Network Access Control
Check Point and Foundry Networks
IT professionals are challenged to manage threats to network security caused by viruses, spyware, worms, and other malware. Infected or vulnerable machines should be automatically isolated from the network until the infection is removed or the vulnerability remediated. While several proprietary (vendor specific) initiatives address this problem, only one standard exists that is widely supported by heterogeneous networking devices: 802.1X/EAP.
Foundry Networks and Check Point have teamed up to certify and promote a joint solution based on the 802.1X/EAP standard. The joint solution-comprising Foundry Networks switches with support for 802.1X/EAP and Check Point Endpoint Security software-automatically verifies compliance with corporate security policy prior to enabling access to the network via Foundry switches. Non-compliant endpoints are automatically placed in a remediation VLAN, where access is provided to remediation tools while shielding infected endpoints from the production network.
Benefits
- Automated quarantine of infected endpoints
- Automatic enforcement of corporate security standards
- Standards-based approach, enabling deployment across a heterogeneous network
Foundry Networks FastIron Switches
Foundry's award-winning products aimed specifically at the enterprise market deliver a new level of high performance capabilities for your networking environment. Based on Foundry's proven hardware architectures, Foundry's enterprise products deliver hardware-based distributed switching and the industry-leading performance, price/performance and high-density 10/100/1000 Mbps connectivity. Whether you need cost-effective basic connectivity or full featured, wire-speed multi-protocol and multicast routing, Foundry has the right products at the right price for your network.
Features (Foundry FastIron 4802)
- Based on Foundry's next-generation JetCore ASIC chipset
- 48 10/100 ports and 2 Gigabit Ethernet ports (Mini-GBIC) consuming just 1.5 rack units
- Integrated ASIC based wire-speed bandwidth provisioning, network monitoring and traffic accounting
- Hot swappable, redundant load sharing AC or DC power supplies
- Full Layer 2 and base Layer 3, upgradeable to full Layer 3 including IP, IPX, AppleTalk, OSPF and BGP4
Check Point Endpoint Security
Check Point Endpoint Security unifies the highest-rated firewall, antivirus, antispyware, network access control (NAC), and remote access VPN in a single, centrally managed client. Unification of these five essential endpoint security components protects organizations from the broadest range of endpoint threats, including confidential data theft, viruses, and host-based intrusions. Check Point Endpoint Security is the only solution that integrates both NAC for endpoint compliance and a remote access VPN client for secure remote access communications. The essential integration of the highest-rated defenses in a single, centrally managed client eliminates the need to deploy and manage multiple endpoint security applications. This increases the range of protection and reduces the overall total cost of ownership by reducing overhead and providing operational efficiencies like no other endpoint solution.
Benefits
- Defeats malware to protect against new and old viruses targeting confidential enterprise data
- Stops unsafe endpoints from infecting enterprise networks
- Ensures the confidentiality of remote access communications
- Enables simpler deployment of essential endpoint defenses and remote access capabilities
- Reduces total cost of ownership and complexity of managing multiple endpoint defenses