What are the key differences between NAC products that use IPS or port monitoring, compared to DNAC?
A. Using IPS or port monitoring requires selecting choke points on the network. This is typically an appliance at critical locations on the LAN for IPS, or attaching the monitoring appliance to a monitoring port on the switch. The choke points filter rogues with access control rules or by sending DOS attacks against the rogues. Either of the above approaches provide granularity only whent he monitoring/choke point is moved close to the endpoint. However, this incurs a significant cost when multiple locations are present. For IPS solutions, the choke points also become potential points of failure.