Validating machines before they connect to the network

Associate
Joined
28 Oct 2002
Posts
1,819
Location
SE London
Just had a bit of an outbreak here - and it was because of some machine which didn't have AV on it. I remember at my previous company when using McAfee we had Rogue System Detection - but we use Symantec Endpoint Protection, I don't think that SEP has anything like RSD built in, so I'm wondering if there is anything out there which is a 3rd party tool or anything of the sorts?

Also, if it could stop it connecting if it doesn't have AV etc that would be awesome - I know such a thing exists as my missus had to have AV etc on her laptop before she connected up to her Uni network, but haven't a clue what it was called.

TIA.

-Rich
 
Associate
Joined
3 Oct 2008
Posts
1,890
Location
South London
Generally speaking being 100% sure an unknown machine is secure is impossible so I tend to recommend using dot1x or port security on switches so nothing can connect to the network proper without you being aware of it.

We use McAfee but it's rogue system detection is far from bullet proof and i wouldn't rely on it if you've had major issues from rogue machines.
 
Associate
Joined
13 Apr 2007
Posts
961
Location
Belfast, Northern Ireland
Have used Cisco Clean Access (and NAC) which is pretty awesome, although ti can get very expensive.

Have also deployed Symantec NAC (SNAC) in environments where there is already a significant Symantec infrastructure. The R&D phase was long since we picked the product up in it's infancy but it works pretty well now.
 
Associate
Joined
20 Aug 2003
Posts
2,139
Location
The Republic
Also, if it could stop it connecting if it doesn't have AV etc that would be awesome - I know such a thing exists as my missus had to have AV etc on her laptop before she connected up to her Uni network, but haven't a clue what it was called.


-Rich

As stated, clean access or NAC was probably what they had, a lot of universities have gone down this route. Cisco is one option, Bradford Networks do another that seems pretty useful. Either will be pretty expensive and will require some heavy duty re-engineering of your network etc.
 
Associate
Joined
14 Sep 2007
Posts
302
It probably was the Bradford Campus manager...



Just had a bit of an outbreak here - and it was because of some machine which didn't have AV on it. I remember at my previous company when using McAfee we had Rogue System Detection - but we use Symantec Endpoint Protection, I don't think that SEP has anything like RSD built in, so I'm wondering if there is anything out there which is a 3rd party tool or anything of the sorts?

Also, if it could stop it connecting if it doesn't have AV etc that would be awesome - I know such a thing exists as my missus had to have AV etc on her laptop before she connected up to her Uni network, but haven't a clue what it was called.

TIA.

-Rich
 
Back
Top Bottom