ForeScout Virtual Appliance: Security For BYOD Era

Mobile devices have changed the rules for access control. ForeScout hopes that virtualization will give its customers more choice in NAC deployment.

The concept behind network access control (NAC) used to be simple: Don't let anyone pass through the boundaries of the enterprise network unless they're compliant with security policies and can authenticate themselves. But with cloud computing and virtualization separating applications from enterprise servers and mobile devices erasing IT control of endpoints, the boundaries of the network have become blurred.

NAC vendor ForeScout is responding to this by releasing the CounterACT Virtual Appliance, a software version of its CounterACT appliance, and moving beyond NAC to include mobile security and compliance monitoring.


More Security Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

"NAC was our bread and butter until pretty much last year," said Hanan Levin, VP of product management at ForeScout." We were leaders right behind Cisco in terms of market share. It was a nice ride." But now the company wants to focus on more, not because the need for access control is disappearing but because so much more is necessary. With mobile devices either employee-owned or not capable of running an agent, requiring one on every client is no longer tenable for many organizations, so access control has to be agentless. The focus is also shifting from clients to traffic, as many enterprises can't realistically expect to control everything that connects to the network but do still need to control exactly what each client can do.

The new version of CounterACT can still use a client-side agent for organizations or applications that require them, but it also supports dissolvable agents that run temporarily for client remediation, as well as standard protocols like 802.1x. "The technology developed use-cases bigger than we had imagined," said Levin. "If you control the access, that's fine, but it's not enough. Security also depends on what's running: processes, registry, has a new application been introduced?" When this isn't possible, the system can isolate particular clients and restrict them to well-defined roles--important for guest access and for limited function devices like printers and IP phones

ForeScout hopes that the CounterACT Virtual Appliance will both extend the market for NAC and enable existing users to deploy it in different scenarios, from the cloud to branch offices where a hardware appliance can't be justified. As with other forms of virtualization, it also means that users can add capacity on demand. The need for NAC can be heavily dependent on the number of clients connecting, making this useful for networks in venues that have large spikes in visitors requiring guest access.

In common with other vendors that have virtualized their appliances, ForeScout's virtual version is functionally identical to the physical one and can be managed using the same interface. However, the company admits that virtual security isn't for everyone, noting in particular that virtualization isn't compliant with some versions of the Federal Information Processing Standards (FIPS) which require hardened hardware. "Customers may not choose to migrate to a virtual environment, and we support them in that," said Levin.

Virtual Event: Business Mobility Unleashed. Zero in on the top mobile technologies and techniques to ensure your organization thrives in the wireless world. Learn about strategies and products that offer remote user applications support, Wi-Fi management, security features, and device management. Our virtual event happens Thursday, July 14. Register now.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
Subscribe to RSS

Resource Links