NAC Agent on MAC OSX 10.9

Hi,
I found on our setup, NAC Agent for MAC does not run properly on MAC OSX 10.9, even the latest MAC Nac Agent (version 4.9.0.1007)
It does not scan, does not pop up, and the endpoint's posture status is always stucked on pending state.
Does any one experience the same?
When will Cisco support it.
Best Regards,
Tomi

NAC Agent 4.9.0.1013 was posted to CCO yesterday and has support for Mac OS 10.9.
NAC & ISE supports for latest OSes - Windows 8.1 and MAC OSX 10.9
NAC:
NAC Server patch for NAC 4.9.3 release is published on CCO. Refresh NAC and Web Agents are posted on Perfigo  and CCO sites.
Customer may please be advised to apply Server patch, refresh Agents and  update to latest Compliance Module and Support Charts v3.6.7873.2.
ISE:
ISE 1.2 Patch 3 is published on CCO and Refresh Agents are posted onto provisioning-update feed file on perfigo server.
Customer may please be advised to apply Server patch, provision refresh Agents and to do a posture-update get latest Compliance Module and Support Charts v3.6.7873.2.
Please refer respective release notes for open caveats.
Please rate helpful posts and mark as answered if this fixes your issue.
Charles Moreton

Similar Messages

  • NAC Agent Login Dialog Not Appearing - ISE 1.1.1 issue ?

    Agent Fails to Initiate Posture Assessment
    The NAC agent is properly installed on a Windoes 7 , IE 9 machine, the certificates from ISE ADM PRI are installed in trustable certificate store in the client machine but is a selfsigned ISE certificate.
    The reports / USER / Profiling report says the Provisioning Agent has completed the assessment ok.
    The redirected URL is working fine (SEE Evidence)
    We are always prompted to install the NAC agent again or looking at the additional prompted information wait for the NAC agent to load and complete.
    The operations status remains with postering status pending forever and nothing else happens.
    Symptoms or Issue
    The agent login dialog box does not appear to the user following client provisioning.
    Conditions Cisco Says this issue can generally take place during the posture assessment phase of any user
    authentication session.
    Cisco Advises as Possible Causes There are multiple possible causes for this type of issue. See the following
    Resolution descriptions for details of what was already tested by us and please see the atached files for your switch configuration and evidences. .
    CISCO SUGGESTED POSSIBLE CAUSES AND RESOLUTIONS
    Resolution • Ensure that the agent is running on the client machine. ALL TESTED OK
    • Ensure that the Cisco IOS release on the switch is equal to or more recent than
    Cisco IOS Release 12.2.(53)SE. - OK
    • Ensure that the discovery host address on the Cisco NAC agent or Mac OS X
    agent is pointing to the Cisco ISE FQDN. (Right-click on the NAC agent icon,
    choose Properties, and check the discovery host.) - OK (See evidence)
    • Ensure that the access switch allows Swiss communication between Cisco ISE
    and the end client machine. Limited access ACL applied for the session should
    allow Swiss ports: ALL CONFIGURED as CISCO GUIDELINES OK (SEE EVIDENCE)
    • If the agent login dialog still does not appear, it could be a certificate issue.
    Ensure that the certificate that is used for Swiss communication on the end client
    is in the Cisco ISE certificate trusted list. (ALL CHECKED OK SEE EVIDENCE)
    • Ensure that the default gateway is reachable from the client machine. (TESTED OK)

    Hi.
    Can you paste all the ACLs on your switch especially the webauth redirect ACL which should deny traffic towards the PSN.
    regards
    Zubair

  • NAC agent don't popup on some computer

    Hi
    I use
    ISE version : 1.1.1.2 and NAC agent version : 4.9.0.42
    NAC agent  does not run on some computers and run on other(windows 7).
    What can be these problems?
    Please help
    Regards

    Please look in to this , it might help you
    Agent Login Dialog Not Appearing
    Symptoms or Issue
    The agent login dialog box does not appear to the user following client provisioning.
    Conditions
    This issue can generally take place during the posture assessment phase of any user authentication session.
    Possible Causes
    There are multiple possible causes for this type of issue. See the following Resolution descriptions for details.
    Resolution
    •Ensure that the agent is running on the client machine.
    •Ensure that the Cisco IOS release on the switch is equal to or more recent than Cisco IOS Release 12.2.(53)SE.
    •Ensure  that the discovery host address on the Cisco NAC agent or Mac OS X  agent is pointing to the Cisco ISE FQDN. (Right-click the NAC agent icon, choose Properties, and check the discovery host.)
    •Ensure  that the access switch allows Swiss communication between Cisco ISE and  the end client machine. Limited access ACL applied for the session  should allow Swiss ports:
    remark Allow DHCP
    permit udp any eq bootpc any eq bootps
    remark Allow DNS
    permit udp any any eq domain
    remark ping
    permit icmp any any
    permit tcp any host 80.0.80.2 eq 443 --> This is for URL redirect
    permit tcp any host 80.0.80.2 eq www --> Provides access to internet
    permit tcp any host 80.0.80.2 eq 8443 --> This is for guest portal
    port
    permit tcp any host 80.0.80.2 eq 8905 --> This is for posture
    communication between NAC agent and ISE (Swiss ports)
    permit udp any host 80.0.80.2 eq 8905 --> This is for posture
    communication between NAC agent and ISE (Swiss ports)
    deny ip any any
    •If  the agent login dialog still does not appear, it could be a certificate  issue. Ensure that the certificate that is used for Swiss communication  on the end client is in the Cisco ISE certificate trusted list.
    •Ensure that the default gateway is reachable from the client machine.

  • Cisco NAC Agent 4.9.1.682 Problems with Mac Os X 10.7.4

    Hi
    My Cisco NAC Agent  (version 4.9.1.682) doesn't work since I upgraded my Mac OS X  4 months ago, This happens every time with CISCO and MAC when there is a new update and it always seems to take forever to fix.
    The NAC agent just keeps asking for my login in details even though there are correct (I can log in with a PC no problem).
    Any update on when a new version is going to be released - Its getting really frustrating?

    I figured out a solution that works you must disable Online Certificate Status Protocol (OCSP) on the affected system. To do this :
        Open Keychain Access. Keychain Access can be found by selecting Go in the Finder and choosing the Utilities option. Keychain access should be listed in the folder that appears. Double-click the Keychain Access icon to open it.
        Select Keychain Access -> Preferences from the menu at the top of the screen
        Choose the Certificates tab
        Change the OCSP option from Best Effort to Off
        Close the Preferences dialog and quit Keychain Access
        You should be able to NAC now

  • Mac OSx Inventory Agent (followup)

    Hi guys,
    First I want to wish a Merry Christmas and Happy New Year to all you guys on the forum :)
    Second:
    I had the chance to work with the Mac OSx Inventory Only Agent and it didnt impress me much. Maybe some of you guys can help me change my mind ;)
    Here's what I have so far. After doing some tests couple months ago I found how to personalize the Agent .PKG so that the Inventory would be installed unatented ( without entering the ZENworks server ip or DNS manually on each machine). So, when the package is run, the Inventory Only run according the Schedule, noting wrong here.
    For a reason I ignore, it seems like none of the changes made on those MAC are taken by the agent and sent to the ZENworks server. For instance, I did the Snow Leopard (10.6) update on my laptop (MacbookPro) which owns the MacOSx Inventory agent since june.
    When I checked back the invetory data with the reports tool on the ZENworks server, the data wasnt updated...and never will.
    Same thing happened when I change the name of a MacMini tha owns the Inventory Agent. His name wasnt updated on the server info.
    Finally, it seems like none of the change made on any MacOSx workstations are taken by the agent and sent to the server. Thats not very usefull when you relly on this inventory agent to get an global idea of your network assets.
    I know the MacInventory is not Novell priority but, why provide us a MacOSx agent, when it doesnt do his job the way it should?
    Anyway, maybe one of you guys had better luck, just let me know here !!!
    Seb

    sebastien,
    It appears that in the past few days you have not received a response to your
    posting. That concerns us, and has triggered this automated reply.
    Has your problem been resolved? If not, you might try one of the following options:
    - Visit http://support.novell.com and search the knowledgebase and/or check all
    the other self support options and support programs available.
    - You could also try posting your message again. Make sure it is posted in the
    correct newsgroup. (http://forums.novell.com)
    Be sure to read the forum FAQ about what to expect in the way of responses:
    http://forums.novell.com/faq.php
    If this is a reply to a duplicate posting, please ignore and accept our apologies
    and rest assured we will issue a stern reprimand to our posting bot.
    Good luck!
    Your Novell Product Support Forums Team
    http://support.novell.com/forums/

  • Mac OS X 10.8.1 and Cisco Nac Agent to 4.9.1.683

    We have this problem with on of our clients:
    "Cisco NAC Agent is having a difficulty with the server. Agent user operation system
    is not supported".
    Anyone encounter this problem ?
    thanks.

    Hi Tarik,
    We have:
    Cisco Clean Access Server   Version 4.9.0
    Cisco Clean Access Lite Manager   Version 4.9.0
    I can see Your point now,  that I should start from upgrading to 4.9.1.
    Let me do  that, and see if it helps.
    thanks  very much, I will keep You posted.

  • Guest Posture Assessment for MAC OSX

    Hi
    I need to perform posture assessment for guest users who own MAC OSX machines , but i couldn't find Webagent available for Mac Osx just regular NAC_AGENT for MAC, so i need to know if it's supported ?
    thanx

    Mac OS X Agent need to be used for posture assessment and remediation
    http://www.cisco.com/c/en/us/td/docs/security/nac/appliance/configuration_guide/47/cam/47cam-book/m_webagt.html#wp1556106

  • Mac osx 10.9.4 slow startup

    Please help shorten startup time. Takes 87 seconds from account/password login until desktop loads and even more time for applications to start.
    Equipment = Mac Mini (late 2011) running Mac OSX 10.9.4 2.3 with GHz Intel Core i5 and 16 GB memory and 500GB storage of which 300 is free
    Here is Etrecheck result:
    EtreCheck version: 1.9.15 (52)
    Report generated September 12, 2014 at 1:20:10 PM PDT
    Hardware Information: ?
      Mac mini (Mid 2011) (Verified)
      Mac mini - model: Macmini5,1
      1 2.3 GHz Intel Core i5 CPU: 2 cores
      16 GB RAM
    Video Information: ?
      Intel HD Graphics 3000 - VRAM: 512 MB
      PA246 1920 x 1200 @ 60 Hz
    System Software: ?
      OS X 10.9.4 (13E28) - Uptime: 0 days 0:4:5
    Disk Information: ?
      Hitachi HTS545050B9A302 disk0 : (500.11 GB)
      S.M.A.R.T. Status: Verified
      EFI (disk0s1) <not mounted>: 209.7 MB
      disk0s2 (disk0s2) <not mounted>: 499.25 GB
      Recovery HD (disk0s3) <not mounted>: 650 MB
    USB Information: ?
      Logitech USB Receiver
      Apple Inc. BRCM20702 Hub
      Apple Inc. Bluetooth USB Host Controller
      EZKEY USB Keyboard
      EZKEY USB Keyboard
      Apple Computer, Inc. IR Receiver
    Thunderbolt Information: ?
      Apple Inc. thunderbolt_bus
    Gatekeeper: ?
      Mac App Store and identified developers
    Kernel Extensions: ?
      [loaded] com.Logitech.Control Center.HID Driver (3.4.0 - SDK 10.0) Support
      [loaded] com.Logitech.Unifying.HID Driver (1.2.0 - SDK 10.0) Support
      [not loaded] com.microsoft.VirtualPC.Networking (7.0.0) Support
      [not loaded] com.microsoft.VirtualPC.Networking.1040 (7.0.2) Support
      [not loaded] com.microsoft.VirtualPC.OSServices (7.0.0) Support
      [not loaded] com.palm.ClassicNotSeizeDriver (3.2.1) Support
      [not loaded] com.pctools.iantivirus.kfs (1.0.1) Support
      [not loaded] com.roxio.TDIXController (1.6) Support
    Launch Daemons: ?
      [loaded] com.adobe.fpsaud.plist Support
      [running] com.backblaze.bzserv.plist Support
      [loaded] com.google.keystone.daemon.plist Support
      [running] com.motive.systemDaemon.plist Support
      [loaded] com.sonos.smbbump.plist Support
    Launch Agents: ?
      [loaded] com.google.keystone.agent.plist Support
      [running] com.motive.alertDetectorHost.plist Support
      [running] com.motive.userAgent.plist Support
      [running] net.culater.SIMBL.Agent.plist Support
    User Launch Agents: ?
      [loaded] com.adobe.ARM.[...].plist Support
      [running] com.backblaze.bzbmenu.plist Support
    User Login Items: ?
      None
    Internet Plug-ins: ?
      nplastpass: Version: 2.5.5 Support
      o1dbrowserplugin: Version: 5.4.2.18903 Support
      Default Browser: Version: 537 - SDK 10.9
      Flip4Mac WMV Plugin: Version: 2.4.4.2 Support
      npMotive: Version: 1.0.0 - SDK 10.7 Support
      AdobePDFViewerNPAPI: Version: 11.0.07 - SDK 10.6 Support
      FlashPlayer-10.6: Version: 15.0.0.152 - SDK 10.6 Support
      DivXBrowserPlugin: Version: 1.0 Support
      Flash Player: Version: 15.0.0.152 - SDK 10.6 Support
      iPhotoPhotocast: Version: 7.0
      googletalkbrowserplugin: Version: 5.4.2.18903 Support
      QuickTime Plugin: Version: 7.7.3
      AdobePDFViewer: Version: 11.0.07 - SDK 10.6 Support
      EPPEX Plugin: Version: 3.0.5.0 Support
      Scorch: Version: ScorchNetscapePlugin 4.1.4 build 1 Support
      JavaAppletPlugin: Version: 14.9.0 - SDK 10.7 Check version
    Safari Extensions: ?
      ClickToFlash-2
      LastPass-2
    Audio Plug-ins: ?
      BluetoothAudioPlugIn: Version: 1.0 - SDK 10.9
      AirPlay: Version: 2.0 - SDK 10.9
      AppleAVBAudio: Version: 203.2 - SDK 10.9
      iSightAudio: Version: 7.7.3 - SDK 10.9
    iTunes Plug-ins: ?
      Quartz Composer Visualizer: Version: 1.4 - SDK 10.9
    User Internet Plug-ins ?
      Google Earth Web Plug-in: Version: 7.1 Support
    3rd Party Preference Panes: ?
      Backblaze Backup  Support
      Déjà Vu  Support
      Flash Player  Support
      GlimmerBlocker  Support
      Logitech Control Center  Support
    Time Machine: ?
      Mobile backups: OFF
      Auto backup: NO - Auto backup turned off
      Time Machine not configured!
    Top Processes by CPU: ?
          4% WindowServer
          2% com.apple.WebKit.WebContent
          1% bzfilelist
          0% mds
          0% fontd
    Top Processes by Memory: ?
      229 MB com.apple.WebKit.WebContent
      98 MB mds_stores
      98 MB Safari
      98 MB node
      98 MB com.apple.IconServicesAgent
    Virtual Memory Information: ?
      13.08 GB Free RAM
      1.24 GB Active RAM
      182 MB Inactive RAM
      1.50 GB Wired RAM
      205 MB Page-ins
      0 B Page-outs

    87 seconds isn't unreasonable but you might be able to improve upon it.
    Back up your system. To learn how to do that read Mac Basics: Time Machine backs up your Mac.
    PC Tools "iAntiVirus" is worthless. Remove it by following these instructions: How to Uninstall PC Tools iAntiVirus
    Like most subscription-based backup services, Backblaze runs poorly on Macs. Try disabling or uninstalling it according to its instructions.
    Evaluate the results.

  • NAC Agent and NSP provisioning with ISE 1.1.1

    I am trying to get all workstations (OSX and Windows) to install both the Native Supplicant Wizard and NAC Agent during the On-boarding process.
    I am currently using the default guest portal in ISE.
    The environment has been setup using a Dual SSID design.
    At the moment, devices can connect to the provisioning SSID and get CWA. Device registration works, the portal runs the NSP setup which correctly sets up the network adapter.
    The problem is the portal never attempts to install the NAC Agent.
    The client provisioning policy has a separate policies for wireless/wired as well as OS. Each policy applies both a NSP and NAC Agent configuration. It appears the guest portal only checks the NSP configuration and not the NAC Agent config.
    Any ideas?

    Just so i understand this correctly you are using both a client provisioning portal and a native supplicant provisoning portal tied into seperate authz policies.
    With that out of the way are you checking to see if the client is compliant in the client provisioning portal policy.
    Let me know if you have the following configured (example windows OS), this is assuming that the endpoint is statically assigned to RegisteredDevices after native suppliant provisioning.
    Rule 0 (endpoint group = RegisteredDevice) AND (AD:Domain user and authentication method:x509 and posturestatus:COMPLIANT) = Permit Access
    Rule 1 (endpoint group = RegisteredDevice) AND (AD:domain user AND authentication method:x509[if you deployed certs in the native supp condition] AND workstation NOT EQUAL:COMPLIANT) RESULT client provisioning portal.
    Rule 2 (endpoint group = Workstation) AND (AD:Domain User AND authentication mehod using mschapv2) RESULT windows provisioning portal
    Hope that helps,
    Tarik Admani
    *Please rate helpful posts*

  • NAC agent failing to popup

                       Dears,
    I have two ISE appliances installed in a distributed deployment (primary "ISE1" and secondary "ISE2"), each node has the three personas installed on it. The servers are registered together and the replication is working properly between the nodes.
    When we are working on the first node everything is fine, if I try to disconnect ISE1 and do my tests on ISE2, the cisco NAC agent doesn't popup, unless I uninstall it and reinstall it again from the ISE2. Then it will work properly.
    Note: the NAC agent version is the following: nacagent-4.9.0.37.
    Any idea?
    Regards
    Zahi

    Hi Tarik,
    below are my answers:
    1- The content of the dACL:
    ip access-list extended POSTURE-REMEDIATION
    permit udp any any eq domain
    permit ip any host 10.10.10.125         >>>> antivirus server
    permit ip any 10.10.240.0 0.0.0.255   >>>> voice subnet
    permit ip any 10.10.31.0 0.0.0.255    >>>> quarantine vlan subnet
    permit ip any host 10.10.10.238        >>>> ip add of ISE1
    permit ip any host 10.10.10.239        >>>> ip add of ISE2
    permit ip any host 10.10.10.206        >>>> wsus server
    permit ip any host 10.10.10.10          >>>> domain 1
    permit ip any host 10.10.10.100          >>>> domain 2
    2- When I open a web browser, yes I get redirected to the nac agent download page
    3- outputs of the show authentication session interface fast 0/12, when the agent pops up with ISE1:
    sw#sho authentication sessions int fast 0/12
                Interface:  FastEthernet0/12
              MAC Address:  b8ac.6fc9.b26f
               IP Address:  10.10.31.2
                User-Name:  RJ\15592
                   Status:  Authz Success
                   Domain:  DATA
          Security Policy:  Should Secure
          Security Status:  Unsecure
           Oper host mode:  single-host
         Oper control dir:  both
            Authorized By:  Authentication Server
              Vlan Policy:  31
                  ACS ACL:  xACSACLx-IP-POSTURE-REMEDIATION-4fe82900
         URL Redirect ACL:  ACL-POSTURE-REDIRECT
             URL Redirect:  https://RJ-ISE-1.rj.com:8443/guestportal/gateway?session
    Id=0A0A0C86000000186ADBBD8B&action=cpp
          Session timeout:  N/A
             Idle timeout:  N/A
        Common Session ID:  0A0A0C86000000186ADBBD8B
          Acct Session ID:  0x00000023
                   Handle:  0x31000018
    Runnable methods list:
           Method   State
           dot1x    Authc Success
           mab      Not run
    sw#sho authentication sessions int fast 0/12
                Interface:  FastEthernet0/12
              MAC Address:  b8ac.6fc9.b26f
               IP Address:  10.10.30.12
                User-Name:  RJ\15592
                   Status:  Authz Success
                   Domain:  DATA
          Security Policy:  Should Secure
          Security Status:  Unsecure
           Oper host mode:  single-host
         Oper control dir:  both
            Authorized By:  Authentication Server
              Vlan Policy:  30
                  ACS ACL:  xACSACLx-IP-PERMIT_ALL_TRAFFIC-4f57e406
          Session timeout:  N/A
             Idle timeout:  N/A
        Common Session ID:  0A0A0C86000000186ADBBD8B
          Acct Session ID:  0x00000023
                   Handle:  0x31000018
    Runnable methods list:
           Method   State
           dot1x    Authc Success
           mab      Not run
    outputs of the show authentication session interface fast 0/12, when the agent pops up with ISE2:
    sw#sho auth sessions int fast 0/12
                Interface:  FastEthernet0/12
              MAC Address:  0025.6458.8409
               IP Address:  10.10.31.8
                User-Name:  RJ\15946
                   Status:  Authz Success
                   Domain:  DATA
          Security Policy:  Should Secure
          Security Status:  Unsecure
           Oper host mode:  single-host
         Oper control dir:  both
            Authorized By:  Authentication Server
              Vlan Policy:  31
                  ACS ACL:  xACSACLx-IP-POSTURE-REMEDIATION-4fe82900
         URL Redirect ACL:  ACL-POSTURE-REDIRECT
             URL Redirect:  https://RJ-ISE-2.rj.com:8443/guestportal/gateway?session
    Id=0A0A0C86000000206AF3FAC1&action=cpp
          Session timeout:  N/A
             Idle timeout:  N/A
        Common Session ID:  0A0A0C86000000206AF3FAC1
          Acct Session ID:  0x0000002B
                   Handle:  0x2C000020
    Runnable methods list:
           Method   State
           dot1x    Authc Success
           mab      Not run
    you may find attached also the pcap file of the client machine when it is authenticating with the ISE2.
    Thank you in advance
    Zahi
    Message was edited by: ZAHI BOU KHALIL

  • How to install Nac Agent 4.8.3.594 patch (Patch-CSCty91628.gz)?

    Hello, Guys
    I have installed NAC 4.8 with agent 4.8.3.594 in the Mac OS Mountain Lion 10.8.2 and NAC Agent isn't working.
    We found these Cisco Website information:
    http://www.cisco.com/en/US/docs/security/nac/appliance/release_notes/48/483rn.html#wp1310587
    Support for Mac OS X 10.8
    Mac OS X Agent version 4.8.3.594 supports Mac OS X 10.8 "Mountain Lion". You need to download a server patch to enable the support from the following URL:
    http://software.cisco.com/download/release.html?mdfid=282855549&flowid=34712&softwareid=282562546&release=4.8.3&relind=AVAILABLE&rellifecycle=&reltype=latest
    Someone How to know install the patch (Patch-CSCty91628.gz) and Where I do it?
    Tks,
    Rodrigo Freitas

    Hello, Guys
    I have installed NAC 4.8 with agent 4.8.3.594 in the Mac OS Mountain Lion 10.8.2 and NAC Agent isn't working.
    We found these Cisco Website information:
    http://www.cisco.com/en/US/docs/security/nac/appliance/release_notes/48/483rn.html#wp1310587
    Support for Mac OS X 10.8
    Mac OS X Agent version 4.8.3.594 supports Mac OS X 10.8 "Mountain Lion". You need to download a server patch to enable the support from the following URL:
    http://software.cisco.com/download/release.html?mdfid=282855549&flowid=34712&softwareid=282562546&release=4.8.3&relind=AVAILABLE&rellifecycle=&reltype=latest
    Someone How to know install the patch (Patch-CSCty91628.gz) and Where I do it?
    Tks,
    Rodrigo Freitas

  • Will firefox insall as my default browser on a mac osx 10.4.11?

    Will Firefox install as my default browser on a mac osx 10.4.11 using safari, version 4.1?
    I dont want to use firefox as my default browser, I want to use both browsers.
    == User Agent ==
    Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10_4_11; en) AppleWebKit/533.16 (KHTML, like Gecko) Version/4.1 Safari/533.16

    Firefox will ask if you want to make it the default browser, and you can select no.
    See:
    [[How to make Firefox the default browser]]
    [[Setting Firefox as the default browser does not work]]

  • NAC Agent/ActiveX/Java applet

    Hi,
    For L3 OOB deployment , does any one know how the NAC agent/ActiveX/Java applet refresh the IP address for the client??
    i know that In the Login Page configuration, two options need to be checked to use the ActiveX/Applet webclient to
    refresh the client’s IP address:
    - Use web client to detect client MAC address and Operating System
    - Use web client to release and renew IP address when necessary (OOB) .
    But what i need to know how the agent/ActiveX/Java applet refresh the IP address for the client???
    are these programs ( agent/ActiveX/Java applet ) triggers the client machine to do that???
    regards
    MAM

    MAM,
    You're right. The applets do indeed trigger a dhcp refresh on the machines. This is to avoid bouncing the port which can be problematic when you have IP phones.
    More info on this in the docs here: http://tinyurl.com/yhnskdf
    HTH,
    Faisal

  • Question about cisco nac agent

    When I deploy Cisco NAC appliance, the main different between using cisco nac appliance with or without agent? I see Cisco NAC agent has two function: scan and remediation. If Cisco NAC appliance without agent, Cisco NAC server will scan device and remediation. That is right?
    Please answer me early. Thank you for your answer.

    Sorry, I believe daldden is correct, without the agent you can still scan using the built-in Nessus scanner.
    We don't use the Nessus scanner, but these are some things to consider if you use the scanner. These are from memory though so anyone who actively uses the scanner may be able to give more up to date or complete info:
    1) You have to decide which vulnerabilities you want to scan for.
    2) The more plug-ins you enable, the longer (obviously) the scan takes.
    3) There are configuration steps for many of the plug-ins
    4) Your users will still need to go to a login page in order to be scanned.
    5) You have to configure the remediation information (URL, steps, etc) for each plug-in you enable.
    From our view point, the only reason we would enable the scanner is if we were looking for a specific vulnerability, perhaps a new threat that didn't yet have a patch. If it had a patch, we would watch for the patch using the agent (installed or web based).
    It was much easier for us to use the agent, to scan their system and make sure that the MS critical hot fixes were installed and/or an AV system was installed and up to date. As mentioned, if there is a patch for a vulnerability, you can use the agent to make sure that specific hot fix is installed.
    Remember that there is also a web agent. The web agent is an ActiveX or Java (you pick which one you want to use) applet that is loaded onto the person's machine, the system scanned, then the applet is unloaded.
    Of course, the agent is only for MSoft (with some MAC options), so if you have Linux systems, the Nessus scanner would be your only option.

  • Mac OSX download stops at 256 MB.

    When attempting to download a file (DMG) of 282 MB in size to a Mac OSX 10.5 system, the download always stops when progress gets to 256 MB. The error dialog displayed says:
    =============
    Download Error
    <path>/netbeans-6.9.1-ml-macosx.dmg.part could not be saved, because the source file could not be read.
    Try again later, or contact the server administrator.
    =============
    The "part" file is always exactly 268434369 bytes in length.
    I am able to download the file successfully using Safari, so I do not believe this is an OSX-specific issue.

    Hi, everyone!
    I found a solution disabling all my addons. I suspected that because a had installed a lot of them. But I don't know exactly by now which one of them is to be blame. I don't have time to find it now.
    The addons I installed are these above. If you have one or many of then maybe it could be esier to find out the guilty. So, please, reply if you find out the problematic addon. Thanks!
    CSS Usage
    DownloadHelper
    Firecookie
    Gresemonkey
    JSONView
    User Agent Switcher
    Web Developer
    YSlow
    P.S. I use Firefox 7, runing on Linux Fedora 15 64bit.

Maybe you are looking for