Network Access Control Overview
What is Network Access Control?To connect to the UNC Campus Network, it has always been the case that a customer’s computer must meet certain minimum requirements, including having anti-virus software installed, running and up-to-date. It must also have specific operating system updates installed to prevent the computer from being compromised. In the past, this policy was enforced using a combination of a customer honor-system and technology (Tipping Points) that identified and blocked “bad” internet traffic to prevent infections from spreading across the network. As our network evolves, we have to modify this approach to continue to protect all users. In order to increase the speed of our network (10x), we had to remove the Tipping Points from most of campus, which could make us susceptible to security risks. As a result, we implemented a new security service called NAC in specific regions of campus. Network Access Control (NAC) is a proactive, end-user networking solution for wired and Wi-Fi connections that allows us to identify potential problems on a computer before it accesses the web. The system can educate the customer about any potential vulnerability and then provide them a link or resource to resolve it on their own. This solution is highly customizable and will be setup in the best interest of all campus network users. Malware (e.g. spyware, viruses, worms) exist that can automatically disable services like anti-virus software. Many times the customer has no idea this has happened. This service will help alert the customer that this problem has occurred and provide them with a solution. How does NAC work?If a computer is connected to a NAC-enabled region of our network via wired or Wi-Fi, then the NAC Assessment server will attempt to communicate with the device (e.g. computer). It checks the device to see if the NAC agent is installed. After a few minutes, if it does not find the NAC agent, it will then redirect any web-based (HTTP) traffic to a specific website. This site will walk the customer through the NAC agent installation steps. Finally, the customer will initiate another scan and if the server can communicate with the agent, then the customer can continue browsing the web with no problem. Next, if the NAC agent identifies a security issue or problem, as explained in the next section, it will then provide the customer with information on how to resolve it. As long as their computer meets the requirements, they will never know that the NAC agent is running. During the installation of this service or if a device is found to have a vulnerability, the only impact on the customer is that they cannot browse the web. If they use internet connected applications like Outlook, Thunderbird, Instant Messaging, etc., those programs will continue to function as normal. Currently, this software is designed to work for computers running Microsoft Windows or Apple OS X. We are specifically exempting Linux-based computers, which is a small minority of campus, and will address those in the future. How is Network Access Control being used?ITS Security and the UNC Legal department have approved the use of NAC to scan devices connected to our network for the following conditions:
All CCI machines are configured to meet all of these requirements by default. If a computer fails any of these conditions, meaning the answer is “No” to the questions above, nothing will happen to customer’s computer. They will be able to browse with no problem, but they will be notified via a pop-up message with a link that will help resolve the issue. If the issue is not resolved within a 2 week period, those computers may be removed from the network until they are in compliance. Currently, this is a manual process, but will be automated in the future. Configuring Network Access ControlThis service is designed to allow specific types of devices or operating systems to simply bypass the service. So if your operating system is not listed (e.g. Ubuntu), then you can simply ignore this service for now. Depending on your operating system, your Network Access Control setup may be slightly different. Please select your operating system below:
We automatically “whitelist” devices that should be exempt from the NAC service e.g scientific equipment. To request an exemption please Submit a Web Request and enter the details of the device. How do I get support?The process for installation should be very fast and user-friendly. If however, you still need help, contact your departmental support team, or through one of the following methods:
General NAC FAQs
|
|


