Context Directory Agent maps the Active Directory Anti-Virus user

Hi,
Today I was able to join a couple of CDA's to our Active Directory domain (2008 R2 DC's) using a non-privileged account and the CDA maps (most) users to IP addresses.
I would like to use the CDA solely for building up firewall policies based on AD details whenever possible
as maintaining granular firewall policies on 8 different ASA's is too time consuming as we are not a large IT organization.
But, after deploying the first "AD Group" based rule, it turned out, that the AD user-account mapped to the IP address of my PC was actually a domain user, running the local anti-virus engine, and not my own.
It makes total sense that the the anti-virus user is logged on to the PC before any user, so it can do "its thing",
but my own user-account is never mapped. 
CDA was able to map certain users to an IP address, even though the anti-virus user is actually logged on to the PC before them.
Has anyone deployed Identity Based Firewalling and experienced something which resembles this scenario and were you able to do any workarounds?
I looked into filtering out the logon events (for the Sophos user-account) from the Windows Security logs,
so the CDA will not be able to map these, but it seems a bit far fetched, and would probably violate a security policy or two :)
Cheers, Søren Elleby Sørensen

I opened a case and they refer me to bug CSCun10631.
(CDA doesn't support 2012R2).
the good news is that a new patch (3) should be release this month (July) and will include support.

Similar Messages

  • Getting the active role of an user in a trigger

    Hello forum!!
    I've been searching to find out if and how I can get the active role of an user when programming a trigger.
    Unfortunately I did not succeed in finding some information about this. Is it possible? If yes, how?
    Thanks for any hint regarding this topic.
    Sebastian

    Thanks for the answers. This helped a lot but it does not seem to work within my triggers.
    CREATE OR REPLACE TRIGGER InscriptionsInsert BEFORE INSERT OR UPDATE ON Inscriptions
      FOR EACH ROW
      DECLARE
        active_role VARCHAR2(11);
      BEGIN
        SELECT role INTO active_role FROM session_roles WHERE role != 'CONNECT';
        IF :new.ni < 1000 AND active_role = 'ind_service' THEN
          RAISE(ABORT, 'le service individuelle ne peut pas faire les inscriptions pour des sportifs');   
        END IF;
        IF :new.i >= 1000 AND active_role = 'eq_service' THEN
          RAISE(ABORT, 'le service equipe ne peut pas faire les inscriptions pour des equipes');   
        END IF;
      END;
    CREATE OR REPLACE TRIGGER ResultatsInsert BEFORE INSERT OR UPDATE ON Resultats
      FOR EACH ROW
      DECLARE
        forme VARCHAR2(12);
        active_role VARCHAR2(11);
      BEGIN
        SELECT forme INTO forme FROM Epreuves WHERE nEpreuve = :new.nEpreuve;
        SELECT role INTO active_role FROM session_roles WHERE role != 'CONNECT';
        IF forme = 'individuelle' AND active_role = 'eq_service'
          RAISE(ABORT, 'le service equipe ne peut pas enregistre des resultats pour des sportifs');
        END IF;
        IF forme = 'equipe' AND active_role = 'ind_service'
          RAISE(ABORT, 'le service individuelle ne peut pas enregistre des resultats pour des equipes');
        END IF;
      END; 

  • How do I install the free mcafee Anti virus for I pad?

    I don't know how to find and install the Free Mcafee Anti Virus software for my IPad.

    You don't need antivirus or security software as long as you don't Jailbreak your iPad.
    Currently there's no known virus affecting iPad.
    http://support.apple.com/kb/HT3743

  • How can I uninstall Kaspersky? The item "Kaspersky Anti-Virus.app" can't be moved to the Trash because it's open.' I did not open it in fact. Please advise. Thanks.

    How can I uninstall Kaspersky to install Mckeeper ?
    The item 'Kaspersky Anti-Virus.app' can't be moved to the Trash because it is opened'. Actually I did not open it.
    Please advise, thanks.
    Emmanuel

    Remove "Kaspersky Security" by following the instructions on this page. If you have a different version of the product, the procedure may be different. The product includes a Safari extension that may not be removed by the uninstaller.
    Back up all data before making any changes.

  • What is the best free anti virus software to install on a macbook pro?

    What is the best free anti virus software to install on a computer used only for personal use?

    yankeefan29 wrote:
    What is the best free anti virus software to install on a computer used only for personal use?
    No antivirus software is needed.
    Install all System, Applications and Security updates released by Apple.
    For more on this:
    http://support.apple.com/kb/PH11432
    About antivirus:
    http://www.thesafemac.com/mmg-antivirus/

  • What's the best free anti-virus software to use?

    I'm looking for the best FREE anti-virus software for personal use. Suggestions? If you could give me the top 2-3 or those that clearly separate themselves from the pack, I'd greatly appreciate it. Thanks!

    Darien,
    Allan is right it's really not needed for MacOSX, but if you feel you need protection from viruses/malware download and install ClamXav. If you want real time scanning for files and downloads use the Clam Sentry feature. Open ClamXav, go to preferences activate clam sentry, when asked  what folder to watch just enter the / which will monitor your entire system. Hope this helps.
    Joseph

  • What is the best free anti-virus download to use on my MacBook Pro?

    I'm worried that whatever Apple has built into the computer is not enough security. Is there a free anti-virus download for Macs? Do they do the job or do I have to spend money on something better? The download would need to identify and fix the problems. I mostly email, search the internet, sometimes buy things, download Kindle books, do my banking, etc. I would really not want to spend any money if it's not needed. Thanks.

    svdmmanta wrote:
    Is there a free anti-virus download for Macs? Do they do the job or do I have to spend money on something better?
    In General 3rd Party AV Software and Cleaning Utilities tend to cause More Issues than they claim to fix...
    They Not Required...
    Mac OS X tends to look after itself.
    See  >  Mac OS X Built in Security  >  http://www.apple.com/osx/what-is/security.html
    More Info Here  >   https://discussions.apple.com/thread/4545776?tstart=0
    And Here  >  Antivirus Discussion
    The Safe Mac  >  http://www.thesafemac.com/mmg/

  • What's the best internet anti virus software for iMac?

    Hi
    Was wondering if anyone could give me advice on what anti-virus/internet security software shall I get for my iMac?
    Thanks a lot!

    None. Have a look at these links from The Safe Mac, klaus1 and John Galt. They provide useful, informed opinion on the merits, or otherwise, of installing anti-virus software on a Mac:
    http://www.thesafemac.com/mmg/
    https://discussions.apple.com/docs/DOC-3030
    https://discussions.apple.com/message/23885605?ac_cid=tw123456#23885605 (see John Galt's response).

  • Does the Mac need anti-virus software?

    I have been told the Mac does not need anti-virus software. I have Kapersky on my Mac now and was told to take it off.  I was told Apple updates the protection software daily.  Any thoughts?

    1. This comment applies to malicious software ("malware") that's installed unwittingly by the victim of a network attack. It does not apply to software, such as keystroke loggers, that may be installed deliberately by an intruder who has hands-on access to the victim's computer. That threat is in a different category, and there's no easy way to defend against it. If you have reason to suspect that you're the target of such an attack, you need expert help.
    If you find this comment too long or too technical, read only sections 5, 6, and 10.
    OS X now implements three layers of built-in protection specifically against malware, not counting runtime protections such as execute disable, sandboxing, system library randomization, and address space layout randomization that may also guard against other kinds of exploits.
    2. All versions of OS X since 10.6.7 have been able to detect known Mac malware in downloaded files, and to block insecure web plugins. This feature is transparent to the user, but internally Apple calls it "XProtect." The malware recognition database is automatically checked for updates once a day; however, you shouldn't rely on it, because the attackers are always at least a day ahead of the defenders.
    The following caveats apply to XProtect:
    It can be bypassed by some third-party networking software, such as BitTorrent clients and Java applets.
    It only applies to software downloaded from the network. Software installed from a CD or other media is not checked.
    3. Starting with OS X 10.7.5, there has been a second layer of built-in malware protection, designated "Gatekeeper" by Apple. By default, applications and Installer packages downloaded from the network will only run if they're digitally signed by a developer with a certificate issued by Apple. Software certified in this way hasn't necessarily been tested by Apple, but you can be reasonably sure that it hasn't been modified by anyone other than the developer. His identity is known to Apple, so he could be held legally responsible if he distributed malware. That may not mean much if the developer lives in a country with a weak legal system (see below.)
    Gatekeeper doesn't depend on a database of known malware. It has, however, the same limitations as XProtect, and in addition the following:
    It can easily be disabled or overridden by the user.
    A malware attacker could get control of a code-signing certificate under false pretenses, or could simply ignore the consequences of distributing codesigned malware.
    An App Store developer could find a way to bypass Apple's oversight, or the oversight could fail due to human error.
    For the reasons given above, App Store products, and other applications recognized by Gatekeeper as signed, are safer than others, but they can't be considered absolutely safe. "Sandboxed" applications may prompt for access to private data, such as your contacts, or for access to the network. Think before granting that access. OS X security is based on user input. Never click through any request for authorization without thinking.
    4. Starting with OS X 10.8.3, a third layer of protection has been added: a "Malware Removal Tool" (MRT). MRT runs automatically in the background when you update the OS. It checks for, and removes, malware that may have evaded the other protections via a Java exploit (see below.) MRT also runs when you install or update the Apple-supplied Java runtime (but not the Oracle runtime.) Like XProtect, MRT is presumably effective against known attacks, but maybe not against unknown attacks. It notifies you if it finds malware, but otherwise there's no user interface to MRT.
    5. XProtect, Gatekeeper, and MRT reduce the risk of malware attack, but they're not absolute protection. The first and best line of defense is always your own intelligence. With the possible exception of Java exploits, all known malware circulating on the Internet that affects a fully-updated installation of OS X 10.6 or later takes the form of so-called "trojan horses," which can only have an effect if the victim is duped into running them. The threat therefore amounts to a battle of wits between you and the malware attacker. If you're smarter than he thinks you are, you'll win.
    That means, in practice, that you never use software that comes from an untrustworthy source, or that does something inherently untrustworthy. How do you know what is trustworthy?
    Any website that prompts you to install a “codec,” “plug-in,” "player," "extractor," or “certificate” that comes from that same site, or an unknown one, is untrustworthy.
    A web operator who tells you that you have a “virus,” or that anything else is wrong with your computer, or that you have won a prize in a contest you never entered, is trying to commit a crime with you as the victim. (Some reputable websites did legitimately warn visitors who were infected with the "DNSChanger" malware. That exception to this rule no longer applies.)
    Pirated copies or "cracks" of commercial software, no matter where they come from, are unsafe.
    Software of any kind downloaded from a BitTorrent or from a Usenet binary newsgroup is unsafe.
    Software that purports to help you do something that's illegal or that infringes copyright, such as saving streamed audio or video for reuse without permission, is unsafe. All YouTube "downloaders" are in this category, though not all are necessarily harmful.
    Software with a corporate brand, such as Adobe Flash Player, must be downloaded directly from the developer’s website. If it comes from any other source, it's unsafe.
    Even signed applications, no matter what the source, should not be trusted if they do something unexpected, such as asking for permission to access your contacts, your location, or the Internet for no obvious reason.
    6. Java on the Web (not to be confused with JavaScript, to which it's not related, despite the similarity of the names) is a weak point in the security of any system. Java is, among other things, a platform for running complex applications in a web page, on the client. That was always a bad idea, and Java's developers have proven themselves incapable of implementing it without also creating a portal for malware to enter. Past Java exploits are the closest thing there has ever been to a Windows-style virus affecting OS X. Merely loading a page with malicious Java content could be harmful.
    Fortunately, client-side Java on the Web is obsolete and mostly extinct. Only a few outmoded sites still use it. Try to hasten the process of extinction by avoiding those sites, if you have a choice. Forget about playing games or other non-essential uses of Java.
    Java is not included in OS X 10.7 and later. Discrete Java installers are distributed by Apple and by Oracle (the developer of Java.) Don't use either one unless you need it. Most people don't. If Java is installed, disable it — not JavaScript — in your browsers.
    Regardless of version, experience has shown that Java on the Web can't be trusted. If you must use a Java applet for a task on a specific site, enable Java only for that site in Safari. Never enable Java for a public website that carries third-party advertising. Use it only on well-known, login-protected, secure websites without ads. In Safari 6 or later, you'll see a lock icon in the address bar with the abbreviation "https" when visiting a secure site.
    Follow the above guidelines, and you’ll be as safe from malware as you can practically be. The rest of this comment concerns what you should not do to protect yourself from malware.
    7. Never install any commercial "anti-virus" or "Internet security" products for the Mac, as they all do more harm than good, if they do any good at all. Any database of known threats is always going to be out of date. Most of the danger is from unknown threats. If you need to be able to detect Windows malware in your files, use one of the free anti-virus products in the Mac App Store — nothing else.
    Why shouldn't you use commercial "anti-virus" products?
    Their design is predicated on the nonexistent threat that malware may be injected at any time, anywhere in the file system. Malware is downloaded from the network; it doesn't materialize from nowhere.
    In order to meet that nonexistent threat, the software modifies or duplicates low-level functions of the operating system, which is a waste of resources and a common cause of instability, bugs, and poor performance.
    By modifying the operating system, the software itself may create weaknesses that could be exploited by malware attackers.
    8. An anti-malware product from the App Store, such as "ClamXav," doesn't have these drawbacks. That doesn't mean it's entirely safe. It may report email messages that have "phishing" links in the body, or Windows malware in attachments, as infected files, and offer to delete or move them. Doing so will corrupt the Mail database. The messages should be deleted from within the Mail application.
    An anti-virus app is not needed, and should not be relied upon, for protection against OS X malware. It's useful only for detecting Windows malware. Windows malware can't harm you directly (unless, of course, you use Windows.) Just don't pass it on to anyone else.
    A Windows malware attachment in email is usually easy to recognize. The file name will often be targeted at people who aren't very bright; for example:
    ♥♥♥♥♥♥♥♥♥♥♥♥♥♥!!!!!!!H0TBABEZ4U!!!!!!!.AVI♥♥♥♥♥♥♥♥♥♥♥♥♥♥.exe
    Anti-virus software may be able to tell you which particular virus or trojan it is, but do you care? In practice, there's seldom a reason to use the software unless a network administrator requires you to do it.
    The ClamXav developer won't try to "upsell" you to a paid version of the product. Other developers may do that. Don't be upsold. For one thing, you should not pay to protect Windows users from the consequences of their choice of computing platform. For another, a paid upgrade from a free app will probably have the disadvantages mentioned in section 7.
    9. It seems to be a common belief that the built-in Application Firewall acts as a barrier to infection, or prevents malware from functioning. It does neither. It blocks inbound connections to certain network services you're running, such as file sharing. It's disabled by default and you should leave it that way if you're behind a router on a private home or office network. Activate it only when you're on an untrusted network, for instance a public Wi-Fi hotspot, where you don't want to provide services. Disable any services you don't use in the Sharing preference pane. All are disabled by default.
    10. As a Mac user you don't have to live in fear that your computer is going to be infected every time you install an application, read email, or visit a web page. But neither should you have the false idea that you will always be safe, no matter what you do. The greatest harm done by security software is precisely its selling point: it makes people feel safe. They may then feel safe enough to take risks from which the software doesn't protect them. Nothing can lessen the need for safe computing practices.

  • What is the best mobile anti-virus for my Nokia 56...

    I want free mobile anti-virus so I will not waste my money and if possible, can you put the link for the anti-virus?
    antivirus discount

    I don't think you need to worry as the OS on your phone cannot get viruses. It run's on S40 (if you wanted to know).
    If I have helped you, please hit the star at the bottom of my posts - it's appreciated!
    Don't forget if your problem is solved to press the "Accept as Solution" button.

  • What is the best COSTING anti virus

    i need a mac anti virus that i can pay for i do not want a free nti virus cause i dont like them i need to know a good anti virus not like norton that f*ed My Mac Up It said 9 files r viruses to mac os and i deleted them and now i cant install anything on my mac so what s good anti viruses
    and should a do a clean istall of mac os cause now i cant install anything
    AND YES U DO NOT NEED TO TELL ME THAT MACS DONT GET VIRUSES I KNOW
    I Just need a anti virus for some backup sometimes

    No viruses that can attack OS X have so far been detected 'in the wild', i.e. in anything other than laboratory conditions.
    It is possible, however, to pass on a Windows virus to another Windows user, for example through an email attachment. To prevent this all you need is the free anti-virus utility ClamXav, which you can download for Tiger and Leopard from (on no account install Norton Anti-Virus on a Mac running OS X):
    http://www.clamxav.com/
    The new version for Snow Leopard is available here:
    http://www.clamxav.com/index.php?page=v2beta
    (Note: ClamAV adds a new user group to your Mac. That makes it a little more difficult to remove than some apps. You’ll find an uninstaller link in ClamXav’s FAQ page online.)
    However, the appearance of Trojans and other malware that can possibly infect a Mac seems to be growing, but is a completely different issue to viruses.
    If you allow a Trojan to be installed, the user's DNS records can be modified, redirecting incoming internet traffic through the attacker's servers, where it can be hijacked and injected with malicious websites and pornographic advertisements. The trojan also installs a watchdog process that ensures the victim's (that's you!) DNS records stay modified on a minute-by-minute basis.
    You can read more about how, for example, the OSX/DNSChanger Trojan works here:
    http://www.f-secure.com/v-descs/trojanosxdnschanger.shtml
    SecureMac has introduced a free Trojan Detection Tool for Mac OS X. It's available here:
    http://macscan.securemac.com/

  • Which is the best alround anti virus I have XP SP 3, windows essentials no longer supported now using thunderbird as well

    xp sp3 no longer supported need to change antivirus

    Hi,
    The best "all-around" antivirus is chosen by you. We have no influence on what antivirus you choose as it's based on personal preference but I can give you some samples on what I know. The below are all <b>free</b> by the way.
    *Avast (http://www.avast.com/en-us/index)
    *AVG (http://free.avg.com/us-en/homepage)
    *BitDefender (http://www.bitdefender.com/solutions/free.html)
    *Avira (http://www.avira.com/en/avira-free-antivirus)
    But in the end, it's up to you.
    P.S. This is a Firefox support forum used for technical support on Firefox. This thread is off-topic and doesn't belong here but I see that it's your first question here, I'll let it slide :)
    Let me know which antivirus you chose.
    Thanks!<br>
    -M

  • What is the best mac anti virus

    Please dont just say to get clamxav or that mac dont get viruses because they do.
    Well they mostly get trojans.
    ps clamxav *****!

    Hi,
    I have been using Sophos Antivirus, it has picked up trojans or whatever it was that was downloaded just by using Apple Mail on both my wife's user account, but at the time it picked it up I was using my own user account!!
    http://www.sophos.com/en-us/products/free-tools/sophos-antivirus-for-mac-home-ed ition.aspx.
    I know I won't be changing AV Products.
    Hope this helps.
    Hugh

  • Installation failing, giving error code 7, disabled the firewall and anti virus and rebooted the machine. Still getting error code 7. HELP

    Can anybody point me in the right direction to resolve error code 7?

    Try an alternative link and validate with your 24 digit serial number - click here for PSE downloads

  • Some kinds of the Security software(Anti-virus) always disable in Firefox,why ?

    None.

    They may not be compatible with firefox - it's most likely an add-on. Or if you could explain further it would help better.

Maybe you are looking for

  • System Image Utility fails to create boot image

    I am not able to successfully build a boot image with the System Image Utility. The build starts and runs for about 1 minute and then I get 100's of ditto messages saying "No space left on device". There's plenty of space left on the device. Eventual

  • How the system automatically kills the process when I close the browser?

    Hi everybody, I have the following problem: I run a report on the web browser. Suppose the user want to detail on one of the characteristics of report. If this takes long time (there are many records in report) and the user closes the web browser, th

  • Restore NOARCHIVELOG database in oracle 9i

    Hello guys, Please help me establish a way to restore my db. Here is the scenario ... The db version 9.2 was installed and running in the server (Windows). The DB was installed in D: drive. The C: drive of the server failed, so the server went down.

  • Seeing Friends wish list so I can buy their wishes as gift.

    Hi all; I know how to add items to my wish list and reaching them when I need . Do you know if there is any way I can see my friends wish lists so I can buy them as present ?      or Is there any way I can let them to see mine so they can make gifts

  • How to share disks without any volume manager

    Hello: Do I have to use volume manager, either Solstice or VxVM, in order to establish disk sharing in between a two-nodes Sun Cluster? The Sun Cluster consists of 2 1405s and shares a D1000. The scdidadm �L shows: � 12 solarisd1k:/dev/rdsk/c5t8d0 /d