This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

What is Sophos view on network access control?

I'm quite new to Sophos XG but am busy revamping our security. I like the idea that the XG does talk to endpoints so we are busy acquiring endpoint licenses too. 

 

I was just wondering how does Sophos view the topic of network access control? 

 

Even though I can create FW rules adn tie them to users/groups and integrate with my active directory I still have the issue of i.e. someone connecting his private device and using his legitimate credentials to access my network. All I can see from the XG dashboard is that I can tie users to MAC addresses but we all know that is not much of a hurdle for anyone...

 

Is there some part I am missing or is NAC just not something the XG provides or considers important?



This thread was automatically locked due to age.
Parents Reply
  • I like the concept and it's another tool to use ie a NAC won't stop a virus spreading but this has the potential to. I do hope they adhere to standards to implement it and don't go of on a tangent like M$ does.

    M$ in their infinite wisdom decided to create a non standard Wake on Lan proxy within their SCCM software. It allows clients with the SCCM client installed to share mac addresses so if a client goes to sleep, the mac address can switch to another client on that lan which then does the waking up.
    Now that's fine, unless you've got a 802.1x network and it starts playing havoc with it when ports shut down due to seeing a new mac address. It's almost virus/worm like behavior and all because they decided to do their own thing like the did with their network load balancing etc.

    So please Sophos.... don't do an M$ and create your own non standard protocol etc to achieve the end result.

Children
No Data