Email this article   Print article 


CRN Interview: Cisco's Chief Security Officer Explains NAC Strategy Shift

By Kevin McLaughlin
August 03, 2006    3:00 PM ET

Page 1 of 2

As chief security officer for Cisco Systems, John Stewart is tasked with securing an enterprise network of more than 60,000 PCs and managing the San Jose, Calif., networking giant's security programs. At the Black Hat security conference in Las Vegas this week, Stewart talked with CRN about recent developments in Cisco's Network Admission Control (NAC) initiative as well as larger issues affecting the security industry.

CRN: Why did Cisco decide to reposition the Clean Access Appliance, now called the NAC Appliance, for enterprise NAC deployments? What does this mean for the industry framework that Cisco envisions becoming a standard for deploying NAC?

STEWART: The framework is progressing as expected. In the past year, we've moved from a purely framework approach to NAC to one that includes the framework and the NAC Appliance. That move has resonated very well with customers who are interested in bridging a multivendor network--or bridging a network that's being upgraded to make it ready for NAC--but would like some usable results immediately.

We've learned that we have enterprise customers who feel the appliance model is what they would like to do philosophically. Instead of placing NAC onto every port or every single network jack, they want to deploy the appliance. We've also learned there are customers looking for immediate, short-term results where they can deploy NAC quickly--and to a degree seamlessly--without changing their network topology.

While customers have bought into the framework vision and want to deploy network security all the way to the port, they're feeling short-term pain. As a result, we've had customers ask Cisco for an interim step they can take as we work toward the NAC framework topology, because it's going to take years for us to roll it out.

CRN: Where do things stand with the work being done to make Cisco's Network Admission Control and Microsoft's Network Access Protection interoperate?

STEWART: Same as it always has been. These two technologies will work together, and we are both committed to making that happen. Part of the reason we don't talk about it is that Cisco and Microsoft are building at exactly the same time. We're building NAC; they're building Vista. We're just making sure to constantly be in communication with Microsoft to ensure that interoperability is there.

We don't yet have the reference architecture that would allow us to point and say, 'Here's exactly how NAC and NAP are going to work together.' We know what we're both working toward, but we don't have a Vista/NAC deployable field trial yet because we're both in the midst of building it.

NEXT: Cisco's acquisition of Meetinghouse Data Communications



1 | 2 | Next >>

To continue reading this article, please download the free CRN Tech News app for your iPad or Windows 8 device.
Related: Videos | Slide Shows | Comments

SHARE THIS ARTICLE

More Security

Recent Articles

Head-To-Head: Symantec Vs. McAfee In Endpoint Protection

McAfee and Symantec are archrivals with a firm grip on the North American security market. CRN pits both vendors' endpoint security products against each other and names a winner.

The 8 Steps Behind The Massive $45M Cyber Bank Heist

More than $45 million was stolen from banks in the U.S. and 19 other countries in a scheme that law enforcement is calling an international conspiracy to drain millions from bank accounts using stolen debit cards and PIN numbers. Here's how they did it.

Name Of The Game: Top 10 States For Identity Theft

A Federal Trade Commission report provides statistics on identity theft and fraud complaints in 2012. Learn which state has the dubious distinction of having the most victims.

  More Slide Shows




Related Videos
Loading...