NETWORK ADMISSION CONTROLTaping Date: February 6, 2008
Air Date: March 6, 2008
Register HereGuests:Alok Agrawal, TME Manager from the Cisco NAC BU
David Anderson, PM from the Cisco NAC BU
Book RecommendationCisco NAC Appliance: Enforcing Host Security with Clean Access
Success Story:University Virtually Eliminates Infections from Internal UsersVirginia Commonwealth University (VCU) recently implemented a comprehensive Cisco security architecture, including ASA, IPS, MARS, SSL VPN and NAC Appliance to protect its data and infrastructure. The video features VCU's Cisco NAC deployment and how it helps control network access, immediately identify copyright violations, and has reduced infections from internal users by approximately 90%.
Segmentation:Segment 1: NAC Foundational ConceptsSegment 2: Server Deployment ModesSegment 3: Topology and DesignSegment 4: Behavioral Profiling Training and Certification Options Links: (some may require a CCO login)
The Chalk Talk Series is a great follow on for finding more detailed info in both audio and video form.
NAC Appliance Product Page
Cisco NAC Appliance
Show Description:In its most basic form, the concept of Network Admission Control (NAC) is quite simple: Define and enforce a security policy that establishes a minimum set of standards that must be met prior to allowing entry to the network. Simple in theory, much more complex in its execution.
NAC is not a one shot installation. It eventually should involve your entire infrastructure and address every point of entry. This usually translates into a phased approach that may involve addressing your riskiest threat vectors first followed by a gradual rollout as time and budgets allow.
Your network and your goals are unique however and these factors will dictate where and how you get started or ultimately finish.
There are details that often get left out of the standard sales pitch. Understanding the impact of your design decisions can make the difference in a project you are proud to reference and not one you would like to sweep under the rug.
This episode is about asking the hard questions as we explore the various technical options available in a mature, goal oriented, NAC implementation.
Seems that every network design question comes with the engineer’s favorite answer: it depends. What does it depend on? That’s what we cover today.
You will walk away with the following questions answered:
1. Is NAC ready for YOUR particular network?
2. What are the four deployment modes you should consider?
3. What are the design implications for VPN, Wireless, Remote Sites or a Campus?
4. What happens when things fail?
5. How do you account for non-PC devices without a bunch of manual work-arounds and dangerous choices?
Cisco NAC BlogInteresting Articles:
Is NAC DeadNAC Gains Traction“What Businesses want from NAC”In a recent NAC survey of businesses, the Aberdeen Group listed the top requirements that the respondents had for NAC. The top technology requirements were: preventing unauthorized users and machines from accessing the network; logging all access events and recording them centrally; enforcing policies on remote users; and quarantining unhealthy machines.
The SurveyQuestions - Why were certain items ranked lower....?
Is NAC Dying?Great set of NAC Articles at Dark Reading