Symantec Network Access Control 11

The offering from Symantec is much larger than the scope of this review.

NAC 11 has additional functionality, such as desktop enforcement through client-installed firewall agents. If a client can answer yes to a series of questions, the client will then be allowed access to the LAN.

There are three types of Symantec Enforcer appliances: Gateway Enforcer, DHCP Enforcer and LAN Enforcer.

The Enforcer is a component that works together with the Symantec Policy Manager and Symantec Agents to protect the enterprise network.

Enforcers are responsible for many tasks. It is generally more convenient to administer them all in one centralized location. The Policy Manager provides this capability.

It is important to note that the Enforcer itself does not perform user-level authentication because authentication will be performed by the RADIUS, Diameter or LDAP authentication server.

A LAN Enforcer, configured to work with a RADIUS server, forwards the user information it receives from the 802.1x supplicant to the RADIUS server for authentication and does not grant access to a client that fails the user-level authentication.

When a client attempts to connect to the network, the Symantec Agent on the computer runs a host integrity check. It then sends the results to the Enforcer. If the client passes the host integrity check, it gains access to the production network.

The installation of NAC 11 is difficult enough that Symantec usually sends a professional service technician to complete the initial install.

Limited documentation for the product is available online. We were unable to locate any additional documentation.

The first year of support, which is included, is available 24/7. Additional 7/24, phone, email and website access are available after the first year.

The pricing for the NAC 11 appliance starts at US$12,732, which includes Symantec Network Access Control Starter Edition 11.0, one Symantec NAC Enforcer Appliance and one year of essential support. This makes the NAC 11 an average value.

See original article on SC Magazine US
Copyright © SC Magazine, US edition
Symantec Network Access Control 11
Verdict
4 out of 5
For: The device is 802.1x compliant, so it is not necessary to buy additional authentication servers. Against: The install is complex and confusing. It is crucial to use Symantec’s professional services. Verdict: An acceptable offering with a level of complexity to implement and manage, but the device delivers all of the features advertised.
Info
Supplier:
Price when reviewed:
USD$12732

What are your thoughts on this article? Add your comment below.

To begin commenting right away, you can log in below or register an account if you don't yet have one. Please read our guidelines on commenting. Offending posts will be removed and your access may be suspended. Abusive or obscene language will not be tolerated. The comments below do not necessarily reflect the views or opinions of SC Magazine, Haymarket Media or its employees.

NOTE: You must be a registered member of SC Magazine to post a comment.

Click here to login | Click here to register
comments powered by Disqus
Sign up to receive SC Magazine email newsletters
   FOLLOW US...
Most Read