NAC vs ASA Built-in Feature

Hi,
I am looking a secure solution for around 25 users - to remote access into our datacentre.
Obvioudly a secure tunnel is needed (SSL/Ipsec), BUT ALSO, i want a solution to provide 'posture assesment' of sorts.
Now, NAC is very expensive for this small type of smallish network.
I have been looking at the ASA55** feature "Pre-Connection Posture Assessment" with the Cisco Secure Desktop :-
It offers "Host integrity verification checking seeks to detect the presence of antivirus software, personal firewall software, and Windows service packs on the endpoint system prior to granting network access."
I think this is PERFECT !!
Can anyone please tell me how this differs from NAC and would it survice ??
Thank you.
P.S I intend to use the IPS module too, to ensure data passing the ASA will be "scrubed" clean.

The Cisco Secure Desktop feature is only available with SSL VPNs, and not with IPSEC. If you plan to use ONLY SSL VPNs then CSD is a reasonable solution for small setups.
For IPSEC endpoints you need to go with NAC.
Regards
Farrukh

Similar Messages

  • Help! Built in features/hints not working flash cs6. Need fix ASAP

    Loads of built in features are not working for me in Flash CS6. When I was using CS4 they did, now they aren't. I will give two examples. Say for example I am writing code in the actions window and I type "green_btn." in regards to the name of a button instance, what usually happens when I hit the "." immediately after "green_btn" a menu will pop up showing me every option I can pick, like green_btn.addEventListener() etc etc. There is usually a menu that comes up, but for me there is no menu. I have also created a button symbol, placed an instance of it on the stage, named the instance and tried it again (cs6 is supposed to recognize the "_btn" automatically and make the menu come up even if there is no button created, but I decided to create one just in case), and no menu pops up, still . Something is wrong here, it used to work for me when I had CS4 installed. Another example is if I am in the actions window again, and I type in a function like trace(); for example, you are supposed to be able to put your cursor infront of it, or highlight it and hit F1 and it will take you directly to the help page for that function. This does not happen as well. As I go on and on I seem to keep stumbling across all these built in features for convenience that are not working. And I know 100% that they are supposed to be, I am actually in a class right now for flash and I watch demo videos where it works perfectly. What is going on with mine? I have checked every possible preference and option, I have everything and I mean EVERYTHING up to date with the most current versions. I'm stuck, and I am getting really pissed off to be blunt, I need to fix this ASAP because it is going to affect my studies which are currently ongoing, I have deadlines to  meet and I am dicking around trying to fix this. PLEASE PLEASE HELP ME! Any suggestions and solution will be greatly appreciated on my behalf. If anyone helps me fix this I'll kiss you!!!!!!!!

    I increased the cache from 800 to 5000, is that sufficient?
    The .fla is saved to my harddrive
    still no code hinting. I also unchecked and rechecked the code hinting, and even did a reboot on my comp and still nothing.
    everything is updated, EVERYTHING, to the most current version available. I updated everything possible through the "Adobe Help Manager" and also through the help menu within the programs themselves; Help->Updates. I made slight progress with the help issue, in general settings withing the "Adobe Help Manager" I changed it to display local help only. So now when I initiate help by either right clicking, and then going to "view help" in the pop-up menu, or by hitting "FN+F1" (hp laptop) it brings up the flash_reference.pdf but it does not go directly to the function selected as it's supposed to. So maybe that isn't even progress...
    I watched the demo video for the course I am in, and it shows our instructor put the cursor immediately infront of trace(); (within the actions window) and go to help and it goes directly to the help section on trace, and then he also highlights trace(); and goes to view help and it does the same thing.
    I am also in touch with him (its an online course) to see if he can figure out it, and I am still waiting to hear back from him, but no one seems to know. I even contacted ADOBE today and got passed on to 3 different people only to be given the toll free 800 number because no one knows how to fix it.

  • MSFT CA vs. ASA built-in CA

    I'm trying to setup VPN users to authenticate with digital certificates as part of 2 factor authenication. With a 5510 (upgrading to 5515) with access to Microsoft 2008r and 2012, Which would be a better fit the Microsoft service or the built-in CA service on the ASA? (needed for less than 25 VPN users but would like setup for growth.)
    Thanks,
    Jeremy

    You would get more benefit out of MS-CA. backups, scale, management, flexibility to use for other purposes if needed (wireless/dot1x for example) are some of the advantages. The Local CA works however and is considered more cost effective.
    FaDi

  • Is the spell checker a built in feature of firefox

    When Firefox is downloaded does the spell checker automatically come with it? Is it built in to the Firefox browser?

    A spell checker is part of Firefox; a small dictionary is included in US English versions only. You can add dictionaries:
    *See --> https://addons.mozilla.org/en-US/firefox/language-tools/ (access this page by clicking on "More" in the line just under "Add-ons" then choose "Dictionaries & Language Packs" on this page: https://addons.mozilla.org/en-US/firefox/ )
    *See --> http://support.mozilla.com/en-US/kb/Using+the+spell+checker
    '''If this reply solves your problem, please click "Solved It" next to this reply when <u>signed-in</u> to the forum.'''

  • USA Today reported that Firefox had a built in feature to opt out of web tracking. How do I access this feature or setting?

    The article was regarding a potential new law which would require web hosters to honor the wishes of a visitor with a "do not track" clause. It mentioned that Firefox made this option available to its users through its software. Please provide any details so I can access this feature or setting.
    Thanks

    I haven't had any problems accessing my bank, MasterCard, or any other sites that I do electronic funds transfers.
    I don't save user-names or passwords but remember that these two programs are mainly after tracking cookies not the site cookies from your bank etc.
    In tools|options|privacy you can set up FF to save site cookies and let the others be discarded. See the article at
    [[https://support.mozilla.com/en-US/kb/Cookies?s=managing+cookies&as=s]]
    for basic cookie management and preferences.

  • IMac Built In Feature To "Clean Up" computer

    Is there anything within the iMac features or functions that can be used to "clean" up the unit to retrieve wasted space? Maybe something like "degragging" on a Windows platform. I need to conserve space on this unit or get ready to buy another (which isn't a good financial choice right now).

    Smaller size files are automatically defragmented as a background process by Mac OS X. Large files and free space are not defragmented, but they usually do not become a problem unless you allow free space to get really low. Don't let the free space get below 10% and if it gets to around 15%, start looking for ways to free up space, either by deleting files or off-loading onto an external drive.
    Note: Even if there is some level defragmentation on the hard drive (there will be), that does not cause more space to be used up. The amount of free space is the same, whether it is in one big contiguous piece, or divided into a bunch of smaller chunks. So defragging will not "conserve space." The only way to "retrieve wasted space" is to delete files you no longer need.
    As long as you maintain a good percentage of free space on the internal drive, you should not worry about it.

  • I can't use the scroll feature built into my touchpad on my laptop, it works with everything else, including a pdf within firefox and the old 3.6 version of firefox but not in the new one. Does anyone know how to fix this?

    The touchpad has a built in feature where when i move my finger over the far right, it scrolls instead of using the mouse. It has been faultless with everything before now, but doesnt work on webpages in Firefox 4, but does in pdfs open within firefox. I can only assume therefore it is the browsers problem not mine. The touchpad is a synaptics pointing device. If this is a browser problem then looks like firefox 4 wont be for me :(

    Apparently it's related to the Firefox plug in.
    This isn't exactly a solution but more of a way to avoid opening PDFs with Firefox's plug in.
    1. Highlight "Tools" from the Menu Bar in the top left of the screen (or click "Options" if using the Firefox Compact Menu)
    2. Select to "Options
    3. Select "Applications"
    4. Look for "Adobe Acrobat Document" under Content Type and to the right under Action select "Use Adobe Reader (default)" instead of the using Adobe Acrobat in Firefox
    5. Open a test PDF. It should open in it's own window now.
    Again, not a complete solution but something that'll at least let you scroll with PDFs open.
    More info here: http://forums.mozillazine.org/viewtopic.php?f=38&t=2171033

  • NAC Framework URL-Redirect supported on ASA ?

    Hi
    Have anybody experience with URL-Redirects and URL-Redirect-ACLs when using NAC on ASA 7.x - are this supported Attributes - who has tested this successfully ?
    regards,
    Herbert
    regards,
    Herbert

    think URL-Redirect is supported. You may check by changing RAC to use IP instead of url. If it works then in ASA add a name command for the url IP and change the RAC to way it was before. Following link may help you
    http://www.cisco.com/en/US/docs/security/asa/asa71/configuration/guide/examples.html

  • Sun ONE Portal Server 6.1 - Reporting features

    Hi,
    I am just curious whether the Portal Server has any built-in feature for adhoc reporting (based on the user selection). If yes please suggest me on how to enable the same / use the same.
    Thank you,
    V

    Hi,
    The problem with integration of struts based
    applications is usually the project funding :-)
    There is no generic struts provider, only some
    custom build pieces...
    I guess that is the reason, why "zero effort" proxy
    of a struts application via IFrame channel is the
    most implemented integration.
    Cheers,
    Alex :-)

  • Resume Reading feature

    Hi there,
    I'm trying to get a better understanding of the data streaming features that comes with the -hot forum topic- Batch eWay in caps 513. Its User Guide has a page on the "Resume Reading" feature of the BatchLocalFile OTD. It allows to read part by part from a large file and does this by remembering the break position in the file, so it knows where to start for reading the next part.
    - How does this got persisted? I guess it's just in memory.
    - What about a system failure during the read? Is there a kind of rollback mechanism foreseen?
    - collaboration rules define the break (identified by i.e. #recs, delimiter character), not by configuration. How?
    Anyone has experience with this feature ?
    Some code snippets would be very usefull.
    Thanks 4 any help on this
    Kris

    Hoi Kris,
    it works together with the Record parsers (BatchRecord OTD).
    The state is written to a file on the side of the domain. As it is meant to work in scenario as LocalFile-BatchRecord-BatchFTP or LocalFile-BatchRecord-JMS, the built-in features of Pre and Post transfer renaming give a pretty good transactional control.
    The thing to make sure is having synchronization enabled so execution is serialized. Also, when adding more logic on top of the BatchRecord features, it is suggested to set "Resume Reading" to false, which just means that it's not going to work perfectly in this situation (if you for example do double splitting on the input datastream and send them off as JMS messages).
    Hope this clarifies things a bit.
    Paul

  • Difference between ISE and NAC?

    Dear All,
    Can you please help to understand difference ISE and NAC?
    Thank You,
    Abhisar.

    Well ISE is the next generation of NAC and has extended the features some of the comparison of features are mentioned in the given diagram

  • Feature Request | Allow custom metadata per table/column to be stored

    Someone please correct me if there's already a feature that allows this...
    I'd like to see a feature where you can define a set of metadata that can be stored per table / column, and perhaps a trigger that updates that metadata.
    As a use case, it is sometimes necessary to find out how many records exist in a table, and the typical way of doing this is by running a statement like select count(*) from example_table;. With a large table, this statement might take a long time though, and certainly has overhead associated with it. If this is something that's done on a regular basis, like maybe even once every minute, wouldn't it be much better to store this number as metadata for the table that can be updated on inserts and deletes and then can be queried? It might involve extra overhead on an insert or delete statement to add to or subtract from this number, but then for some applications the benefit of getting the count quickly might outweigh the extra overhead.
    Another use case is finding a minimum or maximum out of a table. Say you store a date and you need to find the max value for some feature in your application; with a large table, and especially if its a date with accuracy to the millisecond where an index wouldn't help much because most values are unique, it can take quite a bit of time and overhead to find that max value. If you could define for that column that you'd like to store the max value in metadata, and could query it, it would be very quick to get the info. The added overhead in this scenario would be on insert, update or especially on delete, the value would have to be updated. But in some applications, if you don't expect alot of deletes or updates on this column, it might be worth the added overhead to be able to quickly find the max value for this column.
    I know you could probably make a separate table to store such info, and write triggers to keep it up to date, but why not have a built in feature in Oracle that manages it all for you? When you create a table, you could define with the column definition something like 'METADATA MAX' and it will store the max value of that column in metadata for you, etc.
    I know that the overhead of this feature wouldn't be good for most circumstances, but there certainly are those cases where it would be hugely beneficial and the overhead wouldn't matter so much.
    Any thoughts?
    Can this be submitted as a feature request? Am I asking in the right place?
    (p.s. while you're at it, make a feature to mimic IDENTITY columns from SQL Server!)

    I don't think what you mentioned is exactly what I was talking about. There's no min_value or max_value in the dba_tab_columns table; there's only high_value and low_value, and they are stored in binary. And I believe to be accurate in the use cases that I suggested, you would have to analyze the table after every insert/update/delete. So no, that's not the same feature I've asked for, although I appreciate the feedback.
    Also, the num_rows in dba_tables relies on the table being analyzed too, so for a table that stores temporary date to be processed where you want to know the size of the queue every few seconds, it wouldn't make sense to analyze the whole table every few seconds when all you want is a count of the records, and it's also inefficient to use the COUNT function with every query when it would be much faster to store the count in some metadata form that is updated with every insert or delete (adding to a count and subtracting from a count with each insert/delete is WAY faster than analyzing the table and letting it literally recount the entire table every time).
    So again, while I appreciate the feedback, I don't think what you mentioned addresses either of the use cases I gave. I'm talking about a different kind of user defined metadata that could be stored per table/column with rules to govern how it is updated. Not you standard metadata that requires an analyze and isn't real time. I also only gave a few use cases, but the feature I'm really looking for is the ability for users to define many different types of custom metadata even maybe based on their own logic.
    Again, this feature could be implemented right now by creating a USERMETADATA table for every standard table you have, and then using triggers to populate the info you want at the table level and column level, but why do that when it could be built in?
    Also, I don't really agree that having to create a trigger/sequence for every table instead of setting a column as IDENTITY is better. It's cumbersome. Why not build these commonly used features in? It can create a trigger/sequence behind the scenes for all I care, but why not at least let someone mark a column as IDENTITY (or use whatever other term you want) at the time of table creation and let it do everything for them. But that's off-topic; I meant it for more of a side comment, but should really have a separate post about it.

  • Cisco ASA - BGP or OSPF support on Multicontext Firewall?

    Hello Forum,
    I would like to know why is the limitation of Cisco ASA in multicontext mode that it is not able to run routing protocols like OSPF, BGP?
    if I see SRX firewall, you can cut that virtually and can configure BGP, OSPF routing instances with virtual firewall.
    is there any possibility in ASA product to run OSPF, BGP in multicontext mode?
    comments are welcome...
    Thanks
    Dave

    To answer your question, Cisco wants its customers (or at least used to want its customers) to use the ASA as a firewall and not a router.  So you would have one device that is your firewall and one device that is your router.  I suppose they started to realize that customers are looking for an all in one device, so they started adding routing features to the ASA, and firewall features to the routers, yet the firewall still doesn't have all the routing capabilities of a router and the router doesn't have all the firewalling capabilities of the ASA.
    You can speculate that this is a marketing ploy so you are required to purchase more devices, or you could look at it in such a way that it is best practice to seperate all functionality in the instance that a device does get hacked.
    Please remember to select a correct answer and rate

  • Built in  FlashPaper

    Hi
    I want to know whether the Macromedia FlashPaper 2 is comes
    with as built in feature or plugin with any of Adobe software like
    Photoshop CS3 or CS4 or. i have to Purchase Separately.Please Let
    me soon

    Finally found the problem and it's probably more simple than i previously thought. Although resetting the SMC, cold start and etc is probybly not such a bad idea any on an older machine to clean away the dust! it doesn't actually solve the problem we're discussing.You need to check which programs could be using, blocking or have changed isight priorities. After checking all programs i've installed since i can last remember using my camera I found i'd overlooked Airparrot. I'm afraid that if you install Airparrot then you'll likely lose iSight functions. Airparrot blocks video functions. Great eh.You need to completely uninstall it, drivers and all. Simply using the Airparrot uninstall tool didn't do the job for me. Airparrot's uninstall tool has a delete drivers button but it didn't work. I needed to use Terminal to delete the drivers.
    If you havn't used the Terminal before then maybe you should read up first but you'll need to set a password to use the sudo actions. If you don't have one you can set a temporary one and set it back to blank again if you're not into using passwords for home use. Here are a couple of links that will explain everything:
    http://support.airsquirrels.com/article.php?id=8
    http://www.youtube.com/watch?v=r4D3eFf3y64
    Good luck. It worked for me!

  • Is there a feature that will display the current zoom level like Internet Explorer does?

    Zoom level appears in the lower right hand corner of MS IE

    Sorry, there's no built-in feature like what you mean in original Firefox that you download. But you can use this add-ons: [https://addons.mozilla.org/en-us/firefox/addon/default-fullzoom-level/ Default FullZoom Level] . I hope this add-ons can help you.

Maybe you are looking for