Extreme closes NAC loophole

Network specialist Extreme announces upgrades to switch firmware

Written by Dave Bailey

Network vendor Extreme has upgraded its switch firmware, ExtremeXOS (XOS), to plug a security flaw that could be used to bypass network access control (NAC) systems using Dynamic Host Configuration Protocol (DHCP) for policy control.

The upgrade will also allow better NAC rollouts that use either the IEEE 802.1x standard for policy control or Microsoft's Network Access Protection (NAP) NAC system, which is due to be rolled out with Longhorn server later this year.

Extreme’s UK technical manager, Paul O’Kelly, said, "DHCP can be compromised by a hacker or user reconfiguring their PC with a static IP address, so we've introduced a feature embedded in XOS called Trusted DHCP Server. Network admins would use the command line interface (CLI) to configure ports, which then will forward traffic from endpoints communicating by DHCP only."

Extreme is also improving NAC through enhancements to 802.1x. A new Universal Port Framework feature automatically provisions network resources when new users and devices connect. When combined with 802.1x, Universal Port gives much finer control than simple VLAN assignment and would make it simple to set up VoIP and network user policies for users in hotdesking environments.

Finally, Extreme is also furthering its support for Microsoft's NAP initiative by including the ability for the switch to quarantine endpoints automatically, while still allowing access to valid remediation servers based on information provided by the NAP policy server, which would run on Longhorn Server.

O'Kelly said that these enhancements could be used with Extreme's own NAC system, Sentriant Access Guard and that the upgrade from XOS 11.5 to 11.6 costs nothing if firms have a current valid support contract with Extreme.

Tags:

reader comments

related articles

Juniper NAC system is out

Unified Access Control network access control from Jupiter integrates Funk Soft tech 13 Nov 2006

 

Sophos targets network access control

Security vendor Sophos has bought US network access control specialist Endforce 15 Jan 2007

Network access controls evolve

Even if Cisco and Microsoft allow NAC and NAP to work together they may lose ground to rivals, reckons Martin Courtney. 18 Sep 2006

Microsoft and Cisco hook up on network access

Giants to provide joint security architecture 07 Sep 2006

AEP NACpoint appliance guards network access

AEP says the kit can work seamlessly with Cisco, Enterasys, Extreme, HP and 3Com managed network switches 19 Sep 2006

ConSentry punts policy-based application management

New features aim to improve business agility 29 Jan 2008

Juniper upgrades network access protection

Juniper updates its line of unified access control tools 04 Aug 2008

related whitepapers

today's top stories

Solid as a rock - business continuity in a global manufacturer

From power supply problems in Nigeria to email availability in Stockport, PZ Cussons is prepared for anything 02 Dec 2008

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

IT staff desperate to keep their jobs

Most would work longer hours for less pay 02 Dec 2008

VMware View 3 enhances virtual desktops

Virtual clients now take up less storage space and can be 'checked out' to a laptop 02 Dec 2008

Technology and privacy

Watch part one of a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 01 Dec 2008

Advertisement

Newsletter signup

Sign up for our range of FREE newsletters:

Existing User

Newsletter user login:

Advertisement

Jobs

Related jobs

Job of the week

Job alerts

Sign up here

Find your next job

IT Salary Checker

Check salary here

Advertisement

White papers

Search white papers

Top categories

VPN, Extranet and Intranet Solutions

WAN/ LAN Solutions

Network Security

Interoperability-Connectivity

Grid/ Utility Computing

Latest poll

Will the terrorist attacks in Mumbai affect your offshoring plans?

Will the terrorist attacks in Mumbai affect your offshoring plans?

Is India becoming a risky destination?

Previous poll results

Latest audio and video articles

Padlocked CDVideo

Technology and privacy

Watch the final video in a two-part Computing roundtable debate on the importance of putting data privacy issues at the heart of your IT plans 02 Dec 2008

Podcast imageAudio

Computing podcast - Standard Life's offshoring plans; and the prospects for government IT

The insurance giant outlines its new outsourcing strategy; and we ask if the government's economic bailout will affect its IT plans 28 Nov 2008

Latest in-depth articles

Parcel being packedFeatures

Case study: eSpares and business continuity

Online electricals business has managed to decrease its downtime 02 Dec 2008

Royal Blackburn HospitalFeatures

NHS trust recovers from server overdose

Virtualisation technology breathed new life into East Lancashire's cost-intensive system 02 Dec 2008

Advertisement

Primary Navigation