o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">While I do not disagree t=
hat the whole NAC solution can degrade the Internet experience and does add=
 some administrative overhead, what are you doing for remediation
 in regards to your clients? In our network we can enforce system patches, =
anti-virus is updated since these systems are university owned.
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">However when it comes to =
our students we do not have that ability as we do not have ownership. Inste=
ad we require installation of an agent that ensures the
 students are complying to the AUP and keeping their own systems up to date=
. Should a system fall out of compliance after a set period of time the use=
r loses Internet access.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Similarly how to do you p=
rotect against guest access, especially if a guest is bringing a worm, viru=
s, malware, etc?<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">In today&#8217;s budget c=
onscience world I can certainly see removal of money guzzling equipment if =
you have a cheaper means to maintain the same or close to the
 same level of protection for your network and I too would love to save mon=
ey where possible!<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Thanks!<o:p></o:p></span>=
</p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">-dan<o:p></o:p></span></p=
>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Daniel Foerst<o:p></o:p><=
/span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Assistant Director, Netwo=
rks &amp; Security<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">The Catholic University o=
f America<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Washington, DC 20064<o:p>=
</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt;font-family:&quot=
;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span style=3D"font-s=
ize:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"> Resnet F=
orum [mailto:RESNET-L@LISTSERV.ND.EDU]
<b>On Behalf Of </b>Boland, Jordan<br>
<b>Sent:</b> Tuesday, June 14, 2011 10:35 AM<br>
<b>To:</b> RESNET-L@LISTSERV.ND.EDU<br>
<b>Subject:</b> Re: NAC solution removal<o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">My last institution didn&=
#8217;t employ a NAC, but instead used a homebrew client registration syste=
m to help keep order.&nbsp; MAC addresses were registered into a database,
 and VMPS was used to assign machines to the correct VLAN when they connect=
ed.&nbsp; Machines showing &#8216;interesting&#8217; behavior or subject to=
 a policy sanction were either assigned to a jail VLAN or ignored completel=
y (switchport can be disabled remotely via VMPS as
 well).<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">At SMU, we are in the pro=
cess of removing our Bradford NAC and replacing it with a system similar to=
 the one described above.&nbsp; Because we are not a cisco shop
 (and VMPS is deprecated) we are employing 802.1x MAC address authenticatio=
n and dynamic VLAN assignment via RADIUS.&nbsp; The system is designed to b=
e a full-campus solution, but could be deployed to ResNet only if desired.<=
o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">At this time, all proof-o=
f-concept and integration tests have been completed, and I am in the proces=
s of finishing the management scripts and registration user
 interface.&nbsp; Notes and code can be made available to any interested pa=
rties.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">As far as why we are doin=
g this, I find the cost of implementing the NAC is too much considering wha=
t we get out of it.&nbsp; While the 802.1X/RADIUS/DVA solution
 does not provide me with the same level of control that the NAC does, it a=
lso doesn&#8217;t require the client software that seems to degrade our use=
r experience so much.&nbsp; I want to be able to identify a machine on a ne=
twork as belonging to a particular student,
 and take enforcement measures if necessary.&nbsp; Since this provides me w=
ith a big &#8220;Internet kill switch&#8221; on each machine, it works well=
 enough for my purposes.<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">-Jordan<o:p></o:p></span>=
</p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Network Administrator<o:p=
></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Saint Martin's University=
<o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">5300 Pacific Ave SE<o:p><=
/o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">Lacey, WA 98503-7500<o:p>=
</o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">(360) 486-8838<o:p></o:p>=
</span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><a href=3D"mailto:jboland=
@stmartin.edu">jboland@stmartin.edu</a><o:p></o:p></span></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D"><o:p>&nbsp;</o:p></span><=
/p>
<div>
<div style=3D"border:none;border-top:solid #B5C4DF 1.0pt;padding:3.0pt 0in =
0in 0in">
<p class=3D"MsoNormal"><b><span style=3D"font-size:10.0pt;font-family:&quot=
;Tahoma&quot;,&quot;sans-serif&quot;">From:</span></b><span style=3D"font-s=
ize:10.0pt;font-family:&quot;Tahoma&quot;,&quot;sans-serif&quot;"> Resnet F=
orum [mailto:RESNET-L@LISTSERV.ND.EDU]
<b>On Behalf Of </b>Michael P Hizny<br>
<b>Sent:</b> Tuesday, June 14, 2011 5:29 AM<br>
<b>To:</b> RESNET-L@LISTSERV.ND.EDU<br>
<b>Subject:</b> NAC solution removal<o:p></o:p></span></p>
</div>
</div>
<p class=3D"MsoNormal"><o:p>&nbsp;</o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">After having a NAC soluti=
on in place for the last 8 years, we are re-evaluating whether or not we re=
ally need to support a solution of this type anymore.&nbsp; Have
 any other Universities done, or considered removing their NAC solution?</s=
pan><o:p></o:p></p>
<p class=3D"MsoNormal"><span style=3D"font-size:11.0pt;font-family:&quot;Ca=
libri&quot;,&quot;sans-serif&quot;;color:#1F497D">&nbsp;</span><o:p></o:p><=
/p>
<p class=3D"MsoNormal"><i><span style=3D"font-size:10.0pt;font-family:&quot=
;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D">Michael Hizny</span></i>=
<o:p></o:p></p>
<p class=3D"MsoNormal"><i><span style=3D"font-size:10.0pt;font-family:&quot=
;Arial&quot;,&quot;sans-serif&quot;;color:#1F497D">Binghamton Univeristy</s=
pan></i><o:p></o:p></p>
<p class=3D"MsoNormal">___________________________________________________ =
You are subscribed to the ResNet-L mailing list.
<o:p></o:p></p>
<p>To subscribe, unsubscribe or search the archives, go to <a href=3D"http:=
//LISTSERV.ND.EDU/archives/resnet-l.html">
http://LISTSERV.ND.EDU/archives/resnet-l.html</a> _________________________=
__________________________
<o:p></o:p></p>
<p class=3D"MsoNormal">___________________________________________________ =
You are subscribed to the ResNet-L mailing list.
<o:p></o:p></p>
<p>To subscribe, unsubscribe or search the archives, go to <a href=3D"http:=
//LISTSERV.ND.EDU/archives/resnet-l.html">
http://LISTSERV.ND.EDU/archives/resnet-l.html</a> _________________________=
__________________________
<o:p></o:p></p>
<p class=3D"MsoNormal">___________________________________________________ =
You are subscribed to the ResNet-L mailing list.
<o:p></o:p></p>
<p>To subscribe, unsubscribe or search the archives, go to <a href=3D"http:=
//LISTSERV.ND.EDU/archives/resnet-l.html">
http://LISTSERV.ND.EDU/archives/resnet-l.html</a> _________________________=
__________________________
<o:p></o:p></p>
</div>
</body>
</html>
___________________________________________________
You are subscribed to the ResNet-L mailing list.
<p>
To subscribe, unsubscribe or search the archives,
go to http://LISTSERV.ND.EDU/archives/resnet-l.html
___________________________________________________

--_000_648355A0EA9BCE4C8E867D496C8F41B54AC56753Abelstmartinedu_--

home help back first fref pref prev next nref lref last post