About
Subscribe
  • Home
  • /
  • Channel
  • /
  • TippingPoint Integrates Network Access Control into its IPS-Secured Network Solution

TippingPoint Integrates Network Access Control into its IPS-Secured Network Solution

Johannesburg, 09 Mar 2007

SecureData, a member of the JSE-listed ERP.com Group, and the African distributor for TippingPoint Technologies, a division of 3Com, today announced the availability of the latter's fine-grained network access control (NAC) solution. TippingPoint NAC enables enterprises to enforce device and user policies to ensure both endpoint compliance and granular post access compliance. This solution goes beyond traditional pre-check and post-check NAC solutions by linking device and user policies to fine-grained, continuous traffic control made possible only by an intrusion prevention system (IPS). By integrating device, user and IPS-based traffic classification and enforcement, enterprises have much greater control over network access and usage, while reducing network security cost and complexity.

"Comprehensive network security requires both access control and attack control," commented Jon Oltsik, senior analyst for Enterprise Strategy Group. "Most NAC solutions provide authorisation and authentication. Without the additional capabilities of a continuous attack control solution like the TippingPoint IPS, NAC cannot provide adequate visibility and enforcement to protect access to the network."

Entry-level NAC solutions provide endpoint authentication and some degree of health posture check at network entry. The next level of NAC solutions extends these capabilities to include interval-based post-checks of device compliance, and limited traffic inspection based on simple exploit signatures. However, these solutions lack the proven in-line performance of the TippingPoint IPS, and do not have the continuously updated security intelligence customers require for cutting-edge traffic inspection and security enforcement. In the rapidly evolving world of security threats and attacks, settling for a NAC solution with substandard classification and enforcement of traffic from each endpoint is a risky investment, leading to a false sense of security from NAC.

In a TippingPoint NAC environment, access policies subject each device and user pair to rigorous authentication, authorisation, posture compliance checks and enforcement. Non-compliant devices are directed to remediate based on policy class. User access rights are controlled through integration with existing rights management systems including Active Directory, LDAP and RADIUS. TippingPoint NAC then interoperates with the TippingPoint IPS to ensure all malicious traffic is blocked from each endpoint and suspect or non-compliant traffic triggers other policy-controlled actions, including blocking, quarantining, alerting or rate shaping. Now, network and security personnel have unprecedented control over the entire network perimeter with integrated policy-based visibility and control of users, devices and traffic flows.

Providing integrated access and attack control policies is only possible with an IPS - an IPS with proven in-line performance including multi-gigabit throughput and switch-like latency, and operating with thousands of active vulnerability filters at high accuracy. Further, the IPS must keep its security current. The Digital Vaccine(r) service from TippingPoint's DVLabs is a foundational element of the TippingPoint IPS solution, and sets it apart from competing solutions. The Digital Vaccine service delivers thousands of filters to the IPS for pre-emptive protection against worms, viruses, Trojans, denial of service attacks, spyware, phishing and voice over IP security threats.

In addition to in-line enforcement of device, user and traffic flows, TippingPoint NAC also interoperates with other forms of device and user policy enforcement including DHCP and 802.1x. The solution operates in any environment, wired or wireless, without requiring any network infrastructure change since it is deployed as a pure overlay.

By adding NAC capabilities, TippingPoint has delivered another element of its IPS-Secured Networks solution.

For further information, please contact Andrew Ochse at tel. +27 11 790 2500; fax +27 11 790 2599; e-mail andrewo@securedata.co.za

Share

TippingPoint, a division of 3Com

TippingPoint, a division of 3Com, is the leading provider of network-based intrusion prevention systems that deliver in-depth Application Protection, Infrastructure Protection, and Performance Protection for corporate enterprises, government agencies, service providers and academic institutions. Our innovative approach offers customers unmatched network-based security with unrivaled economics, ultra-high performance, scalability and reliability. TippingPoint is based in Austin, Texas

3Com Corporation

3Com is a leading provider of secure, converged voice and data networking solutions for enterprises of all sizes. 3Com offers a broad line of innovative products backed by world class sales, service and support, which excel at delivering business value for its customers. When customers exercise choice, their choice is 3Com.

SecureData

SecureData, an ERP.com company, is Africa's Premier Value-Added Distributor & Solution Provider of Perimeter, Network & Endpoint Information Security and Risk Management Solutions. As well as being the sole distributor in Sub-Saharan Africa for Trend Micro, SecureData is the Sub-Saharan African distributor for AirDefense, Application Security, Check Point Software Technologies, Cibecs, eEye, Network Engines, Precise Biometrics, Rocket Software, RSA Security, St Bernard Software, TippingPoint Technologies and Websense. For more information, visit SecureData at www.securedata.co.za

ERP.com

ERP.com is a JSE-listed IT company focused on solutions and services that address the issues of Information Risk Management. For more information, visit ERP.com at www.erpcom.co.za

Editorial contacts

Paul Booth
Global Research Partners
(082) 568 1179
pabooth@mweb.co.za