Download What can NAC do for you now?

Survey
yes no Was this document useful for you?
   Thank you for your participation!

* Your assessment is very important for improving the work of artificial intelligence, which forms the content of this project

Document related concepts

Computer security wikipedia , lookup

Transcript
4.30.07
●
www.networkworld.com
●
27
CLEAR CHOICE TEST
What can NAC do for you now?
Test of 30 products shows benefits, limitations of existing Cisco- and standards-based NAC schemes
BY JOEL SNYDER, NETWORK WORLD GLOBAL TEST ALLIANCE
With Cisco’s virtual lock on the Ethernet switching market, any enterprise IT manager has to consider that company’s product line as at least one network-access-control option. But how does a Cisco-controlled NAC deployment
hold up against the more industry-standards-based one offered by the Trusted Network Connect working group of
We conducted the industry’s largest public test of
available NAC products and found that for very simple
NAC tricks, either Cisco’s or TCG-TNC’s architecture will
do. In both cases, once they step out of the world of
Windows clients, however, IT personnel will be pushing
the bleeding edge of security technology and need to
be prepared for a longer-than-normal testing and
deployment schedule.
For more complex NAC deployments where policies for
guest users and agentless devices have to be incorporated,
the combination of Cisco’s range of NAC-ready infrastructure gear and its marketing muscle, which has corralled
more vendors to play its version of the NAC game,serves up
a more mature, fleshed-out ecosystem for implementing
advanced NAC configurations than the thinner rendition
available from TCG-TNC’s partners.
That said, Cisco’s NAC policy engine, the Secure Access
Control Server (ACS), is the Achilles’ heel in its architecture, in that its management capabilities are lacking.The
Juniper NAC policy-management engine that drives the
TCG-TNC realm, Unified Access Control (UAC), is more
usable and offers greater options for managing access,
as well as a finer-grained set of controls.
For this test, we invited Cisco, as well as any third parties that plug into the Cisco NAC scheme at any level,
into our lab to prove that the Cisco Network Admission
Control (CNAC) framework is strong enough to meet the
diverse requirements of large enterprise networks.
At the same time, we scoured the market for other parties willing to stand up to Cisco and its partners. With
Microsoft’s Network Access Protection (NAP) still waiting for the Longhorn release to be fully functional, and
the IETF’s Network Endpoint Assessment (NEA) working
group barely started with meetings and discussions, the
only credible alternative is TCG-TNC.We invited the TCG
to help us deploy a complete NAC installation based on
the nonproprietary TCG-TNC specifications.
To test the CNAC and TCG-TNC NAC ecosystems, we
began with a multivendor network and a pile of test servers
and laptops (see “How we did it” at www.nwdocfinder
.com/8421). For this test, however, the network was not as
important as either the use scenarios or the security policies we tried to implement within each framework.
Cisco’s network engineering team showed up with a list
of 43 separate scenarios they thought we should test, rang-
nww.com
the Trusted Computing Group and backed by Cisco competitor Juniper Networks?
More NAC online
Joel Snyder’s assessment of NAC management.
SSL VPN’s role in NAC.
Where is Vista in the NAC picture?
Our NAC test methodology.
NAC Buyer’s Guide.
You can access all of these resources from our
introduction page at www.nwdocfinder.com/8336
ing from the obvious (Windows XP clients everywhere) to
the more obscure but still plausible, such as Pre-Execution
Environment (PXE) boot, where timing values are particularly important. The TCG-TNC team was only a little less
ambitious: By the time we concluded testing with them,we
had deployed 22 scenarios.
To set the focus, we made our own list of nine scenarios, divided into three categories:
● Employees with managed and unmanaged Windows
XP systems, as well as Mac OS X systems.
● Guests or contractors using Windows and Mac systems, as well PDA-based clients.
● Embedded devices including printers and VoIP
phones.
From here, we assessed what role each product played
inside each scenario within both NAC architectures.
Because of the sheer number of products tested (more
than 30), we’ve divided our presentation of test results
based on the NAC roles: authentication, endpoint security, enforcement and management.
Snyder is a senior partner at Opus One in Tucson, Ariz.
He can be reached at [email protected].
The art of NAC authentication
Tactics vary based on use scenario
BY JOEL SNYDER, NETWORK WORLD GLOBAL TEST ALLIANCE
Because it’s the first step in the NAC process, we began
our testing with authentication: How will users identify
themselves to the network?
We started with a simple test case:one enforcement point
using 802.1X for authentication, virtual LAN (VLAN)
assignment for access control, one policy server, no endpoint security and a Windows XP client.
For a Cisco Network Admission Control (CNAC) enforcement point,we used the Cisco Catalyst 3750 switch,a workhorse and solid performer,at the edge of the network.(Cisco
offered an enterprise-sized Cisco Catalyst 6509 switch, but
because we weren’t testing performance, we used the 3750
as a smaller and more environmentally friendly test case.)
CNAC’s policy server, running on our management network and accessible to the Catalyst switch, was Cisco
Secure Access Control Server (ACS) Version 4.1, the only
choice for CNAC.Endpoint authentication was handled by
Cisco’s Cisco Secure Services Client (CSSC) as an 802.1X
supplicant, with the Cisco Trust Agent layered on top, both
running on top of Windows XP.
On the Trusted Computing Group’s Trusted Network
Connect (TCG-TNC) side, we had more choice in some
areas and less in others. Our initial enforcement point was
an Enterasys Matrix C2-series switch.For a policy server,we
started with Juniper’s Unified Access Control (UAC) server,
the IC-4000, the strongest contender supporting the TCGTNC NAC framework. For the endpoint, we installed
Juniper’s UAC Agent,which included the 802.1X supplicant
and posture-checking capabilities.
We expected this to be a slam-dunk test,and it was.
We then complicated the test network. We added a
Cisco access point to the CNAC side of things, and an
Aruba mobility controller to the TCG-TNC side. We also
threw three more switches into the TCG-TNC setup,an HP
ProCurve Switch 5406zl, a Cisco Catalyst 3750, and an
Extreme Networks Summit X450a.All the new gear, wired
and wireless, worked flawlessly in our simple, Windows
4.30.07
printers all on the same ports.
Of course, using a MAC address
for authentication has its own
risks. Printers usually have a label
containing their MAC address
somewhere that’s easy to see; if
not, determining the MAC address
would only take a few seconds of
an attacker’s time. If the MACauthenticated printer was put on a
VLAN specifically for printers, firewalled to allow only printing traffic and isolated from the rest of the
network, that might be an acceptable compromise. On the other
hand, many network managers
might want to place printers on
the same VLAN as users’ systems.
In that case, using MAC addresses
for authentication or statically
mapping a port would represent a
gaping hole in the security of any
type of NAC strategy.
Even if printers could be firewalled off, the variety of agentless
devices in a network might preclude having a firewall for every
type of device. Printers and VoIP
phones are easy to put into special
bins because they have predictable traffic patterns and destinations. But what about badge
readers, security cameras, temperature sensors, UPSs and all other
manner of devices plugged into
the network? Cisco and the TCGTNC team had ideas about how to
cope with this diversity.
Cisco brought in partners Qualys and Great Bay Software, each
with its own strategy for handling guests and unauthenticated devices.
Qualys provides a small appliance, part of its QualysGuard service, which normally is used for
vulnerability scanning across a
corporate network. Our Qualys
appliance talked directly to the
Cisco ACS server.When a new system requested access, the ACS
server sent a message using a
Cisco-defined protocol to the
QualysGuard appliance detailing
the IP address of the requester.The
QualysGuard appliance ran a
quick scan and returned a status
report with a pass/fail result on the
new system.
The integration was quick and
elegant, but the actual deployment was very limiting. In this initial incarnation of the QualysGuard-NAC integration, we didn’t
have a lot of options for configuring the difference between good
systems and bad systems,because
the report didn’t seem to give us a
lot of information about what was
going on. As more guest users
come with firewalls running on
their laptops,this approach probably will offer less useful information. Because QualysGuard has to
have the IP address of a system to
scan it, this approach also didn’t
work for 802.1X users or MACauthenticated devices.
Great Bay Software brought in its
Beacon appliance to integrate
with Cisco ACS and help with the
problem of such devices as VoIP
phones and printers. Beacon is a
multipurpose device,but one of its
primary tasks is a network-device
discovery tool. Using a variety of
techniques,such as packet sniffing
and SNMP discovery, Beacon tries
to associate a profile with each
device on the network. With
Beacon,we wouldn’t have to catalog the MAC address for every
agentless device on our network
and we would have some checking to reduce the risk of MACaddress spoofing by an intruder
posing as a printer. We used
●
www.networkworld.com
●
29
Beacon to identify our VoIP
phones and printers based on how
they behaved on the network.
The link between Beacon and
Cisco ACS is made using an
Lightweight Directory Access
Protocol (LDAP) connection.
When an agentless device tries to
connect,its MAC address is sent to
30
●
www.networkworld.com
●
4.30.07
Endpoint security requires effort
BY JOEL SNYDER, NETWORK WORLD GLOBAL TEST ALLIANCE
Endpoint security assessment can be the killer component that makes NAC a worthwhile investment.Testing endpoint security assessment required the most lab time and
effort, but it also proved to be the NAC realm least fraught
with problems.
We concentrated on employee endpoint security first. In
addition to its own Cisco Secure Services Client (CSSC)
assessment tool, Cisco brought in four endpoint-security
assessment tools, including products from Trend Micro,
McAfee, LANDesk and BigFix. For the Trusted Computing
Group’s Trusted Network Connect (TCG-TNC),we had tools
from PatchLink, Symantec and Juniper.
Just checking for antivirus and personal firewall status
turned out to be too easy for both schemes. First up into
our test bed were simple endpoint security tools from
Trend Micro (on Cisco Network Admission Control
[CNAC]) and Symantec (on TCG-TNC).We set up a policy
that required employees’ machines to have current and
active software, or they would be quarantined accordingly.
We went on to verify that the McAfee and LANDesk products integrated successfully and handled quarantine and
remediation without relevant incident. Although getting
those tools installed took a long time, the integration with
the Cisco Secure Access Control Server (ACS) policy
engine was fairly simple.
The biggest problem we ran into was getting all the different scenarios integrated into the Cisco ACS GUI.Because
Cisco ACS grew from a stand-alone RADIUS server into a
NAC policy engine, the pieces of policy definition and different conditions are scattered around the GUI in a very
confusing manner. However, to be fair, we were pushing it.
Buoyed by the success in integrating simpler endpoint
security tools,we turned to the bigger dogs,represented by
patch-management and compliance vendors BigFix
(CNAC) and PatchLink (TCG-TNC). Both vendors were in
the early stages of their NAC integration, so we had a bit of
intensive technical support and some quick bug fixes to
get everything stitched together in the NAC environment.
This made the total integration more difficult than it had
been with the simpler packages, but when everything was
working — well, everything worked.
Our experience with the patch-management tools was
better overall than with the simpler endpoint-assessment
products,because these tools had very strong remediation
strategies.If you have been looking for an excuse to go to a
more comprehensive patch-management and compliance
tool, NAC is another arrow in the quiver. If you are running
patch management, you’ll find that the user experience
with both TCG-TNC and CNAC is excellent.
For example, these patch-management tools are good at
putting up dialog boxes telling the user what is going on
and why, rather than simply saying,“You are quarantined.”
Users get a feeling for what is happening and that they will
emerge from purgatory once the patch-management tool
has done its job. In some cases, the patch-management
tools also engaged in self-remediation, such as turning on
virus scanners that had been turned off.
We also verified that continuous protection was in place:
Users who went out of compliance during their sessions
were detected and quarantined,and let back onto the LAN
only when they had come back into compliance. This
worked well in both CNAC and TCG-TNC.
Mac woes
Moving off our Windows XP environment, we had less
success. Our employee-owned Mac laptops were ham-
pered by the same problems we had when we tried to
authenticate: The lack of a NAC client means there is no
way to pass posture information from the client to the NAC
policy server.
The only way to get these systems onto the network with
posture-checking enabled was to have them act as guest
users: We didn’t run 802.1X, but let them fail through to a
guest virtual LAN (VLAN) and get an IP address.Once they
were on the guest VLAN, Cisco offered an easy solution,
based on the QualysGuard scanning technology we’d used
to gain guest access previously. With CNAC, we defined a
policy that let users onto the network based on the results
of the QualysGuard audit launched on them as guest users.
In the TCG-TNC network, Juniper took a different approach to the problem by suggesting we use the built-in
posture-checking tools of its Unified Access Control
(UAC) appliance. Based on the same technology as the
Juniper SSL VPN product line, the UAC posture-checker is
supported on Mac and Linux platforms. In our tests, once
the Mac user connected to the captive portal, the UAC
appliance pushed down an endpoint-security-checking
tool into the browser, and the tool checked the posture
and allowed access accordingly. This approach also
would work well for employees who have personal or
unmanaged Windows machines without a NAC client.
Agentless devices, such as our printers, Palm PDA, and
Nokia E61 smart phone and VoIP phones posed no real
challenge — because there was no endpoint security to
test.We continued to use the tools we had installed during the authentication phases of our testing for agentless
status checking, including the QualysGuard scanner, the
Beacon appliance from Great Bay Software and Q1 Labs’
QRadar, all of which could act as pieces of an endpointsecurity posture-checking strategy.We discovered that the
QualysGuard scanner was a little too aggressive for our
slow, wireless PDA devices, causing several crashes on
the Nokia E61. Beacon worked well when we integrated
it with our Cisco CNAC and TCG-TNC frameworks, helping detect a Linux laptop that was pretending to be a
Cisco VoIP phone.
Lessons learned about endpoint security
The promise of putting endpoint security, user authentication and access control together to make a solid NAC
deployment seems very well fleshed out in both the
CNAC and TCG-TNC frameworks. We found that higherend patch-management systems, such as PatchLink and
BigFix, offered users an outstanding experience. If compliance with policy is important, all the tools we tested
were solid performers.
CNAC has enormous marketing muscle behind it and
offered us a wider variety of endpoint-security posturechecking tools than we could find with the TCG-TNC
framework. At the same time, Juniper’s UAC appliance
gave us some hope for Mac and Linux posture-checking.
The problem of guest users and their posture seems to
be a hard one. Whether you audit guest users or try to
push a posture-checker into their browsers will depend
on your own security policy,and how you want to handle
endpoint security for employees and guests.
While both CNAC and TCG-TNC have tools to help with
this, network managers might want to look at adding
other protective technologies, such as an intrusionprevention system between guest users and the rest of
the network. This would give greater security than posture-checking that the systems are not infected or
engaged in malicious activity. ■
continued from page 29
Cisco ACS for authentication,which looks it up using LDAP
in the Beacon server. If Beacon has built a profile for that
device, the profile is sent back to ACS, which uses it to
decide what access-control settings are appropriate. In the
case of our VoIP phones and printers, we put them on the
correct VLANs without having to know ahead of time what
their MAC addresses were.
Of course, because Beacon talked to Cisco ACS using a
standardized protocol — LDAP — rather than a proprietary protocol — as QualysGuard needs to — we were
able to sneak the Beacon Appliance onto our TCG-TNC
network as well,with the same functionality.We did have to
cope with the clumsiness of having two RADIUS servers on
the TCG-TNC side, but were able to authenticate printers
and VoIP phones using this technique.
We brought in QRadar, a security information management product from Q1 Labs,to solve the guest and agentless device problem.We set up a QRadar appliance and
linked it to the Juniper UAC policy-decision point using
the TCG-TNC protocols.The idea behind QRadar’s link to
TCG-TNC is outstanding: As you discover that something
is wrong with a device, you should act to block or quarantine that device as soon as possible. As a SIM, QRadar
is in a unique position to know when a system starts to
go bad by the alerts and logs that it sets off throughout
the network. Unfortunately, although the QRadar link to
the Juniper UAC was a direct one using TCG-TNC protocols, the act of marking a system as bad was a manual
operation, requiring the operator to select a device and
set its status.
We also ran into conceptual problems related to network
layers.When QRadar detects a system as bad,the common
identifying information is the IP address on that system,
and possibly the user credentials. However, during the
802.1X authentication, when QRadar is queried for pertinent information about the system, the IP address is not
known because it hasn’t been assigned yet.
Lessons learned from NAC authentication
From the point of view of the framework,CNAC and TCGTNC are in great shape when it comes to the mainstream
case of authenticating users on Windows laptops. Everything works well at this juncture,and except for a huge pile
of uncertainty about Vista (see www.nwdocfinder
.com/8423), it’s shipping and ready to implement today.
Adding users who have 802.1X authentication but
don’t have the Cisco CSSC or Juniper UAC client
revealed a crack in Juniper’s shipping product that we
had to patch by adding in a second RADIUS server.The
CNAC realm covered that scenario more gracefully,
because it could handle different types of RADIUS
queries at the same time.
When we added complexity with additional scenarios,
we quickly discovered that NAC calls for more hardware
and software than just a RADIUS server and some client
tools.Many of the capabilities of the NAC network are just
as dependent on configuration flexibility within the
switches and wireless devices we selected.
Bringing in outside sources of information, as we did
with QualysGuard,QRadar and Beacon,looks like a great
way to help add security to a NAC deployment and to
reduce the amount of custom configuration required in
networks with many embedded devices. However, at this
stage the level of integration and quality of information is
basic.While there seems to be strong interest in integrating these products with both the CNAC and TCG-TNC
frameworks, what we saw needs more functionality to
truly smooth deployment woes. ■
See NAC enforcement, page 32
32
●
www.networkworld.com
●
4.30.07
NAC enforcement is a mixed bag
BY JOEL SNYDER, NETWORK WORLD GLOBAL TEST
ALLIANCE MEMBER
The “C” in NAC stands for control: defining access to network resources based on the valid authentication and endpoint security posture of the user.Until this point in our testing, Cisco’s Network Admission Control (CNAC) and the
Trusted Computing Group’s Trusted Network Connect
(TCG-TNC) were friendly bedfellows, offering very similar
functionality with many of the same high and low points in
their results.
When we got to the control part of the picture, we found
there’s not just white and yellow cheese out there, but 246
flavors from which to choose.
In this area of our comparison, our use scenarios weren’t
important, because once you get to the control part, everyone — employees, guests and agentless devices — are all
the same. So here we honed in on the dizzying array of
options each side gave us.
Even though Cisco offers a proprietary framework,it still
is the world’s largest network hardware manufacturer, so
the list of enforcement choices runs for pages.We started
with LAN switches and 802.1X authentication,which gave
us virtual LAN (VLAN)-based access controls. If you’re
happy with VLANs, Cisco has about a half-dozen families
of LAN switches, and two or three times that in recently
retired hardware that’s still perfectly CNAC-capable. Plus,
all Cisco wireless equipment, from stand-alone access
points to Airespace wireless switches, could be enforcement points as well.
Many Cisco switches have packet filtering capabilities,
and a CNAC deployment also can employ packet filters.
Even when we added these packet filters, we weren’t
stretching the limits of CNAC enforcement.Cisco has what
it calls “Layer 2 IP”and “Layer 3 IP”NAC clients,which forgo
authentication in favor of endpoint security and enforcement measures. These NAC client modes work with
switches and IOS routers for additional enforcement
options. We did not test Layer 2 IP or Layer 3 IP client
modes because they lack authentication, but Cisco engineers told us that authenticating versions of those clients
are under development but would not say when they
would be released.
Cisco’s ASA series of firewall-VPN appliances also can be
NAC enforcement points.We configured an ASA 5100 to be
part of our CNAC deployment; that let us require an endpoint security assessment before we would let someone
onto our network through an IPSec VPN tunnel.
Policy tools lacking
There is no shortage of outstanding control points, but
there is a shortage of policy tools to make use of all this
power. Because CNAC requires Cisco Secure Access
Control Server (ACS),we could express only the most primitive policies because of ACS’ inherent limitations.
For example, users cannot be placed in multiple groups
and have overlapping access to resources. Defining policy
that might combine VLAN, packet filters, VPNs and endpoint security would be nearly impossible for anything but
the most basic of networks in the ACS user interface. And
for every different security policy in our network,we had to
make four to 10 additions in ACS.
The good news is that tests of individual advanced CNAC
access controls were all successful.When we added packet filters and other controls, they were pushed from the
Cisco ACS server to the network enforcement point,and we
were locked down.
If anything will hold back advanced CNAC deployments,
it’s that ACS is not up to the task of being a general network
policy tool for control, and so there’s little or no point in
doing any control in CNAC beyond a small set of VLANs at
this juncture.
Of course,that might not be a problem.In many networks,
a dozen VLANs may be all the partitioning and access control required for a very successful NAC deployment. If that
fits your network, you’ll probably be perfectly happy with
Cisco ACS and recent-vintage (that is, any switch released
in the last few years) Cisco hardware. If you only are doing
VLAN-based access controls, you may be able to use non-
4.30.07
Cisco switches very successfully.
That said, these have to be welldesigned switches to have the
same feature set as Cisco’s
Catalyst line,such as the Enterasys
Matrix C2 we had in our test bed.
The power of Juniper
What if you really do want very
strong access controls? Juniper
takes NAC to the next level with
the integration between its
Unified Access Control (UAC)
appliance an ScreenOS-based
firewall product line, but only
inside the TCG-TNC framework.
Using
Juniper’s
accesscontrol model, you not only separate users based on VLANs, you
also scatter firewalls inside your
network to provide full, stateful
firewall rules for each user.
Defining NAC policy is easy and
intuitive.We found that debugging
the UAC appliance and ScreenOS
firewalls was more complex and
difficult than necessary, but once
we did get the bugs worked out,
everything worked as expected.
The Juniper approach is powerful, but depends on a Juniper
client and Juniper UAC appliance
working together with Juniper
firewalls -— gaining all that extra
access control requires a fair
amount of proprietary magic.
This point was hammered home
when Vernier Networks came to
our lab with its EdgeWall 8800
enforcement point and the accompanying EdgeWall Control
Server. As a stand-alone NAC vendor, Vernier has its own powerful
story to tell (see www.nwdocfind
er.com/8422), complete with
stateful firewalls, multiplatform
endpoint posture assessment,and
integrated intrusion-prevention
system in a multigigabit chassis.
The 8800 enforcement point
joined the TCG-TNC camp in this
test, integrating with our UAC
appliance for policy and endpoint security.
As a pure TCG-TNC player, we
were able to use only about 10% of
EdgeWall’s capabilities because
Lab Alliance
■ Snyder is also a member of the
Network World Lab Alliance, a cooperative of the premier testers in the
network industry, each bringing to
bear years of practical experience on
every test. For more Lab Alliance
information, go to www.network
world.com/alliance.
all its powerful policy controls are
proprietary to Vernier’s own
Control Server. By driving the
EdgeWall from the UAC appliance,
we couldn’t push policy down to
the EdgeWall — we were able to
use it only as a firewalling switch.
We could have taken the policy
out of the UAC appliance and put
all the controls in Vernier’s Control
Server — a strategy that would
work well in a network where
EdgeWall appliances are the primary control mechanism.
Enforcement lessons learned
If your access controls for NAC
will be limited to VLAN assignment,you won’t be stressing either
the CNAC or TCG-TNC frame-
works very much,nor will you find
much to differentiate them.
However, if you want to add
advanced access controls to your
NAC deployment, such as packet
filters or stateful firewalling,you’ll
find significant differences.While
Cisco has the widest variety of
hardware in the world, the CNAC
framework is being held back by
●
www.networkworld.com
●
33
the required Cisco ACS policy
engine,an unsuitable tool for any
complex network-security policy
definition. You can go down the
proprietary path with TCG-TNC
just as easily, but get a significantly better tool in Juniper’s UAC
controller,along with a wide variety of low-end and high-end
enforcement points. ■