<?xml version="1.0" encoding="UTF-8"?><!-- generator="wordpress/2.2.1" -->
<rss version="2.0" 
	xmlns:content="http://purl.org/rss/1.0/modules/content/">
<channel>
	<title>Comments on: IETF Picks Up TNC Standards</title>
	<link>http://nacblog.juniper.net/2008/04/02/ietf-picks-up-tnc-standards/</link>
	<description>Steve Hanna's Weblog</description>
	<pubDate>Fri, 08 Aug 2008 00:24:03 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.2.1</generator>

	<item>
		<title>By: Tarek Amr</title>
		<link>http://nacblog.juniper.net/2008/04/02/ietf-picks-up-tnc-standards/#comment-71</link>
		<author>Tarek Amr</author>
		<pubDate>Fri, 11 Apr 2008 10:13:08 +0000</pubDate>
		<guid>http://nacblog.juniper.net/2008/04/02/ietf-picks-up-tnc-standards/#comment-71</guid>
		<description>It's really great that Juniper and TNC are doing their best to standardize the NAC. I believe this will really help in speeding up the adoption of such new technology. 

I've noticed that most of the standards are focusing on how the PDP communicates with the PEP when the PEP is a LAN switch or Access Point. Correct me if I am wrong, but when the UAC communicates with Juniper Firewalls they do it in a non standard way. So, are you planning to come out with another standard for communicating with Firewalls? Or are you going to re-use what is currently done when dealing with LAN switches in the Firewalls? I've noticed that the new ScreeOS version support IEEE 802.1x, so I was thinking that you may be planning to make your Firewalls support EAP-JUAC, and may be then you can come out with some extensions in the JUAC to help in pushing policies to the firewalls. Then it may be easier for other Firewall vendors (or any network-based security products) to interoperate with Juniper's UAC or any TCG-TNC compliant NAC solution.</description>
		<content:encoded><![CDATA[<p>It&#8217;s really great that Juniper and TNC are doing their best to standardize the NAC. I believe this will really help in speeding up the adoption of such new technology. </p>
<p>I&#8217;ve noticed that most of the standards are focusing on how the PDP communicates with the PEP when the PEP is a LAN switch or Access Point. Correct me if I am wrong, but when the UAC communicates with Juniper Firewalls they do it in a non standard way. So, are you planning to come out with another standard for communicating with Firewalls? Or are you going to re-use what is currently done when dealing with LAN switches in the Firewalls? I&#8217;ve noticed that the new ScreeOS version support IEEE 802.1x, so I was thinking that you may be planning to make your Firewalls support EAP-JUAC, and may be then you can come out with some extensions in the JUAC to help in pushing policies to the firewalls. Then it may be easier for other Firewall vendors (or any network-based security products) to interoperate with Juniper&#8217;s UAC or any TCG-TNC compliant NAC solution.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Grant Hartline</title>
		<link>http://nacblog.juniper.net/2008/04/02/ietf-picks-up-tnc-standards/#comment-51</link>
		<author>Grant Hartline</author>
		<pubDate>Thu, 03 Apr 2008 16:37:18 +0000</pubDate>
		<guid>http://nacblog.juniper.net/2008/04/02/ietf-picks-up-tnc-standards/#comment-51</guid>
		<description>I'm happy to see the movement towards unification of standards and appreciate all of the effort you've put into NAC standards adoption, both within the TCG and the IETF.  However, one TNC standard that is conspicuous in its absence is IF-PEP.  Is there an IETF working group that may pull in IF-PEP for the purposes of triggering enforcement actions?  Alternatively, or at least in the meantime, do you see any movement within what we'll call "the industry" on adoption of RFC 3576 within Ethernet switches?</description>
		<content:encoded><![CDATA[<p>I&#8217;m happy to see the movement towards unification of standards and appreciate all of the effort you&#8217;ve put into NAC standards adoption, both within the TCG and the IETF.  However, one TNC standard that is conspicuous in its absence is IF-PEP.  Is there an IETF working group that may pull in IF-PEP for the purposes of triggering enforcement actions?  Alternatively, or at least in the meantime, do you see any movement within what we&#8217;ll call &#8220;the industry&#8221; on adoption of RFC 3576 within Ethernet switches?</p>
]]></content:encoded>
	</item>
</channel>
</rss>
