- Nokia's new N97 vs. the iPhone
- Talk-powered cell phones?
- FBI: Copper thieves jeopardize U.S. infrastructure
- 10 Microsoft research projects
- Smartphone smackdown: Storm vs. iPhone
If the LAN is supposed to get smarter and help us improve security-and other control features - with enforcement, what does that mean for policy and identity? Right now, it seems like all these aspects are separate - do you see them coming together?
You're absolutely right that all these pieces - the network, the identity store, and policy - need to work in concert to do control right in the LAN. Currently, these three elements are fairly separate, but ultimately, they need to be much more tightly integrated to really simplify the administration of controls in the LAN.
Let's look at each piece in turn.
The network: Today, most network devices offer fairly limited enforcement. Standards like 802.1X that allow or deny a user access to the LAN are typical of the capabilities in today's infrastructure. But these mechanisms are fairly blunt, and the infrastructure typically relies on an outside "brain" to tell it how to act on the traffic.
The identity store: This area is probably the most evolved, with well-defined standards and implementations for accessing both a user's identity and role. Active Directory, RADIUS, and LDAP all provide strong options, and other devices can successfully tap into these stores and use the data residing there.
Policy: Despite years of work on policy-based management, with architecture standards for policy enforcement points and policy administration points, too few organizations have networks that can take advantage of these architectures. So for the most part, policy is done by different vendors. Think of all the various policy stores common in networks today - those for wireless, VPN, NAC, identity and access management, and security are just a few examples of how rampantly these policy stores have grown.
So where are we headed?
The network is definitely getting smarter. We're seeing more intelligent devices-at the access layer, LAN core, and LAN/WAN boundary-that understand users and applications and offer greater flexibility for enforcement. The strongest of these devices can maintain their own policy stores, currently derived from vendor-specific policy engines, and act on traffic independently of those engines.
The network needs to bind with the identity store, and an evolution toward this is definitely in progress. The simple case of an 802.1X switch is the first step; an intelligent switch that uses the information in an identity store is an even stronger example. The switch learns the user's name and role, and associates them with the application currently running to apply policy.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment