NAC Framework Windows HotFixes

Hello,
I have implemented NAC Framework and i want know how i can manage the windows hotfixes. I want detect if the user have all hotfixes and if is missed return Checkup Posture-Token.
Regards.

The following url has enough information ,
http://www.cisco.com/en/US/netsol/ns617/networking_solutions_sub_solution_home.html

Similar Messages

  • NAC framework NAC-L2-802.1x, CTA 2.1, CSSC, ACS 4.2 not working???

    Hi
    I'm trying to setup my first crack at the NAC framework, using NAC-L2-802.1x. For this, the equipment I'm using is;
    Cisco 2950 switch (IOS /c2950-i6q4l2-mz.121-22.EA11.bin)
    Cisco 1811 router (inter-vlan routing)
    Cisco Secure ACS (90 day trial) 4.2
    CTA 2.1.103
    CSSC 5.1.0.39
    Windows XP SP3 client machine
    So I've tried to follow the Network Admission Control Framework Guide for the NAC-L2-802.1x section and all seems to have gone as laid out in the document, except when I get to the point where I actually test the config by bringing up the client port. I do the 'no shut' on the port, the light on the switch port goes amber and the CSSC client says its waiting for an ip address, it never pops up asking for credentials as shown in that document. I check the RADIUS server logs and there is no passes or fails for this host. I know RADIUS is working from this switch as I have it setup for login authentication which works just fine. I am completely stumped and the only thing I can think of is trying to install a full certificate server and going that way, instead of the Self Signed Cert which CSACS has generated and I've copied the .cer file to the client and installed it and verified it is installed with the Certificates MMC. Please, somebody provide some better reading on this matter, or some assistance. Thanks very much.
    Jason
    aaa new-model
    aaa authentication login default group radius local
    aaa authentication dot1x default group radius
    aaa authorization network default group radius
    aaa accounting dot1x default start-stop group radius
    dot1x system-auth-control
    Client port;
    interface FastEthernet0/1
    switchport mode access
    dot1x port-control auto
    dot1x timeout reauth-period server
    dot1x reauthentication

    You can refer to the below URL for future reference:
    http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/3.3/user/guide/nac.html
    http://www.cisco.com/en/US/netsol/ns617/networking_solutions_sub_solution_home.html

  • NAC Framework with TrendMicro Policy Server? External Posture Assessment?

    Hi
    I've got a NAC Framework 2.1 setup using NAC-L2-802.1x with 2950 switches and so far it's working great. I've recently begun testing NAC with TrendMicro OfficeScan, which includes the Trend Policy Server for Cisco NAC.
    I've imported the Trend.adf file, created a new Internal Posture Validation to check these TrendAV settings (DAT version, protection enabled, etc) and it is working great with the clients. (Healthy if up to date, quarantined if out of date).
    What I'm trying to do is get this integrated with the Trend Policy Server for Cisco NAC. I've created an External Posture Validation entry for the Trend Policy Server;
    https://win2k3std:4343/antibody
    And have supplied it with the password (no username is needed to login to the web console of this server). I've also selected Trend:AV as the forwarding credential. I've gone into Network Access Profiles and made sure this was selected as an External Posture Validation Server and set it to quarantine under "Failure Posture Token". When I test this from the client (once I've enable External Posture Validation), it always ends up quarantined (even though the client is fully up to date). If I disable the External Posture Validation server from the NAP, the client test passes as Healthy (since all AV is up to date).
    I've got the Policy Server for Cisco NAC defined under NAC on my Trend OfficeScan server, and on the Policy Server for Cisco NAC, I've got the OfficeScan server defined. Yet, no matter what I've tried, the client always fails with this msg in the CSACS logs;
    Posture Validation Failure on External Policy
    Does anyone have any experience or help with this. Thanks very much.
    Jason Humes

    Please check the links for the Configuration and Troubleshoot of NAC
    www.cisco.com/c/en/us/td/docs/security/nac/appliance/configuration_guide/48/cam/48cam-book/m_agntd.html
    www.cisco.com/c/en/us/td/docs/security/nac/appliance/configuration_guide/47/cam/47cam-book/m_agntd.html#wp1234860

  • NAC Framework with 802.1x authentication

    I am having trouble getting support and information on NAC framework. According to the cisco web NAC framework is in Phase 2 and is useable. According to Cisco representitives it is not supported yet. I have ACS 4.1, CTA 2.0, Symantec 10.1.4, and CSA 4.5. I can get NAC to work Layer 2, 802.1x to authenticate, but I cannot get both to work at the same time. Also, I have found no support for Symantec being checked even after I loaded the posture plugin, adf, etc. Is it time to give up on NAC framework? Thanks.

    My friend, i have a customer with whis configuration and worki fine.
    symantec need antivirus version 10 (8 or 9 no !!!!), the symantec posture plug installed in the clients.
    work fine wiht w2k and xp
    cta 2.x work fine. 1.x only work with L3 ip, no 802.1x.
    csa i don?t have experience.
    take care, it is hard to configure, if you need something more ask me to.
    Leo.

  • Software inventory for Windows Hotfix

    How do you do an inventory report or query for Windows Hotfix? It
    doesn't seem to be part of the inventory.
    Thanks.

    E,
    It appears that in the past few days you have not received a response
    to your posting. That concerns us, and has triggered this automated
    reply.
    Has your problem been resolved? If not, you might try one of the
    following options:
    - Do a search of our knowledgebase at
    http://support.novell.com/search/kb_index.jsp
    - Check all of the other support tools and options available at
    http://support.novell.com in both the "free product support" and "paid
    product support" drop down boxes.
    - You could also try posting your message again. Make sure it is
    posted in the correct newsgroup. (http://support.novell.com/forums)
    If this is a reply to a duplicate posting, please ignore and accept
    our apologies and rest assured we will issue a stern reprimand to our
    posting bot.
    Good luck!
    Your Novell Product Support Forums Team
    http://support.novell.com/forums/

  • NAC Framework NAC-L3-IP, passing posture validation, but no ACLs downloaded

    Hi
    I've got the NAC Framework NAC-L3-IP setup using an 1800 router and Cisco ACS Server 4.2. When my client attempts to reach the internet (through our NAD configured for network admission), I get a popup saying the Posture is Healthy, the ACS server says its good, yet I never get any of my configured ACLs downloaded to the router. I think my problem is with my RADIUS AUthorization Components...what should the Healthy RAC look like? This is what I've currently got;
    IETF Session-Timeout (27) 36000
    IETF Termination-Action (29) RADIUS-Request (1)
    Cisco IOS/PIX 6.0 cisco-av-pair (1) status-query-timeout=300
    I've got that RAC tied to a NAP and a downloadable ACL also associated to it through the Network Access Profiles page.
    Can anyone provide help with this. Thanks

    Ooops, nevermind, I had to enable aaa authorization network default group radius and then the ACLs downloaded as expected. Thanks!
    Jason

  • Hide Cisco NAC agent window

    Dear all,
    We have cisco NAC version 4.9.1 and the agent version is 4.9.1.5. We want to know if there is a way to hide the cisco NAC agent window so the user do not see it, i mean run it on the background to make it a bit more transparent to the final user.
    Anyone have any ideas?
    Thanks in advance.

    Go to "Administration > User Pages" and make sure you have configured a proper login page for Windows 7.

  • How to qualify for NAC Framework?

    Hi, we have been considering NAC for a while and have evaluated NAC Appliance. However, we have a requirement to use 802.1x for posture validation, authentication etc. I have looked at cisco trust agent and there is a statement about needing to be 'approved' to deploy CTA? Any one have any ideas about how to go about this and to be able to deploy NAC framework? We feel framework fits our situation much better than appliance. Many thanks for your time.

    Exact statement would be
    "The Cisco Trust Agent is available for download only by customers approved to deploy the NAC Framework solution. If you are not approved, please contact your Cisco account team about Cisco NAC solutions. Deprecated versions of Cisco Trust Agent - CLITE client may be found at http://www.cisco.com/cgi-bin/tablebuild.pl/cta-deprecated "
    From the URL http://www.cisco.com/cgi-bin/tablebuild.pl/cta

  • Configuring NAC Framework ( NAC-L3-IP ), any guides or help?

    So I've been doing some research on the NAC Framework and the various modes of operation. So far, I've gotten NAC-L2-802.1x working great and I'd like to add on the NAC-L3-IP on our edge routers/firewalls, but I can't find any guides detailing how to do so...everything says to see the "NAC Implementation Guide" which I can't find anyplace. Can anyone direct me to a NAC-L3-IP guide? Thanks very much.
    Jason

    Hi,
    below is the link, On left had side you will find tech doc.
    http://www.cisco.com/en/US/netsol/ns617/networking_solutions_sub_solution_home.html
    The below link also will help more.
    http://www.cisco.com/en/US/docs/security/nac/appliance/configuration_guide/413/cam/m_cca.html
    Hope this helps.
    Regards
    pravin

  • NAC Framework and NAC Appliance in scenary WAN

    How will be the scenary of NAC appliance and NAC Framework in a topology WAN, for example i have my core and remote office and I want to implement NAC for all remote site and central site.
    which will be the solution?
    Best Regards

    Hello Daladen,
    Which is the solution for WAN topology in NAC Appliance?
    one NAS for Site? and the NAM in the Central?
    Thanks
    Álvaro

  • NAC Framework vs NAC Appliance??? Cisco says, Appliance is 'easier'...

    Hi
    So I've recently been told by Cisco that I shouldn't be deploying the NAC framework and that they REALLY suggest the appliance instead. Can anyone provide me with some REAL reasons why I'd want to purchase more hardware from Cisco when I've already got all the necessary pieces for the Framework deployed on my network. Cisco, at this point, has not given me a good reason other than, the appliance is easier to deploy...and to me, that is a highly subjective statement. Please help. Thanks
    Jason

    Jason,
    From my experience the appliances are the way to go. It is just like Colin said, the deployment is much easier. What's more the testing is much easier. For instance, in a typical out-of-band solution for a wired network you could test your configuration on a single port on a single switch. This is much less invasive than the NAC framework and much easier to tune.
    Just my 2 cents. Hope this helps.
    Paul

  • Windows Hotfix Thininstal​ler SCCM

    Hello,
    I apply the thininstaller to install drivers on our models.
    I have successfully been able to apply the windows hotfixes by adding them to the sccm task sequence as a package and installing them directly with the msu file (silent switch /quiet /norestart through command line).
    My question:
    Since there are different hotfixes for different models, are they really important to the overall performance and experience? 
    Shouldn't these be applied through Windows Updates?

    Hotfixes are the way Microsoft does bug fixes.  They release hotfixes somewhat quickly, and then after an extended period of testing (sometimes several months, or more), they usually go into Windows Update and/or a Service Pack.
    The readme for each hotfix describes what it is intended to solve.  A lot of them are specific to a certain configuration, or a unique situation that might not apply to you.
    It's really your own judgement call whether to deploy the hotfixes or not.  Personally, I would skip them unless you're having the specific issue/bug that the hotfix is intended to solve.

  • NAC FRAMEWORK

    Hello,
    I want to know if NAC FRAMEWORK is EOL/EOS what deployment can i use?
    Best Regards
    Álvaro

    I believe NAC Appliance is the one closest to NAC framework:
    http://www.cisco.com/en/US/prod/collateral/vpndevc/ps5707/ps8418/ps6128/product_data_sheet0900aecd802da1b5.html
    regards,

  • NAC not checking the Window hotfix policy eventhough the hotfix is installed

    I need a little help in deploying the NAC . I am using the NAC in OOB Virtual Gateway mode.  I am facing a problem that i have made a check which check if KB910437 is available on the machine or not .If it is not it goes to microsoft site and download the patch and install it on machine manually. After installation still my device doesn't come in certification list .I have attached the screen shot of the check list ,Rules and requirement for the reference.
    The path given for the update to check is
    HKLM \  HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Updates\Windows XP\SP3\KB910437\

    HKLM \  HKEY_LOCAL_MACHINE is wrong, you need only HKLM\SOFTWARE\Microsoft\...
    because HKLM= HKEY_LOCAL_MACHINE

  • NAC check windows firewall

    Hi,
    Is there a NAC CCA check to see whether the windows firewall is enabled or not?
    Thanks,
    Wei

    Hi,
    Thanks for the reply. I am looking at the ICF firewall. Do you know what's the pre-configured check/rule name for it.
    Anyway, after googled on the internet, I found the ICF firewall was controlled by the following registry setting. I manually created a check/rule. It seems working. Now I will further find out what's the registry related to the vista windows firewall.
    [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\]
    "EnableFirewall"=dword:1
    Regards,
    Wei

Maybe you are looking for