Access Control Concepts

Network Access Control Technologies

Post-connecttesting—This testing takes place at set intervals through- out the connection, ensuring endpoints continue to comply. Post-connect testing is a key component for complete endpoint integrity enforcement. Without it, end-users quickly learn that they can, for example, raise browser security settings, connect to the network, and immediately lower the settings again.

Testing Methods

To test an endpoint, a network access controller must collect information about the endpoint that the endpoint does not generally advertise about itself.

The mechanism that allows an endpoint to respond to tests is called an agent; the agent must be installed on the endpoint prior to testing. Agents fall into two general categories:

Permanent agents, which once installed remain on the endpoint perma- nently

Transient agents, which install on the endpoint temporarily at the initia- tion of each test

Instead of relying on an agent designed specifically for the endpoint integrity solution, a network access controller can leverage an application that is already installed on most endpoints. This option is called an agentless solution.

Permanent Agents. Perhaps the most straightforward approach for deploying agents is to manually install on each endpoint the agent specific to your network access controller. Some solutions, including the ProCurve NAC 800, also allow users to download and install the agent the first time the NAC attempts to test their endpoint.

Permanent agent-based solutions have several benefits:

Minimal impact on users—Once the agent is installed, testing occurs in the background. As long as the endpoint meets the criteria for connecting, users might not even notice the testing.

Control—Permanent agents can sometimes automatically correct con- figuration problems and open ports that need to be opened for testing.

Reduced bandwidth consumption—Installed permanently, the agent is not downloaded through the network every time an endpoint is tested.

1-38