SHARE
Follow this article on Twitter Facebook LinkedIn Bookmark and Share
Home >> Voice, Data, and IP >> Protocols and Standards

Juniper uses 802.1X access control

Juniper uses 802.1X access control

By:  Tim Greene  On: 01 Feb 2007 For: Network World Creator

An upgrade to Juniper Networks’ network access-control software makes it possible for customers to block network access via any switch, not just by Juniper firewalls.

An upgrade to Juniper Networks’ network access-control software makes it possible for customers to block network access via any switch, not just by Juniper firewalls.

Juniper’s Unified Access Control (UAC) 2.0, supports 802.1X port-level authentication, which can restrict what devices gain access to a network before they are assigned IP addresses. This 802.1X support puts Juniper on footing with Cisco and other vendors whose NAC schemes call for enforcement of access policies on all access switches. Juniper launched its UAC architecture using its firewalls as enforcement points with the intent of adding 802.1X later.

UAC 2.0 machines with profiles that fail security scans can be locked out of the network or quarantined on a designated virtual LAN, says John Oltsik, an analyst with Enterprise Strategy Group. UAC 2.0 still supports its existing enforcement mode of restricting access via Juniper firewalls.

UAC, Juniper’s architecture for access control, is compliant with an alternate, open-standard scheme called Trusted Network Connect promoted by Trusted Computing Group and works with any 802.1X switch. UAC competes with Cisco’s Network Admission Control, which supports enforcement by its own 802.1X switches.

Juniper also is a partner with Microsoft, so its Network Access Protection software can fit into the UAC architecture.

The Juniper 802.1X features come via technology Juniper acquired when it bought Funk Software in 2005. In particular, Juniper is adding client software called an 802.1X supplicant, which can be downloaded to machines as they seek authorization to join the network. The supplicant, sold as Odyssey Access Client by Funk, lets 802.1X switches enforce what switch-level access the supplicant machine will get.

Juniper also is adding a stripped down version of Juniper’s Steel-Belted Radius authentication, authorization and auditing software to its Infranet Controller device. Infranet Controller stores access policies and delivers them to the enforcement points. It also authenticates users and can push the 802.1X supplicants and endpoint scanning software to machines logging in.

With a RADIUS server onboard, Infranet Controllers don’t need to access a separate RADIUS server, says Rob Whitelely, an analyst with Forrester Research.

While most large businesses may have more than one RADIUS server, many are under control of remote access administrators, not security administrators, he says, so having the software integrated can reduce deployment headaches.

If customers already have suitable RADIUS servers, they can use them instead of the RADIUS capabilities that ship with UAC 2.0, he notes.

Robert Lumm, the IS supervisor for KAMOPower, says the power company serving Arkansas, Kansas, Missouri, Oklahoma and headquartered in Vinita, Okla., plans to use UAC 2.0 to restrict access to the company network by power network affiliate companies. Most of them access via wireless, and 802.1X enforcement will let him block them before they get access to the network, he says.


Sign up for our Newsletters












Print |  Views: 781   |   Rating:offoffoffoffoff  (0 votes)
Rate this article on a scale of
1 to 5 stars,5 being the best.




Tim Greene Tim Greene is a contributor to the International Data Group (IDG) News Service, which publishes global technology stories from bureaus around the world to more than 300 publications in more than 60 countries.

Related Content

University of Toronto researchers uncover Chinese computer spy network
University of Toronto researchers uncover Chinese computer spy networkGhostNet compromised ministries of foreign affairs, embassies, news media and the office of the Dalai Lama. How a Canadian team exposed the network
Juniper stresses simplicity in new data centre architecture
Juniper stresses simplicity in new data centre architectureCompany claims using its recently-announced products can chop one tier from designs. However, one industry analyst says the vision doesn't deal with new technologies such as unified fabric
Blade software stacks, virtualizes
Blade software stacks, virtualizesNetwork switches across multiple chassis or racks can be managed as a single virtual switch, according to Blade Network Technolgies
Trying to understand parliamentarians' misunderstanding of core new technology issues
when asked about what the core concepts are for understanding what made “new media” possible, i talk about two things: the movement away from communications technology where the network was smart and the terminals were dumb (radio, television, telephone), towards a design where the network is dumb and the terminals are smart (also known as the
blog comments powered by Disqus