Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


August 2006

QUARANTINE!

NAP keeps noncompliant machines from accessing and infecting your network
RSS
Subscribe to Windows IT Pro | See More Security Articles Here | Reprints | Or get the Monthly Online Pass—only $5.95 a month!

Kevin explained NAP's use of IPsec. "IPsec lets you protect network resources from client machines that don't have a particular credential set to prove they've met requirements. So by combining IPsec with NAP, you can have compliance checking within your network."

Arlene added, "What Kevin is talking about specifically is NAP's IPsec enforcement. You can use it for domain and server isolation."

Mike concluded, "What the survey data points out is that we need to clarify in our communication the various uses for IPsec and then specifically what we're talking about with respect to NAP."

Ease of Use
Many respondents asked, "How complex is NAP deployment?" Calvin answered, "Ease of use and the GUI were big requests in the survey. You can use a wizard-based configuration page and answer some simple questions to configure NAP. In the survey, some people said the command line was a shortcoming of existing products. We can configure, deploy, and monitor using just the UI."

For users who prefer a command line interface, Calvin noted, "When we designed the product, we had both IT generalists and specialists in mind. IT generalists want to use and configure everything through the GUI. IT specialists want to go to the command line. We're providing both GUI and command-line interfaces."

Why is ease of use such a concern? Calvin pointed out, "When it comes to narrow access authorization, there are so many moving parts: NAP needs to integrate with user authentication and machine authorization. There's the multidomain model and so many different kinds of clients. It's good that you can validate the system health, but how do you provide automatic updates to keep systems compliant? Because there are so many moving parts, Microsoft needs to provide ease of use and a well-integrated product end to end."

Most Requested Features
The survey asked readers what elements of the client they want NAP to inspect and verify. Calvin said, "I was pleased to see that the top functionalities that customers want align with what we've done. Nearly 93 percent of readers wanted NAP to verify an antivirus signature, 86.9 percent said patch level, followed by OS configuration [62.8 percent] and host firewall configuration [57.6 percent]. When we designed the product, these elements were our top goals, and these are health-status checks NAP performs."

In addition, many readers want NAP to go beyond identifying and isolating noncompliant machines by providing remediation.As one reader put it, isolating machines and "giving a user a message or a Web link doesn't provide remediation. It generates Help desk calls." Calvin agreed: "There are four pillars of NAP: client validation, isolation, remediation, and ongoing compliance. Automatic remediation is built into the product with the System Health Agent (SHA). If your machine is out of compliance, you'll be notified of the consequence—for example, limited network connectivity. But while you're getting the notification, SHA will do its best to automatically remediate. If a machine is out of compliance, it will follow SHA's instructions, such as turning on the firewall, to get out of quarantine."

Turning on a firewall is a quick solution, Calvin admitted, but some compliance actions, "such as downloading a service pack, can take hours. You can configure such actions on the server side." For example, you can specify deferred enforcement, which Calvin explained: "I won't quarantine you immediately, but you have 30 days to comply with the corporate policy of downloading a service pack. Then NAP will download automatically." Calvin emphasized, "We don't expect users to go to a Web site and download patches or turn on the firewall. That should happen automatically."

It's All in the Policy
What were the key takeaways for the NAP team? Kevin said, "This survey really drove home the importance of ease of use. Also, we noted some confusion about using IPsec, so we need to do clarity and focus on IPsec in our guidance."

Kevin continued, "Another point was that 70 percent said they have a written security policy. Developing security policies is the most important step. Any enforcement technology is only truly effective if the proper level of thinking has gone into developing appropriate access policies. So we need to educate people about why they need a policy and what that policy is. Just installing NAP does nothing for you if you don't have anything to marry that to."

Mike added, "Maybe it's a catch-22. Why create a policy if you have nothing to enforce it? Maybe NAP is the catalyst for the other 30 percent to develop a security policy."

End of Article

   Previous  1  [2]  Next  


Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
The Memory-Optimization Hoax

Don't believe the hype. At best, RAM optimizers have no effect. At worst, they seriously degrade performance. ...

The Desktop tab is missing from the Display Properties in Windows XP?

...

Microsoft's Olympic Gold

With world records being broken at a dizzying pace, the 2008 Summer Olympics in Beijing has drawn massive audiences from around the world, most watching the games via traditional TV coverage. But behind the scenes, a massive array of technology is ...


Security Whitepapers Anti-Virus Is Dead: The Advent of the Graylist Approach to Computer Protection

Getting the Job Done: Comparing Approaches for Desktop Software Lockdown

Instant Messaging, VoIP, P2P, and games in the workplace: How to take back control

Related Events Check out our list of Free Email Newsletters!

Security eBooks Spam Fighting and Email Security for the 21st Century

Understanding and Leveraging Code Signing Technologies

A Guide to Windows Certification and Public Keys

Related Security Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.

Job Openings in IT


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

WinConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

Deploying SharePoint! In-Person Event Series – 8 Cities
Discover best practices and tips for deploying the perfect SharePoint infrastructure. Early Bird Price of $99 extended till Sept. 15th.

Find a new job now on the all new IT Job Hound!
Search jobs, post your resume, and set up job e-mail alerts!

Master SharePoint with 3 eLearning Seminars
Learn how to build a better SharePoint infrastructure and enable powerful collaboration with MVPs Dan Holme and Michael Noel. Register today!

Top Tools for Virtualization Disaster Recovery & Replication
View this web seminar on August 14th to learn about two tools that will result in faster backup and restore with P2V disaster recovery.

SharePointConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

VMworld 2008 - Sign Up Today!
Join your peers on September 15-18 at The Venetian Hotel in Las Vegas as VMware hosts VMworld 2008, the leading Virtualization event.



When managing just VMware isn’t enough
Plan/Manage/Secure – NetIQ VMware management. Download whitepaper.

What’s up with your network? Find out with ipMonitor
Availability monitoring for servers, applications and networks – FREE trial

Microsoft® Tech•Ed EMEA 2008 IT Professionals
Advance your thinking with new ideas and practical real-world solutions at Microsoft’s FIVE day technical infrastructure conference 3-7 Nov., 2008. Register before 26 September 2008 to save €300.

Order Your Fundamentals CD Today!
Gain an introduction to Exchange, learn server security requirements, and understand how unified communications can play a role in your messaging strategies with this free Exchange CD.

Are You Really Compliant with Software Regulations?
View this web seminar that will help you with compliance best practices and check out a management solution to assure that you won’t be in jeopardy of an audit.

Virtualization Congress Oct. 14-16 in London
Don't miss Virtualization Congress, the premiere EMEA conference dedicated to hardware, OS and application virtualization. Oct. 14-16 in London.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound ITTV
IT Library Technical Resources Directory Connected Home Windows Excavator Windows SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing