Sophos NAC Advanced

The Sophos NAC Advanced product is a well-designed offering which balances the need for ease of administration with network protection.

The Sophos NAC Advanced product is a well-designed offering which balances the need for ease of administration with network protection.

It uses a Windows 2003 Server with SQL installed as a platform for the software-based offering. There are two ways to deploy the NAC tool.

First is an agent-based install where a client is loaded onto each machine. The second method uses a web browser and an ActiveX control.

If the client uses the dissolvable (web) agent or the software agent, the policy is pulled from the Sophos configuration interface, which resides on the Windows 2003 server.

Setting up policies is quite easy. A sample policy might require Windows XP to have Service Pack 2 installed with all of the associated hotfixes, the Sophos Anti-Virus 6 running, and with updated DAT files, and also the Sophos personal firewall installed and running.

If the client fails to meet those criteria, the machine can be placed in either a partially compliant state, or, if more controls are missing, the device will be placed in a non-compliant state.

The tool has three methods for enforcing the network policy should a device be placed into a non-compliant state.

The first is to work with a Microsoft or Lucent Dynamic Host Configuration Protocol (DHCP) server to assign an address, which only allows the client to have access to the remediation server and the internet.

The second is to use 802.1x to assign the non-compliant machine to a VLAN, which places the machine in quarantine. The third is to work with the Cisco NAC platform to further restrict access.

Sophos includes 24/7/365 support to all users with no additional charge.

Pricing is based on per seat licensing. The per-seat fees are US$14 per user per year with a minimum of 1,000 seats.

This places the offering in the middle to upper range in this Group Test, but when free lifetime support is added, the offering is very affordable.

See original article on SC Magazine US
Copyright © SC Magazine, US edition
Sophos NAC Advanced
Verdict
5 out of 5
For: An elegant solution, does not place undue burden on the admin. Against: The per seat pricing may make the cost prohibitive for some. Verdict: A great balance between ease of use and security. Free lifetime support elevates this tool to the Recommended category.
Info
Supplier:
Price when reviewed:
USD$14
Keywords

What are your thoughts on this article? Add your comment below.

To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.

NOTE: You must be a registered member of SC Magazine to post a comment.

Click here to login | Click here to register
comments powered by Disqus
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read