Saturday, January 8, 2011

The Mac App Store makes multi-Mac ownership cheaper than multi-PC ownership | COMPTIA VIDEOS! Comptia A+ Videos Training, Comptia video training at comptiavideo.com

Apple has struck a blow again Microsoft by making multi-Mac ownership cheaper than multi-PC ownership.

Note: Putting aside that whole piracy problem plaguing the Mac App Store …

How has Apple pulled off this trick? Through this simple entry in the Mac App Store FAQ:

Q: Can I use apps from the Mac App Store on more than one computer?

A: Apps from the Mac App Store may be used on any Macs that you own or control for your personal use.

People seem to have forgotten that Microsoft had an app store of sorts built into Windows Vista called Windows Marketplace. It died.

Complete Comptia A+ trainingComptia A+ Certification for just $99 at Actualkey.com

Check out the use of the word “any” in that sentence. Apple is placing no restriction (other than the personal use clause, which I’m seeking clarification on from Apple ) on the number of Macs that you can install purchased apps on.

No more having to buy software twice. Once you’ve bought it, you can install it on all your systems. Sure, the freedoms are nowhere near as broad as those offered by open source software, but as far as commercial software goes, these restrictions are about as loose as you’ll find. And these aren’t just junk ‘fart’ apps and so on. For Mac users there’s some quality stuff to be found in the Mac App Store at a decent price. Sure, not everything, everyone will ever need is there, but if that was a criteria for success, nothing would ever succeed.

Not only that, but the end to serial numbers, activation codes and the like:

Q: Do apps from the Mac App Store require activation keys, serial numbers, or registration numbers?

A: No, but you may be asked for your Apple ID and password the first time you use an app.

I don’t know about you, but to me that sounds like a serious simplification for Mac-owning consumers. Not only for those owning multiple Mac systems, but also for those upgrading to newer systems.

About the only potential gotchya I can see is this:

Q: If I have already downloaded an app from the Mac App Store, can I redownload it for free?

A: Yes. You can redownload apps from the Mac App Store as long as the app remains available. You may be asked to enter the Apple ID and password you initially used to download the app.

follow Adrian Kingsley-Hughes on Twitter

So if an app or developer vanishes from the App Store, you’re out of luck unless you’ve got a backup (in which case, you’ve still got access to the app in question).

It’s clear that when it came to the Mac App Store that Apple really did choose to ‘think different’ when it came to licensing. People seem to have forgotten that Microsoft had an app store of sorts built into Windows Vista called Windows Marketplace. It died. Why? Partly because Microsoft couldn’t see it as any more than a new way to distribute old thinking.

Whether you’re a fan of Apple or not, the company deserves some praise for making software ownership for consumers less of a hassle.

CES wrap: Nvidia, Motorola Mobility get top marks | COMPTIA VIDEOS! Comptia A+ Videos Training, Comptia video training at comptiavideo.com

The Consumer Electronics Show is about to wind down—mercifully—and it’s time to hand out grades for the major tech players. Motorola Mobility and Nvidia move to the front of the class.

This wrap focuses on the strategic positioning of the players at CES this week. Why? Let’s face it: Many of the products highlighted this week are either six months away or vaporware. At best, CES is a demoware festival. That’s part of the reason why I never go to CES. However, you do get a good feel for strategy from some key tech vendors.

With that in mind, here are my top 5 performances at CES from a strategic perspective.

Motorola Mobility: CEO Sanjay Jha did what he had to at CES. First, he diversified with AT&T and showed off the Atrix, which looks like a interesting contender to win the superphone crown. James Kendrick already has it pegged as best in show. Motorola was also out front with its Verizon Wireless 4G LTE launch with the Bionic. Toss in Motorola Mobility’s Xoom tablet (right), which appears to be a showpiece for Google’s Android Honeycomb effort, and the company had a solid CES. Motorola Mobility sees itself as a bridge between computing and mobility.

Best comptia A+ Training, Comptia A+ Certification at Certkingdom.com

Stifel Nicolaus analyst Doug Reid said:

Motorola Mobility confirmed steps to diversify carrier relationships beyond Verizon (specifically, with Atrix 4G on AT&T) give us increased confidence that management is effectively addressing the threat of iPhone arriving on Verizon in 1Q11.

Grade: A. See all on Motorola Mobility.

Nvidia: The graphics chip maker is really stepping on the gas. Its Tegra2 is at the heart of several new handsets from Motorola and LG. In addition, Nvidia is positioned at the heart of 4G devices. With Motorola’s Atrix, which docks to create a PC, Nvidia is subliminally positioning itself beyond phones. Speaking of that move, Nvidia also unveiled a CPU effort. Simply put, Nvidia was everywhere at CES—even at Audi press conferences.

Grade: A+

Samsung: At CES, Samsung is everywhere. The company is talking phones, PCs, TVs and everything in between. The biggest standout for Samsung was its slider PC, which is a workable mix between a tablet and a laptop. Is Samsung’s device an iPad killer? No way. However, Samsung may just have found a way to create a netbook done right. On the 4G device front, Samsung was also all over the place boasting powerful Android smartphones. One knock on Samsung was all the talk about Smart TV, which could be a rathole since the market is so fragmented. Also see:

* CES: First look at the Samsung’s first sliding laptop PC
* Image Gallery: Close-up look at Samsung’s first sliding laptop computer

Grade: B

Apple: Apple wasn’t at CES, but the company looks better than everyone there strategically. The biggest takeaway: Despite dozens of tablets at CES there was nothing that looked ready to duel with the iPad. Motorola’s Xoom looks promising, but the tablet needs to get to market first.

Grade: A

Google: The biggest event of CES—in my view—was the long demonstration of Android Honeycomb. Overall, the video—relayed by Jason Hiner—was impressive. If the tablet market is riding on Honeycomb, the demonstration gave me confidence that Android may just step up to the iPad plate. Google gets dinged because its TV efforts were barely worth talking about at CES.

CES video: Google’s surprise demo of Android 3.0 Honeycomb

Grade: B

Other thoughts:

* Microsoft Surface 2.0 is interesting and could be one helluva coffee table one day. Windows 8 nuggets were also notable.

* Dell’s 10-inch Streak is likely to be pushed as an enterprise device for key verticals.
* HTC had a solid CES, but is going to have trouble standing out in the Android brawl with Motorola and Samsung. I’m not sure the next-gen Sense—touted by AT&T—is much of a selling point.
* 4G marketing is a complete mess for consumers. Every carrier is now talking 4G—even if technically their networks are built for “4G speeds.” The 4G marketing is only going to confuse the consumer and everyone and their mother will be 4Gwashing. The term 4G will be meaningless by March. See: CES: The Real Cost of 4G

CCNA Training, CCNA Certification key Understanding the critical role of Cisco’s Access Control Server in Cisco NAC « CCNA KEY

Typically, you only hear about the importance of the Cisco ACS server for VPN and dial-up authentication, authorization, and accounting. However, today the Cisco ACS server is being used as the central posture server when implementing Cisco's Network Access Control (CNAC). Let's discuss the role ACS plays in NAC.


CCNA Training and CCNA Certification and more Cisco exams log in to Certkingdom.com

What is the Cisco ACS Server?

It's the job of Cisco Secure Access Control Server (ACS) to offer authentication, accounting, and authorization services to network devices. It includes routers, switches, Cisco PIX firewalls, and network access servers. Cisco Secure Access Control Server supports two major AAA protocols; namely, TACACS+ and RADIUS. Figure A shows an example of how Cisco ACS plays a role in the typical network for wireless network authentication.
Figure A

Cisco ACS can work with wireless network authentication.

Cisco ACS not only centralizes authentication (who you are) but also authorization (what you can access) and accounting (the logging of what when you logged in and out, as well as what you were granted access to). Traditionally, this was just needed for dial-up users over modem phone lines; later, for Internet VPN users. However, beginning with ACS version 4.0, Cisco ACS is performing the same authentication, authorization, and accounting functions for networks that are NAC-enabled.

You can obtain Cisco ACS in either a Windows version or an appliance version. The appliance version is called the Cisco ACS Solution Engine. The UNIX version of Cisco ACS has been discontinued.
What is a posture validation server?

When learning about and implementing Cisco NAC, there are some new terms that you must learn. One of many such terms is the posture validation server. Exactly what is this? The short answer is that Cisco ACS is the posture validation server.

Cisco Secure Access Control Server plays a prominent role in Cisco NAC as a policy decision point. Generally speaking, Cisco Secure Access Control Server connects with the Cisco Trust Agent to build much of the NAC framework. The Cisco Secure Access Control Server judges the state or health of the host. Additionally, you have a choice of downloading access lists and VLAN assignment to the NAD, to control the PC host.

The best part about Cisco Secure Access Control Server is that it also implements security policy verification of host credentials. This, in turn, enforces policy items like antivirus signature file version and OS patch level. You can extend the Cisco Secure Access Control Server policies by forwarding credentials to third-party servers.

There are some who believe the performance of the Cisco ACS server needs to be increased in order to support Cisco NAC; generally, this is not true. While Cisco ACS plays an important role in the Cisco NAC equation, it can do this for many thousands of users without a lot of horsepower.

To see what the Cisco ACS Web console looks like, check out Figure B.
Figure B

The Cisco ACS Web console.

Figure C shows Cisco NAC and how ACS plays a role.
Figure C

In this diagram, ACS is the Cisco Policy Server.
What are profiles and postures?

Cisco's NAC relies on the RADIUS authorization protocol to communicate the authorization information to ACS. The RADIUS request will contain VSAs, or vendor specific attributes. Back on the ACS server, there will be a NAP (network access profile) that determines what to do with the RADIUS request. That is because the ACS server is probably not only authenticating NAC hosts and NADs, but also VPN clients and other RADIUS clients.

Next, the ACS Server checks the authentication credentials against its own internal database, or Microsoft Active Directory (AD), for example. After that, the Type Length Value (TLV) and posture of the host requesting accesses is checked against the posture validation rules. These posture validation rules are a series of polices with multiple rules inside each policy. The decision that the ACS server makes about the posture of the PC host is made on a first-match basis. This means the NAC administrator must write the rules in a way that the most common rule is matched first. Usually, the first rule is that the client be healthy and is allowed access to the network.

Optionally, the ACS server can send the credentials off to a third-party posture validation server. This is primarily because the third-party validation server can have other types of validations and features that ACS does not support. For example, the Trend Micro OfficeScan solution works with Cisco ACS and the NAC framework to check a user's posture when it comes to the state of that user's antivirus client. Is that AV client up-to-date? Another similar solution is the McAfee Policy Enforcer.
What are audit servers?

While Cisco ACS can do auditing and logging of certain user activities, there are also third-party audit servers that are compatible with the NAC framework, such as the Qualsys Appliance, McAfee Policy Enforcer, and Altiris.
What's the downside to using Cisco ACS?

If you implement Cisco NAC, you are basically choosing to implement Cisco ACS as well. With that, there are some downsides that you should consider:

* You'll most likely want to implement 802.1X. This can be complex and will require some user training.
* You'll need Cisco routers and switches.
* You'll have to use Cisco RADIUS for authentication and the Cisco ACS server as your authentication server.
* The Cisco ACS server cannot protect itself from being attacked or from having malicious code loaded on it. Therefore, you must be very careful to apply Windows security patches and use a host-based firewall on the ACS Server.

In conclusion

The Cisco ACS server is a critical part of Cisco's NAC solution. With the help of Cisco Secure Access Control Server, you can decide who can login to the network based on their credentials. From there, you can decide if that device is healthy enough to be on the network: Do they have all the right patches, antivirus updates, and firewall settings? In addition, you can assign a different set of privileges to each user in the network. Finally, you can audit that user's activity of logging in and out of the network. Besides being a Cisco NAC AAA server, Cisco ACS also performs AAA for wireless LAN devices, dial-up users, VPN users, and more.

CCNA Training, CCNA Certification key Learn the components of Cisco’s NAC Framework « CCNA KEY

Cisco's NAC Framework is an architectural design for how multiple hardware and software components can work together to protect your network from unhealthy clients. Those clients could be PC's without the latest security patches, the latest anti-virus definitions, or a personal firewall enabled. In this article, I'll attempt to explain the complex NAC Framework as clearly as possible.


for CCNA Training and CCNA Certification and more Cisco exams log in to Actualkey.com

What are the components of the Cisco NAC Framework?

Cisco's NAC Framework attempts to solve a complex problem, and is consequently a complex solution. A full-blown implementation of the NAC Framework is not an easy task because the architecture includes lots of different components from Cisco and other vendors. For example, there is a NAC policy manager, multiple network systems, an audit server, a remediation server, and third-party security software posture validation servers. Figure A shows how the framework would work:
Figure A

The Cisco NAC Framework.

It's quite a challenge for both security and network personnel to make sure that above-mentioned components work cohesively. Irrespective of that, the Cisco-led NAC initiative is supported by majority of vendors associated with endpoint security, secure access gateways, and remediation servers.
How does the Cisco NAC Framework work?

So what can the Cisco NAC Framework do for you? Well, a lot. Here's how it works:

* If a PC host is attempting to access the network, it must be authenticated and audited for policy compliance. This attempt triggers a NAC Process.
* The PC host is running the Cisco Trust Agent (CTA).
* The Network Access Device (NAD) is the Ethernet switch attempting to initiate the network access on behalf of the PC host.
* The Extensible Authentication Protocol (EAP) is used and the host credentials are sent to a Cisco Secure Access Control Server (ACS).
* Until the entire process is complete, the PC host (your potentially malicious computer) is only passing credentials through from the Cisco Trust Agent to the network. The PC host cannot really communicate on the network.
* The Cisco Trust Agent passes credentials through a secure tunnel so that the NAD cannot see them.
* The ACS Server can pass the credentials to other servers. For example, much of the time today, these credentials are sent to Windows AD servers who can verify the credentials used. However, the credentials could also go to other servers, like LDAP or one-time-password servers.
* Based on the response of one or more authentication servers, the ACS server can grant, deny, or quarantine the PC host requesting network access. Additionally, the ACS Server can assign different levels of network access.
* To verify security policy compliance of the PC host, Cisco NAC Framework conducts network and agent-based scans.
* The Cisco NAC Framework can implement compliance checks on all types of devices.
* The Cisco NAC Framework notifies users of connection status, and if there's any problem, it automatically corrects problems by updating the machine's patches, firewall, or other settings. Optionally, the host PC can be notified whether his or her credentials allowed them network access with a pop-up window or similar function. For example, the user could get a message: "Your computer is lacking the necessary updates and therefore is not granted access to the network. In order to resume normal network access, please update your computer now at the following location: [URL]."

Figure B helps better explain the process:
Figure B

The connection process.

You should note that usually the 802.1X network authentication protocol is used to authenticate the devices to the network. The switch that the NAD is connected to must support 802.1X, or the device cannot be truly quarantined until it is authenticated and scanned.
What are the components of Cisco's NAC Framework?

Now that you understand how the framework works, you should learn a little bit about the components of the framework. These are as follows:

* Posture: The posture of a host is a set of credentials and attributes that define the state or health of a user's computer and the applications on that computer.
* Cisco Trusted Agent: Cisco Trusted Agent (CTA) is one of the integral components of Cisco NAC Framework. The CTA is termed a posture agent. Cisco Trusted Agent is basically an installed software client whose main responsibility is to collect state information from security software on the endpoint (the NAD). In addition, it also communicates the "posture" (or what it learns) to the Cisco ACS Policy Server.

It's worth mentioning in this regard that Cisco Trusted Agent only communicates with client applications that are NAC-enabled by Cisco partners. There are around 50 vendors in the market actively participating in the NAC initiative. It includes, leading patch management vendors, client security vendors, and antivirus vendors.

* Network Access Devices (NAD): The NAD is, most commonly, the switch that the PC is connected to. However, it could also be a router, VPN concentrators, or other similar network access device. Many vendors switch manufacturers support the Cisco NAC Framework.
* AAA Policy Server: The AAA policy server is the Cisco Secure Access Control Server (or ACS). The main function of the ACS Server is to act as the policy decision point in NAC deployments. Apart from that, Cisco Secure Access Control Server also evaluates user credentials and calculates the security posture of network endpoints.

Frequently, the Cisco Secure ACS Server sends out per-user authorization to Cisco access devices with the help of downloaded access control lists. If you're running non-Cisco access devices, don't worry: Cisco Secure Access Control Server sends out per user authorization in this scenario as well.

The Cisco ACS Server is a Cisco application that runs on a Windows or Linux Server. ACS Servers can be scaled to very large implementations. Even without NAC, the Cisco ACS system operates as a centralized RADIUS or TACACS+ server. In general, the Cisco Secure Access Control Server manages the authorization, accounting, and authentication of users who access corporate information in a network.

The main advantage of Cisco Secure Access Control Server is that it gives you an authority to control user access to the network. You also get the power to authorize different kinds of network services for users. If you want to keep a record of all network user actions, you can do so easily with Cisco Secure Access Control Server.

* Directory Servers: The Directory Servers offers user IDs, authorization privileges, and group membership information.
* Posture Validation Server: As already mentioned, Cisco Secure Access Control Server has an ability to pass posture data to application-specific posture validation servers, which are normally given by third-party security vendors. Posture Validation Server judges whether endpoint software is up to the mark or not. On the basis of Posture Validation Server evaluation, Cisco Secure Access Control Server allows or disallows user access to networks.
* Remediation Servers: It's the job of remediation servers to bring devices back into compliance. The best part about remediation servers is that they can be as straightforward as a Web server that supports software downloads. Apart from that, remediation servers can automatically evaluate devices and if needed also supply mandatory software updates.

Parts of the greater whole

Cisco's NAC Framework is an architectural design for how multiple hardware and software components can work together to protect your network from unhealthy clients. While the Framework isn't as easy to use as the Cisco NAC Appliance, it does offer the benefit of bringing together offerings from various third-party security companies. At this point, you should understand the different components of the Cisco NAC Framework -- posture agent (Cisco Trust Agent), posture validation server (Cisco ACS Server), Network Access Device (NAD) -- the Cisco switch, and the remediation server (where users will go to get the firewall, OS, or AV software needed to get the PC host in compliance).

SolutionBase: Get familiar with Cisco’s NAC solution

Network Admission Control (NAC) is a solution that allows network administrators to define and enforce security policies across network devices. NAC allows only healthy hosts to access your network, but which are the healthy hosts? As this is not a simple question to answer, the solution can also be complex. Cisco NAC (CNAC) is no different. In this article, we will learn about Cisco’s solution to NAC and see how it stacks up to the competition.
What is Cisco’s NAC solution?

Cisco’s original NAC solution is the NAC Framework. Later, Cisco bought a company called Perfigo and released the NAC Appliance. Both of these solutions have merit, and one is not a replacement for the other. So while these are two valid but distinctly separate choices, Cisco has announced that they plan to combine these solutions in the future. It’s rumored that Cisco will call the solution OneNAC, which makes one wonder if the second revision would be called TwoNAC, and so on.


for CCNA Training and CCNA Certification and more Cisco exams log in to Actualkey.com

Why should I use NAC?

There are a number of benefits to using a NAC system from any vendor, not just Cisco Systems. As malware, viruses, and spyware just continue to become greater issues, NAC becomes more important. If your manager asks why you’re looking into NAC, you can give an informed response:

* Protects your company’s assets: Those assets could be your data (many times, that’s the company’s most valuable asset). NAC enforces the policies that you define to prevent your company’s data from being sent out to Russia or China.
* Protects against business disruption: When a computer connects to your network, an Internet worm on that computer could bring your whole network down.

What is the Cisco NAC Framework?

The Cisco NAC Framework is just a framework, not really a solution. The NAC Framework is architecture that Cisco offers to partners and customers. By using their framework, the third-party partner’s products can interoperate with Cisco’s products to create a complete solution. Once the Framework solution is put together with the partners’ products, it can create a highly-automated NAC infrastructure.

One of my initial concerns with the Cisco NAC Framework is that it’s really a framework to which over 75 Cisco security partners subscribe to make their products compatible and interoperable. The framework isn’t a solution in itself, nor is it a standalone product. Can the products of 75 different vendors really work together to create a successful solution? And who would you buy these products from; 75 different vendors? Initially, it doesn’t sound like a solution that’s easy to understand or implement.

However, based on my research, most people say that the products of the multiple Cisco NAC framework partners work well with the Cisco NAC policy controller. However, just as with any complex project, you may have to invest heavily in software, hardware, and services to make a Cisco NAC Framework implementation a success.
What is the Cisco NAC Appliance?

Previously called Cisco Clean Access, Cisco NAC Appliance is the alternative to the Cisco NAC Framework. The Cisco NAC Appliance offers companies an option to deploy a self-contained endpoint assessment, remediation service, and policy management solution all in one box. The best part is that this is all implemented quickly without need for modifications.

The downside of the Cisco NAC Appliance is that its capabilities are narrower when compared to a full-blown NAC Framework implementation; however, the time and effort needed to implement the NAC Appliance is generally also smaller. Figure A shows what the Cisco NAC Appliance looks like.
Figure A

The Cisco NAC Appliance.
Which is right for you?

There’s a lot of talk about the NAC Framework, but Cisco recommends the NAC Appliance for initial deployments in their FAQ:

Cisco recommends the NAC Appliance to most customers as their initial deployment method. The NAC Appliance delivers a successful solution to solve our customers’ real world business problems. We have established a large and rapidly growing customer install base with worldwide NAC Appliance deployments.

However, that is only a recommendation for initial deployments. You might not be facing a clean scenario that could be described as an initial deployment; perhaps you’re using 802.1X, or you have part of a solution installed, but not others. In some cases, the Cisco NAC Framework can also turn out to be useful. This is especially true when you require extensive integration with third-party NAC-enabled products. When the NAC Appliance isn’t possible for you, the NAC Framework is the option to choose.

While the NAC Appliance is the easiest road for a single network, it doesn’t scale well. And though the NAC Framework might sound like a great all-encompassing alternative, most IT shops don’t end up deploying a full NAC framework when they choose that option, simply because of the time, resources, and infrastructure costs involved.
Interoperability of NAC solutions

Cisco’s NAC Framework is what Cisco will really point to when it comes to questions of interoperability. However, you have to look at the multitude of NAC parts and pieces and wonder how or if they could all work together. Just in the Cisco arena, all of these pieces can be part of a NAC solution:

* Cisco Secure Agent (CSA)
* Cisco Security Monitoring, Analysis, and Response System (MARS)
* Cisco Trust Agent (CTA)
* Cisco Secure Access Control Server (ACS)
* Cisco routers with NAC
* Cisco switches with NAC
* Cisco VPN concentrators
* Cisco wireless devices

As those are all Cisco devices, it’s likely that they all can work together to provide a NAC solution; however, the computing environment is not homogenous. So what about your PCs, laptops, PDAs, and such?

Fortunately, for those of us who use the Windows OS, Microsoft and Cisco announced a deal to make Cisco NAC and Microsoft NAP compatible with each other. This seems like a win/win situation for the consumer; we don’t have to choose, and allows us to protect our investment in their NAC/NAP infrastructure. I wish more vendors would follow their lead; this interoperability isn’t functional until you start using Windows Server 2008.
Cisco NAC and the competition

Although Cisco’s NAC and Microsoft’s NAP may be two most recognizable buzzwords revolving around NAC, that doesn’t mean they’re the only game in town; there’s a lot of competition out there. NAC is still a young technology with lots of innovation going on in the marketplace. Here’s the short list of CNAC competitors:

1. Bradford Networks: All Bradford does is NAC.
2. ConSentry Networks: Their product line is called LAN Shield and they focus on NAC.
3. ForeScout Technologies: Their two products are CounterACT and ActiveScout. Forescout has had good reviews for their NAC solutions.
4. InfoExpress: Offers CyberGatekeeper Dynamic NAC. They claim that you won’t have to make any network changes.
5. Juniper Networks: The large firewall & router manufacturer produces Unified Access Control (UAC) and sells the Infranet Controller as their policy controller.
6. Lockdown Networks: Produces Real NAC and has had good reviews in tests.
7. McAfee: The large software company produces McAfee Policy Enforcer and ePolicy Orchestator. Together, these are supposed to provide a complete NAC solution, but they still lack some basic NAC features.
8. StillSecure: Their NAC product is called Safe Access.
9. Symantec: This large software company offers SNAC (Symantec NAC), which won the title of best overall NAC solution in a recent test.
10. Vernier Networks: They claim that over 1,000 organizations have deployed their NAC product.

While Cisco’s NAC solution may seem like a safe bet, you might want to take a look at the other vendors: in a recent unbiased test done between 13 NAC vendors (including Cisco), Symantec’s solution won (the runners-up were Forescount, LockDown, and Juniper). To Cisco fans, it may seem unimaginable for Cisco not to rate in the top four NAC vendors; but, in my opinion, the test results show that Cisco’s solution is more fragmented and immature than the competition.
In summary

Cisco currently offers two NAC solutions: Framework and Appliance. The framework is an architecture of which many parts of your network (Cisco or non-Cisco) can belong. The framework is more of a guide on how various pieces might fit together to create a NAC solution. However, a complete Cisco NAC Framework can be difficult and costly to implement. On the other hand, the Cisco Appliance can be deployed in-band or out-of-band and is used to block or quarantine clients directly.

As the NAC market is still young, Cisco has some tough competition out there. Although it is just one of many NAC solutions available today, I feel that the Cisco NAC appliance deserves a review when considering enterprise NAC solutions.

SolutionBase: Cisco’s NAC hardware explained

Cisco Network Admission Control (NAC) is a system to enforce the security policy of your company on all devices attempting network access. The Cisco NAC solution is made up of many different pieces of hardware, software, and services; this article will explain its many pieces.
What hardware makes up Cisco’s NAC solution?

On Cisco’s network security solutions Web page, you’ll find the following list of Cisco technologies, all of which play a part in the complete Cisco NAC solution:


for more info on CCNA Training and CCNA Certification and more Cisco exams log in to Certkingdom.com

* Advanced Services for Network Security
* Cisco Security Agent (CSA)
* Cisco Security Monitoring, Analysis and Response System (MARS)
* Cisco Trust Agent 2.0 (CTA)
* Cisco Secure Access Control Server for Windows (ACS)
* Cisco Secure Access Control Server Solution Engine (ACS)
* Cisco Works Interface Configuration Manager (ICM)
* Cisco Works Security Information Management Solution (CW-SIMS)
* NAC-enabled routers
* Router security
* Cisco VPN 3000 Series Concentrators
* Cisco Unified Wireless Network
* Cisco Catalyst switches

Let’s discuss some of the more critical pieces of Cisco’s NAC solution.
Cisco NAC-enabled routers

The recently released Cisco router NAT module enforces NAC at the remote branch locations or ancillary buildings of a campus. Apart from that, the NAC router module also improves the overall security of the network by making sure that all incoming users and devices comply with security policies.

Additionally, the Cisco NAC router module (part # NME-NAC-K9) brings the capabilities of Cisco NAC Appliance Server to Cisco 2800 and 3800 Series Integrated Services Routers. This module helps network administrators by not having to deploy NAC appliances across the board and it helps to consolidate the administrative tasks into fewer boxes.

Amazingly, this module is actually a 1 GHz Intel Celeron PC, with 512 MB RAM, 64 MB of Compact Flash, and an 80 GB SATA hard drive. All that fits onto a single 1 pound module that slides into a router and enforces your security policies. This module requires a 2800 or 3800 series router running IOS 12.4(11)T or later.
Cisco NAC Appliance

The single most popular piece of the Cisco NAC solution has been the Cisco NAC Appliance. As evident from the name itself, Cisco NAC Appliance is an appliance-based solution that offers fast deployment, policy management, and enforcement of security policies.

With the Cisco NAC Appliance, you can opt for an in-band or out-of-band solution. The in-band solution is for smaller deployments. As your network grows into a more campus environment, you may not be able to keep in the in-band design. In that case, you can move to the out-of-band deployment scenario.

Here are some advantages of the Cisco NAC Appliance:

* Identity: At the point of authentication, the Cisco NAC Appliance recognizes users, as well as their devices and their responsibility in the network.
* Compliance: Cisco NAC Appliance also takes into account whether machines are compliant with security policies or not. This includes enforcing operating system updates, antivirus definitions, firewall settings, and antispyware software definitions.
* Quarantine: If the machines attempting to gain access don’t meet the policies of the network, the Cisco NAC Appliance can quarantine these machines and bring them into compliance (by applying patches or changing settings), before releasing them onto the network.

For more information about the Cisco NAC Appliance, see the Cisco NAC Appliance datasheet.
Cisco Secure Access Control Server (ACS)

The Cisco ACS Server could be called the “brain” of the Cisco NAC solution. It is here that users’ credentials are checked to see if they are valid, policies are sent back to be enforced, and activities are logged. The ACS server is called an AAA Server because it performs authentication, authorization, and accounting.

This server runs on an existing Windows server in your organization and can use other existing databases in your organization to verify users’ credentials. For example, most companies have ACS point toward their Windows Active Directory (AD) system to look up credentials. If those credentials are valid, then ACS can enforce network authorization polices on those users, with the help of the network hardware: NAC Appliance, Router NAC module, or ASA/PIX firewalls.
Cisco Security Agent (CSA)

Cisco CSA is a software client that is run on every machine in an organization. These clients talk to a centralized policy server. Together, these software applications know what software and activities that occur on each PC in the organization are or are not “normal”. The CSA agent may alert on or block certain activities that it sees as abnormal.

When compared to anti-virus software that depends on definition updates to stay current, Cisco touts that the CSA never needs updating because it is constantly “learning” and monitoring activities, not definitions of viruses.

For more information about the Cisco CSA solution, see the Cisco CSA datasheet.
Cisco Trust Agent (CTA)

You can think of the Cisco Trust Agent as the “NAC Client”. The CTA runs on each PC in the organization. It talks to the NAC Appliance, for example, to tell it about the state of the device attempting to access the network. For example, the CTA reports the version of the OS, patch level, the AV definition level, the firewall status, and more. According to Cisco, the CTA “interrogates devices.” You can obtain CTA free of charge from Cisco Systems.
Cisco Works Security Information Management Solution (CW-SIMS)

The Cisco Works Security Information Management Solution (CW-SIMS) in the centralized repository that all Cisco devices use for security logging and other information. According to Cisco, this application “integrates, correlates, and analyzes security event data from the enterprise network to improve visibility and provide actionable intelligence for strengthening an organization’s security.”

With so many security devices in your network, one application has to try to correlate all the logs and security information that is generated. According to Cisco, here are the features that the CW-SIMS offers:

* Comprehensive Correlation: Statistical, rules-based, and vulnerability correlation of events as they happen, in real time, across all integrated Cisco network devices.
* Threat Visualization: See a visual status and generate reports of all the security events as they happen across your network.
* Incident Resolution Management: SIMs integrates with common helpdesk packages to track security events until resolution.
* Integrated Knowledge Base: SIMS can be a source of knowledge about security issues and how they are resolved.
* Real-Time Notification: SIMS can notify security admins, in real time, when events occur.

For more information about the Cisco CW-SIMS solution, see the Cisco SW-SIMS datasheet.
Cisco Security Monitoring, Analysis, and Response System (MARS)

While MARS may seem similar to CW-SIMS, it is quite different. MARS actually understands the configuration and topology of your network. You can think of MARS as a “virtual security admin” for your network — working while you sleep.

MARS uses NetFlow data from Cisco routers to have a real-time understanding of network traffic. It knows what is considered normal and what is not; this is called behavioral analysis. With behavioral analysis, MARS can stop abnormal network traffic. MARS has over 150 audit compliance templates ,and will make recommendations on how to remediate threats to your network.

MARS is actually an appliance that you install on your network. This appliance comes in a variety of sizes and license levels based on the size of your network. Cisco Security MARS and Cisco Security Manager are part of the Cisco Security Management Suite.
In summary

To be a complete solution that can fulfill the Cisco Self-Defending Network framework, the hardware and software of Cisco’s NAC solution must integrate well. With nine or more different pieces of hardware and software related to NAC, the challenge of acquiring (i.e., affording), learning to configure, deploying, and monitoring these solutions can be a large task for any organization. While having the centralized software applications like CW-SIMS and MARS can really bring it all together, those applications will take time, effort, and expertise to master. For this reason, I can relate to anyone who says that deploying a security solution is difficult.

In this article, I’ve attempted to clarify the purpose of the different NAC security solutions offered by Cisco today; with this information, I hope that your quest for strong network security can be realized.

Free Training | Free Certification Free MCITP Free Training Key » Blog Archive » TS: Configuring Microsoft Windows Vista Client – 70-620

QUESTION 76
You work as the desktop support technician at CertKingdom.com. The CertKingdom.com network consists
of a single Active Directory domain named CertKingdom.com. You have been assigned to the
CertKingdom.com help desk to aid all the CertKingdom.com users who experience trouble with their
workstations. There are both desktop and laptop workstations in operation at CertKingdom.com.
The manager of the CertKingdom.com Sales department named Clive Wilson contacted the
CertKingdom.com help desk to ask for assistance with his department’s main workstation. According
to Clive Wilson, he makes use of many Web sites and services to order and track sales from
several companies. This result in him having a lot of custom settings and preferences on these
sites that he does not want to lose. Many of the sites have passwords that the manager is no
longer required to enter because they are stored locally on the computer.
Clive Wilson has recently delegated the task of processing sales orders online to some of his staff
members. He would like them to have their own credentials on the Web sites, so they can track
their own sales. To this end you are required to remove the stored passwords from the computer
and prevent them from being stored locally again.
Which two of the following actions should you perform?

A. Navigate to the Advanced tab in Internet Options and click Restore advanced settings.
B. Navigate to the Advanced tab in Internet Options and click Reset
C. On the Privacy tab in Internet Options, set the level to High.
D. On the Content tab in Internet Options, click the AutoComplete Settings button and clear the
User names and passwords on forms check box.
E. Click Tools in the Internet Explorer and then click Delete Browsing History. Click Delete
passwords.

Answer: D,E

Best online Microsoft MCTS Certification, Microsoft MCITP Certification at Actualkey.com

Explanation:
To remove the passwords, you should open Internet Explorer, click Tools, and then click Delete
Browser History. Then click Delete Passwords to remove the local passwords stored for Internet
content.
You also must clear the User names and passwords on forms option in the AutoComplete Settings
dialog box. This will prevent user name and password settings from being stored locally in the
future.


QUESTION 77
You work as the desktop support technician at CertKingdom.com. The CertKingdom.com network
consists of a single Active Directory domain named CertKingdom.com. You have been assigned to the
CertKingdom.com help desk to aid all the CertKingdom.com users who experience trouble with their
workstations. There are both desktop and laptop workstations in operation at CertKingdom.com.
A user named Mia Hamm contacted the CertKingdom.com help desk to report that she is experiencing
trouble with viewing Web sites in Microsoft Internet Explorer 7.0. She says that all Web pages are
displayed in the upper-left corner of the tab. The text as well as the images appear very small and
make it very awkward to view. You need to enable Mia Hamm to view the pages at their original
size. To this end you therefore change the text size from medium to large, but it has very little
impact on the text, and the images are still too small.
What should you do?

A. You need to decrease the screen resolution.
B. You need to increase the screen resolution.
C. You need to decrease the monitor refresh rate.
D. You need to increase the monitor refresh rate.
E. You need to decrease the zoom level for the tab.
F. You need to increase the zoom level for the tab.

Answer: F

Explanation:
Internet Explorer 7.0 allows one to view Web pages at different zoom levels and judging by the
symptoms described in the question it is possible that Mia Hamm accidentally pressed the
Ctrlkeys to zoom out. Changing the zoom level affects the entire page, resizing both text and
images. If you change the zoom level to 100 percent, Web pages will appear in their original
sizes. Therefore you should increase the zoom level for the tab.


QUESTION 78
You are employed as an administrator at CertKingdom.com. The CertKingdom.com network consists of a
single Active Directory domain named CertKingdom.com.
CertKingdom.com contains a computer named CERTKINGDOM-WS621 that is running Microsoft
Windows Vista. You have received instructions to remove any Microsoft Windows Internet
Explorer 7 add-ons from CERTKINGDOM-WS621 that do not have prior approval from Microsoft,
System manufacturer or Service provider.
What should you do?

A. You need to remove any add-ons that are not found in the list of add-ons that are at currently
loaded in Windows Internet Explorer 7.
B. You need to remove all add-ons then reapply the add-ons you want to keep.
C. You need to remove any add-ons that are not found in the list of add-ons that run without
requiring permission.
D. You need to remove any add-ons that are not found in the Temporary Internet Files folder.
E. You need to remove any add-ons that are not found in the list of add-ons used by Windows
Internet Explorer 7.

Answer: C

Explanation:
Internet Explorer 7 add-ons that are approved by Microsoft, System manufacturer and the Service
provider do not require your permission to run. They will run automatically. Any add-on that isn’t
approved will require your permission to run. Therefore, to remove all the unapproved add-ons,
you need to remove any add-ons that are not found in the list of add-ons that run without requiring
permission.


QUESTION 79
You are employed as a network administrator at CertKingdom.com. The CertKingdom.com network
consists of a single Active Directory domain named CertKingdom.com.
A CertKingdom.com user named Mia Hamm who works in the Marketing department of CertKingdom.com,
has been assigned a computer named CERTKINGDOM-WS623. CERTKINGDOM-WS623 has the popup
blocker enabled. To do her daily work she visits a certain Web site which makes use of popups.
Mia Hamm wants to view the pop-ups from this Web site while maintaining the highest level of
security for all other Web sites.
Which two of the following options would achieve this goal?

A. You need to disable the pop-up blocker.
B. You need to set the default security level to High.
C. You need to add the URL of the Web site to the list of allowed sites.
D. You need to set the default security level to Medium.
E. You need to visit the Web site and select the Always allow pop-ups from this site option.

Answer: C,E

Explanation:
To enable the pop-ups from a certain website to be viewed, the URL of the Web can be added to
the list of allowed sites in the Pop-Up Blocker settings. Alternatively, you can visit the website and
select the Always allow pop-ups from this site option.


QUESTION 80
You work as the Help Desk technician at CertKingdom.com. The CertKingdom.com network consists of a
single Active Directory domain named CertKingdom.com. CertKingdom.com also operates a Customer
Care Help Desk for the benefit of its customers.
A CertKingdom.com customer named Rory Allen has contacted you at the Customer Care Help Desk.
Rory Allen has configured Microsoft Internet Explorer 7 with a Really Simple Syndication (RSS)
subscription to a website. Rory Allen now has a problem that the RSS subscription Web page has
failed and show the information that the RSS feed Web page displays from the website.
How can you assist Rory Allen to configure Internet Explorer to display the current content from
the RSS feed?

A. Instruct Rory Allen to add the URL of the Web site to the list of allowed sites.
B. Instruct Rory Allen to configure the RSS feed properties to use the maximum interval value
C. Instruct Rory Allen to enable the feed reading view in the RSS feed settings.
D. Instruct Rory Allen to configure the RSS feed properties to use the minimum interval value.
E. Instruct Rory Allen to disable the pop-up blocker for the website.

Answer: D