What is Qmanage?
Qmanage is a Network Access Control application. Qmanage automatically allocates workstations to the appropriate network segment, giving the network administrators better control. Authorized users can always access their resources, unauthorized users are automatically banned from the network. Unregistered workstations are placed in an isolated environment and can then be registered via that environment. Infected workstations can be placed automatically in the quarantine segment.
In situations involving an "open" network, anyone with physical access can connect a device to the network. Such devices present a potential risk since they fall outside the control of the central security policy. Providing guests with secure but workable access to a network is a labour-intensive activity. Qmanage ensures that switchports are always put in the appropriate VLAN, so that your own staff as well as guests have access to the network in the correct manner.
How does Qmanage work?
Qmanage dynamically modifies the configuration of your switchports in such a way that the user or workstation is automatically allocated to the correct VLAN. It is not neccesary for the switches to support 802.1x. This means that older switches do not have to be replaced (eg HP Procurve 4000/8000). Guests can be placed in a segregated guest VLAN, following registration if desired. Any users placed in quarantine will be sent to the quarantine VLAN so that they can no longer cause disruption to the rest of the network. On wireless networks, placing the user in the correct VLAN is supported as well - usually by means of 802.1x.
The isolated user in the quarantine-VLAN is alerted that his connection has been placed in quarantine by means of a personalised web page, and is advised about the steps to be taken in order to be reconnected. A limited number of sites will remain accessible, for example Microsoft's Windows update site and anti-virus software sites. The network manager decides which sites these will be.
If desired users may be offered the facility to reconnect themselves. The manager may determine for himself how often this facility is extended, and to whom. In all other cases the end user must contact the manager by a web-based form, by e-mail or by telephone.
There's also a webcast available so you can see the functionality Qmanage provides.
Qdetect can be used in combination with Qmanage to ensure that infected workstations are automatically placed in quarantine. Our honeypot identifies infected machines and reports these to the quarantine environment. Since detection is based on the method used to spread the virus, unknown viruses can also be picked up.
What are the benefits?
More information on the benefits of Qmanage can be found here.