Survey
* Your assessment is very important for improving the work of artificial intelligence, which forms the content of this project
* Your assessment is very important for improving the work of artificial intelligence, which forms the content of this project
4.30.07 ● www.networkworld.com ● 27 CLEAR CHOICE TEST What can NAC do for you now? Test of 30 products shows benefits, limitations of existing Cisco- and standards-based NAC schemes BY JOEL SNYDER, NETWORK WORLD GLOBAL TEST ALLIANCE With Cisco’s virtual lock on the Ethernet switching market, any enterprise IT manager has to consider that company’s product line as at least one network-access-control option. But how does a Cisco-controlled NAC deployment hold up against the more industry-standards-based one offered by the Trusted Network Connect working group of We conducted the industry’s largest public test of available NAC products and found that for very simple NAC tricks, either Cisco’s or TCG-TNC’s architecture will do. In both cases, once they step out of the world of Windows clients, however, IT personnel will be pushing the bleeding edge of security technology and need to be prepared for a longer-than-normal testing and deployment schedule. For more complex NAC deployments where policies for guest users and agentless devices have to be incorporated, the combination of Cisco’s range of NAC-ready infrastructure gear and its marketing muscle, which has corralled more vendors to play its version of the NAC game,serves up a more mature, fleshed-out ecosystem for implementing advanced NAC configurations than the thinner rendition available from TCG-TNC’s partners. That said, Cisco’s NAC policy engine, the Secure Access Control Server (ACS), is the Achilles’ heel in its architecture, in that its management capabilities are lacking.The Juniper NAC policy-management engine that drives the TCG-TNC realm, Unified Access Control (UAC), is more usable and offers greater options for managing access, as well as a finer-grained set of controls. For this test, we invited Cisco, as well as any third parties that plug into the Cisco NAC scheme at any level, into our lab to prove that the Cisco Network Admission Control (CNAC) framework is strong enough to meet the diverse requirements of large enterprise networks. At the same time, we scoured the market for other parties willing to stand up to Cisco and its partners. With Microsoft’s Network Access Protection (NAP) still waiting for the Longhorn release to be fully functional, and the IETF’s Network Endpoint Assessment (NEA) working group barely started with meetings and discussions, the only credible alternative is TCG-TNC.We invited the TCG to help us deploy a complete NAC installation based on the nonproprietary TCG-TNC specifications. To test the CNAC and TCG-TNC NAC ecosystems, we began with a multivendor network and a pile of test servers and laptops (see “How we did it” at www.nwdocfinder .com/8421). For this test, however, the network was not as important as either the use scenarios or the security policies we tried to implement within each framework. Cisco’s network engineering team showed up with a list of 43 separate scenarios they thought we should test, rang- nww.com the Trusted Computing Group and backed by Cisco competitor Juniper Networks? More NAC online Joel Snyder’s assessment of NAC management. SSL VPN’s role in NAC. Where is Vista in the NAC picture? Our NAC test methodology. NAC Buyer’s Guide. You can access all of these resources from our introduction page at www.nwdocfinder.com/8336 ing from the obvious (Windows XP clients everywhere) to the more obscure but still plausible, such as Pre-Execution Environment (PXE) boot, where timing values are particularly important. The TCG-TNC team was only a little less ambitious: By the time we concluded testing with them,we had deployed 22 scenarios. To set the focus, we made our own list of nine scenarios, divided into three categories: ● Employees with managed and unmanaged Windows XP systems, as well as Mac OS X systems. ● Guests or contractors using Windows and Mac systems, as well PDA-based clients. ● Embedded devices including printers and VoIP phones. From here, we assessed what role each product played inside each scenario within both NAC architectures. Because of the sheer number of products tested (more than 30), we’ve divided our presentation of test results based on the NAC roles: authentication, endpoint security, enforcement and management. Snyder is a senior partner at Opus One in Tucson, Ariz. He can be reached at [email protected]. The art of NAC authentication Tactics vary based on use scenario BY JOEL SNYDER, NETWORK WORLD GLOBAL TEST ALLIANCE Because it’s the first step in the NAC process, we began our testing with authentication: How will users identify themselves to the network? We started with a simple test case:one enforcement point using 802.1X for authentication, virtual LAN (VLAN) assignment for access control, one policy server, no endpoint security and a Windows XP client. For a Cisco Network Admission Control (CNAC) enforcement point,we used the Cisco Catalyst 3750 switch,a workhorse and solid performer,at the edge of the network.(Cisco offered an enterprise-sized Cisco Catalyst 6509 switch, but because we weren’t testing performance, we used the 3750 as a smaller and more environmentally friendly test case.) CNAC’s policy server, running on our management network and accessible to the Catalyst switch, was Cisco Secure Access Control Server (ACS) Version 4.1, the only choice for CNAC.Endpoint authentication was handled by Cisco’s Cisco Secure Services Client (CSSC) as an 802.1X supplicant, with the Cisco Trust Agent layered on top, both running on top of Windows XP. On the Trusted Computing Group’s Trusted Network Connect (TCG-TNC) side, we had more choice in some areas and less in others. Our initial enforcement point was an Enterasys Matrix C2-series switch.For a policy server,we started with Juniper’s Unified Access Control (UAC) server, the IC-4000, the strongest contender supporting the TCGTNC NAC framework. For the endpoint, we installed Juniper’s UAC Agent,which included the 802.1X supplicant and posture-checking capabilities. We expected this to be a slam-dunk test,and it was. We then complicated the test network. We added a Cisco access point to the CNAC side of things, and an Aruba mobility controller to the TCG-TNC side. We also threw three more switches into the TCG-TNC setup,an HP ProCurve Switch 5406zl, a Cisco Catalyst 3750, and an Extreme Networks Summit X450a.All the new gear, wired and wireless, worked flawlessly in our simple, Windows 4.30.07 printers all on the same ports. Of course, using a MAC address for authentication has its own risks. Printers usually have a label containing their MAC address somewhere that’s easy to see; if not, determining the MAC address would only take a few seconds of an attacker’s time. If the MACauthenticated printer was put on a VLAN specifically for printers, firewalled to allow only printing traffic and isolated from the rest of the network, that might be an acceptable compromise. On the other hand, many network managers might want to place printers on the same VLAN as users’ systems. In that case, using MAC addresses for authentication or statically mapping a port would represent a gaping hole in the security of any type of NAC strategy. Even if printers could be firewalled off, the variety of agentless devices in a network might preclude having a firewall for every type of device. Printers and VoIP phones are easy to put into special bins because they have predictable traffic patterns and destinations. But what about badge readers, security cameras, temperature sensors, UPSs and all other manner of devices plugged into the network? Cisco and the TCGTNC team had ideas about how to cope with this diversity. Cisco brought in partners Qualys and Great Bay Software, each with its own strategy for handling guests and unauthenticated devices. Qualys provides a small appliance, part of its QualysGuard service, which normally is used for vulnerability scanning across a corporate network. Our Qualys appliance talked directly to the Cisco ACS server.When a new system requested access, the ACS server sent a message using a Cisco-defined protocol to the QualysGuard appliance detailing the IP address of the requester.The QualysGuard appliance ran a quick scan and returned a status report with a pass/fail result on the new system. The integration was quick and elegant, but the actual deployment was very limiting. In this initial incarnation of the QualysGuard-NAC integration, we didn’t have a lot of options for configuring the difference between good systems and bad systems,because the report didn’t seem to give us a lot of information about what was going on. As more guest users come with firewalls running on their laptops,this approach probably will offer less useful information. Because QualysGuard has to have the IP address of a system to scan it, this approach also didn’t work for 802.1X users or MACauthenticated devices. Great Bay Software brought in its Beacon appliance to integrate with Cisco ACS and help with the problem of such devices as VoIP phones and printers. Beacon is a multipurpose device,but one of its primary tasks is a network-device discovery tool. Using a variety of techniques,such as packet sniffing and SNMP discovery, Beacon tries to associate a profile with each device on the network. With Beacon,we wouldn’t have to catalog the MAC address for every agentless device on our network and we would have some checking to reduce the risk of MACaddress spoofing by an intruder posing as a printer. We used ● www.networkworld.com ● 29 Beacon to identify our VoIP phones and printers based on how they behaved on the network. The link between Beacon and Cisco ACS is made using an Lightweight Directory Access Protocol (LDAP) connection. When an agentless device tries to connect,its MAC address is sent to 30 ● www.networkworld.com ● 4.30.07 Endpoint security requires effort BY JOEL SNYDER, NETWORK WORLD GLOBAL TEST ALLIANCE Endpoint security assessment can be the killer component that makes NAC a worthwhile investment.Testing endpoint security assessment required the most lab time and effort, but it also proved to be the NAC realm least fraught with problems. We concentrated on employee endpoint security first. In addition to its own Cisco Secure Services Client (CSSC) assessment tool, Cisco brought in four endpoint-security assessment tools, including products from Trend Micro, McAfee, LANDesk and BigFix. For the Trusted Computing Group’s Trusted Network Connect (TCG-TNC),we had tools from PatchLink, Symantec and Juniper. Just checking for antivirus and personal firewall status turned out to be too easy for both schemes. First up into our test bed were simple endpoint security tools from Trend Micro (on Cisco Network Admission Control [CNAC]) and Symantec (on TCG-TNC).We set up a policy that required employees’ machines to have current and active software, or they would be quarantined accordingly. We went on to verify that the McAfee and LANDesk products integrated successfully and handled quarantine and remediation without relevant incident. Although getting those tools installed took a long time, the integration with the Cisco Secure Access Control Server (ACS) policy engine was fairly simple. The biggest problem we ran into was getting all the different scenarios integrated into the Cisco ACS GUI.Because Cisco ACS grew from a stand-alone RADIUS server into a NAC policy engine, the pieces of policy definition and different conditions are scattered around the GUI in a very confusing manner. However, to be fair, we were pushing it. Buoyed by the success in integrating simpler endpoint security tools,we turned to the bigger dogs,represented by patch-management and compliance vendors BigFix (CNAC) and PatchLink (TCG-TNC). Both vendors were in the early stages of their NAC integration, so we had a bit of intensive technical support and some quick bug fixes to get everything stitched together in the NAC environment. This made the total integration more difficult than it had been with the simpler packages, but when everything was working — well, everything worked. Our experience with the patch-management tools was better overall than with the simpler endpoint-assessment products,because these tools had very strong remediation strategies.If you have been looking for an excuse to go to a more comprehensive patch-management and compliance tool, NAC is another arrow in the quiver. If you are running patch management, you’ll find that the user experience with both TCG-TNC and CNAC is excellent. For example, these patch-management tools are good at putting up dialog boxes telling the user what is going on and why, rather than simply saying,“You are quarantined.” Users get a feeling for what is happening and that they will emerge from purgatory once the patch-management tool has done its job. In some cases, the patch-management tools also engaged in self-remediation, such as turning on virus scanners that had been turned off. We also verified that continuous protection was in place: Users who went out of compliance during their sessions were detected and quarantined,and let back onto the LAN only when they had come back into compliance. This worked well in both CNAC and TCG-TNC. Mac woes Moving off our Windows XP environment, we had less success. Our employee-owned Mac laptops were ham- pered by the same problems we had when we tried to authenticate: The lack of a NAC client means there is no way to pass posture information from the client to the NAC policy server. The only way to get these systems onto the network with posture-checking enabled was to have them act as guest users: We didn’t run 802.1X, but let them fail through to a guest virtual LAN (VLAN) and get an IP address.Once they were on the guest VLAN, Cisco offered an easy solution, based on the QualysGuard scanning technology we’d used to gain guest access previously. With CNAC, we defined a policy that let users onto the network based on the results of the QualysGuard audit launched on them as guest users. In the TCG-TNC network, Juniper took a different approach to the problem by suggesting we use the built-in posture-checking tools of its Unified Access Control (UAC) appliance. Based on the same technology as the Juniper SSL VPN product line, the UAC posture-checker is supported on Mac and Linux platforms. In our tests, once the Mac user connected to the captive portal, the UAC appliance pushed down an endpoint-security-checking tool into the browser, and the tool checked the posture and allowed access accordingly. This approach also would work well for employees who have personal or unmanaged Windows machines without a NAC client. Agentless devices, such as our printers, Palm PDA, and Nokia E61 smart phone and VoIP phones posed no real challenge — because there was no endpoint security to test.We continued to use the tools we had installed during the authentication phases of our testing for agentless status checking, including the QualysGuard scanner, the Beacon appliance from Great Bay Software and Q1 Labs’ QRadar, all of which could act as pieces of an endpointsecurity posture-checking strategy.We discovered that the QualysGuard scanner was a little too aggressive for our slow, wireless PDA devices, causing several crashes on the Nokia E61. Beacon worked well when we integrated it with our Cisco CNAC and TCG-TNC frameworks, helping detect a Linux laptop that was pretending to be a Cisco VoIP phone. Lessons learned about endpoint security The promise of putting endpoint security, user authentication and access control together to make a solid NAC deployment seems very well fleshed out in both the CNAC and TCG-TNC frameworks. We found that higherend patch-management systems, such as PatchLink and BigFix, offered users an outstanding experience. If compliance with policy is important, all the tools we tested were solid performers. CNAC has enormous marketing muscle behind it and offered us a wider variety of endpoint-security posturechecking tools than we could find with the TCG-TNC framework. At the same time, Juniper’s UAC appliance gave us some hope for Mac and Linux posture-checking. The problem of guest users and their posture seems to be a hard one. Whether you audit guest users or try to push a posture-checker into their browsers will depend on your own security policy,and how you want to handle endpoint security for employees and guests. While both CNAC and TCG-TNC have tools to help with this, network managers might want to look at adding other protective technologies, such as an intrusionprevention system between guest users and the rest of the network. This would give greater security than posture-checking that the systems are not infected or engaged in malicious activity. ■ continued from page 29 Cisco ACS for authentication,which looks it up using LDAP in the Beacon server. If Beacon has built a profile for that device, the profile is sent back to ACS, which uses it to decide what access-control settings are appropriate. In the case of our VoIP phones and printers, we put them on the correct VLANs without having to know ahead of time what their MAC addresses were. Of course, because Beacon talked to Cisco ACS using a standardized protocol — LDAP — rather than a proprietary protocol — as QualysGuard needs to — we were able to sneak the Beacon Appliance onto our TCG-TNC network as well,with the same functionality.We did have to cope with the clumsiness of having two RADIUS servers on the TCG-TNC side, but were able to authenticate printers and VoIP phones using this technique. We brought in QRadar, a security information management product from Q1 Labs,to solve the guest and agentless device problem.We set up a QRadar appliance and linked it to the Juniper UAC policy-decision point using the TCG-TNC protocols.The idea behind QRadar’s link to TCG-TNC is outstanding: As you discover that something is wrong with a device, you should act to block or quarantine that device as soon as possible. As a SIM, QRadar is in a unique position to know when a system starts to go bad by the alerts and logs that it sets off throughout the network. Unfortunately, although the QRadar link to the Juniper UAC was a direct one using TCG-TNC protocols, the act of marking a system as bad was a manual operation, requiring the operator to select a device and set its status. We also ran into conceptual problems related to network layers.When QRadar detects a system as bad,the common identifying information is the IP address on that system, and possibly the user credentials. However, during the 802.1X authentication, when QRadar is queried for pertinent information about the system, the IP address is not known because it hasn’t been assigned yet. Lessons learned from NAC authentication From the point of view of the framework,CNAC and TCGTNC are in great shape when it comes to the mainstream case of authenticating users on Windows laptops. Everything works well at this juncture,and except for a huge pile of uncertainty about Vista (see www.nwdocfinder .com/8423), it’s shipping and ready to implement today. Adding users who have 802.1X authentication but don’t have the Cisco CSSC or Juniper UAC client revealed a crack in Juniper’s shipping product that we had to patch by adding in a second RADIUS server.The CNAC realm covered that scenario more gracefully, because it could handle different types of RADIUS queries at the same time. When we added complexity with additional scenarios, we quickly discovered that NAC calls for more hardware and software than just a RADIUS server and some client tools.Many of the capabilities of the NAC network are just as dependent on configuration flexibility within the switches and wireless devices we selected. Bringing in outside sources of information, as we did with QualysGuard,QRadar and Beacon,looks like a great way to help add security to a NAC deployment and to reduce the amount of custom configuration required in networks with many embedded devices. However, at this stage the level of integration and quality of information is basic.While there seems to be strong interest in integrating these products with both the CNAC and TCG-TNC frameworks, what we saw needs more functionality to truly smooth deployment woes. ■ See NAC enforcement, page 32 32 ● www.networkworld.com ● 4.30.07 NAC enforcement is a mixed bag BY JOEL SNYDER, NETWORK WORLD GLOBAL TEST ALLIANCE MEMBER The “C” in NAC stands for control: defining access to network resources based on the valid authentication and endpoint security posture of the user.Until this point in our testing, Cisco’s Network Admission Control (CNAC) and the Trusted Computing Group’s Trusted Network Connect (TCG-TNC) were friendly bedfellows, offering very similar functionality with many of the same high and low points in their results. When we got to the control part of the picture, we found there’s not just white and yellow cheese out there, but 246 flavors from which to choose. In this area of our comparison, our use scenarios weren’t important, because once you get to the control part, everyone — employees, guests and agentless devices — are all the same. So here we honed in on the dizzying array of options each side gave us. Even though Cisco offers a proprietary framework,it still is the world’s largest network hardware manufacturer, so the list of enforcement choices runs for pages.We started with LAN switches and 802.1X authentication,which gave us virtual LAN (VLAN)-based access controls. If you’re happy with VLANs, Cisco has about a half-dozen families of LAN switches, and two or three times that in recently retired hardware that’s still perfectly CNAC-capable. Plus, all Cisco wireless equipment, from stand-alone access points to Airespace wireless switches, could be enforcement points as well. Many Cisco switches have packet filtering capabilities, and a CNAC deployment also can employ packet filters. Even when we added these packet filters, we weren’t stretching the limits of CNAC enforcement.Cisco has what it calls “Layer 2 IP”and “Layer 3 IP”NAC clients,which forgo authentication in favor of endpoint security and enforcement measures. These NAC client modes work with switches and IOS routers for additional enforcement options. We did not test Layer 2 IP or Layer 3 IP client modes because they lack authentication, but Cisco engineers told us that authenticating versions of those clients are under development but would not say when they would be released. Cisco’s ASA series of firewall-VPN appliances also can be NAC enforcement points.We configured an ASA 5100 to be part of our CNAC deployment; that let us require an endpoint security assessment before we would let someone onto our network through an IPSec VPN tunnel. Policy tools lacking There is no shortage of outstanding control points, but there is a shortage of policy tools to make use of all this power. Because CNAC requires Cisco Secure Access Control Server (ACS),we could express only the most primitive policies because of ACS’ inherent limitations. For example, users cannot be placed in multiple groups and have overlapping access to resources. Defining policy that might combine VLAN, packet filters, VPNs and endpoint security would be nearly impossible for anything but the most basic of networks in the ACS user interface. And for every different security policy in our network,we had to make four to 10 additions in ACS. The good news is that tests of individual advanced CNAC access controls were all successful.When we added packet filters and other controls, they were pushed from the Cisco ACS server to the network enforcement point,and we were locked down. If anything will hold back advanced CNAC deployments, it’s that ACS is not up to the task of being a general network policy tool for control, and so there’s little or no point in doing any control in CNAC beyond a small set of VLANs at this juncture. Of course,that might not be a problem.In many networks, a dozen VLANs may be all the partitioning and access control required for a very successful NAC deployment. If that fits your network, you’ll probably be perfectly happy with Cisco ACS and recent-vintage (that is, any switch released in the last few years) Cisco hardware. If you only are doing VLAN-based access controls, you may be able to use non- 4.30.07 Cisco switches very successfully. That said, these have to be welldesigned switches to have the same feature set as Cisco’s Catalyst line,such as the Enterasys Matrix C2 we had in our test bed. The power of Juniper What if you really do want very strong access controls? Juniper takes NAC to the next level with the integration between its Unified Access Control (UAC) appliance an ScreenOS-based firewall product line, but only inside the TCG-TNC framework. Using Juniper’s accesscontrol model, you not only separate users based on VLANs, you also scatter firewalls inside your network to provide full, stateful firewall rules for each user. Defining NAC policy is easy and intuitive.We found that debugging the UAC appliance and ScreenOS firewalls was more complex and difficult than necessary, but once we did get the bugs worked out, everything worked as expected. The Juniper approach is powerful, but depends on a Juniper client and Juniper UAC appliance working together with Juniper firewalls -— gaining all that extra access control requires a fair amount of proprietary magic. This point was hammered home when Vernier Networks came to our lab with its EdgeWall 8800 enforcement point and the accompanying EdgeWall Control Server. As a stand-alone NAC vendor, Vernier has its own powerful story to tell (see www.nwdocfind er.com/8422), complete with stateful firewalls, multiplatform endpoint posture assessment,and integrated intrusion-prevention system in a multigigabit chassis. The 8800 enforcement point joined the TCG-TNC camp in this test, integrating with our UAC appliance for policy and endpoint security. As a pure TCG-TNC player, we were able to use only about 10% of EdgeWall’s capabilities because Lab Alliance ■ Snyder is also a member of the Network World Lab Alliance, a cooperative of the premier testers in the network industry, each bringing to bear years of practical experience on every test. For more Lab Alliance information, go to www.network world.com/alliance. all its powerful policy controls are proprietary to Vernier’s own Control Server. By driving the EdgeWall from the UAC appliance, we couldn’t push policy down to the EdgeWall — we were able to use it only as a firewalling switch. We could have taken the policy out of the UAC appliance and put all the controls in Vernier’s Control Server — a strategy that would work well in a network where EdgeWall appliances are the primary control mechanism. Enforcement lessons learned If your access controls for NAC will be limited to VLAN assignment,you won’t be stressing either the CNAC or TCG-TNC frame- works very much,nor will you find much to differentiate them. However, if you want to add advanced access controls to your NAC deployment, such as packet filters or stateful firewalling,you’ll find significant differences.While Cisco has the widest variety of hardware in the world, the CNAC framework is being held back by ● www.networkworld.com ● 33 the required Cisco ACS policy engine,an unsuitable tool for any complex network-security policy definition. You can go down the proprietary path with TCG-TNC just as easily, but get a significantly better tool in Juniper’s UAC controller,along with a wide variety of low-end and high-end enforcement points. ■