When an Endpoint Assessment Fails

I have an ASA 5515-x running 9.03, and have AnyConnect clients running version 3.1.04063.  I am licensed for Advanced Endpoint Assessment and CSD.  The issue I am having is when I client connects using TrendMicro AV, and the Trend service is stopped, the Endpoint Assessment recognized this and attempts to start (which is good!), but it fails to start with the following warning logged:   
[Tue Sep 03 10:53:38.957 2013][cscan][warn][scan_advanced_av] unable to enable antivirus (Trend Micro Client/Server Security Agent)
At the end of the scan, it also logs that the check for activescan failed:
[Tue Sep 03 10:53:43.668 2013][cscan][debug][get_data] endpoint.av["TrendMicroAV"].activescan="failed"
The VPN conenction is then established and the user works as if everything passed (which is not good!).
What I am looking for is: if restarting the service fails, like in this case, deny the connections and hopefully put up a friendly message that the access was denied because AV failed to start.
Any ideas?    

Hi Richard,
you should be able to do this using DAP (Dynamic Access Policies) on the ASA, i.e. create a DAP rule that denies the connection if endpoint.av["TrendMicroAV"].activescan has a value of false, and a default rule that allows all other connections.
see http://www.cisco.com/en/US/products/ps6120/products_white_paper09186a00809fcf38.shtml
hth
Herbert

Similar Messages

  • AnyConnect - Posture Assessment Failed: Unable to get the available CSD version....

    Hello all
    I am attempting to get the HostScan posture assessment working so we can check that any device connecting to the ASA is a valid corporate asset.
    I have installed the posture module onto our test client machine (Windows 8.1) using the following software:
    anyconnect-posture-win-4.0.00061-pre-deploy-k9
    Then in ASDM under Remote Access VPN > Host Scan Image I have uploaded the following package:
    disk0:/hostscan_3.1.06073-k9.pkg
    ...and ticked the box 'Enable Host Scan/CSD'.
    Under Remote Access VPN > Secure Desktop Manager I have configured an initial simple Prelogin policy to test it working, this simply just checks that the OS is Windows 8. A success should map this user to a Group Policy I have created that is mapped to a Connection Profile. 
    So, with all that said, when I try to connect I see that the AnyConnect client going through the motions: "Posture Assessment: Checking for updates....", after which I get a pop-up and error message:
    "Posture Assessment Failed: Unable to get the available CSD version from the secure gateway"
    A bit stumped here and haven't quite found much on the web as to how to resolve this.
    Has anyone encountered this before? If so, can you advise on what I can do
    By the way I am connecting using IKEv2 (IPsec) as these are the requirements and the AC version is 4.0.00061, ASA version: 9.2(1).
    Many thanks

    Hello
    Please forgive the shameless bump. Was hoping someone could help?
    Many thanks

  • Automatic Install of Endpoint Protection fails on windows 8.1 clients with SCCM 2012 R2

    Running SCCM 2012 R2 and deploying CM clients and Endpoint Protection via software updates. CM client and EP install fine on Windows 7 clients. CM client installs fine but endpoint protection fails on Windows 8.1 clients with the following from the
    endpoint protection agent log:
    <![LOG[Create Process Command line: "C:\Windows\ccmsetup\SCEPInstall.exe" /s /q /policy "C:\Windows\CCM\EPAMPolicy.xml".]LOG]!><time="12:22:02.560+240" date="08-13-2014" component="EndpointProtectionAgent"
    context="" type="1" thread="4260" file="epagentutil.cpp:607">
    <![LOG[Detail error message is : [EppSetupResult]
    HRESULT=0x80070643
    Description=Cannot complete the System Center Endpoint Protection installation. An error has prevented the System Center Endpoint Protection setup wizard from completing successfully. Please restart your computer and try again. Error code:0x80070643. Fatal
    error during installation.
    So on the win8.1 client I run the above command line manually in a command window and receive Access is denied. Then I run the same command in an elevated command window and EP installs fine. Does this have something to do with why the automatic
    EP client install fails with the 0x80070643 error code? If so, what is the fix?

    Hi,
    Try uninstalling any other security software.
    For more information, please review the link below:
    I‘m getting an error code from my Microsoft security software
    http://www.microsoft.com/security/portal/mmpc/help/errorcodes.aspx
    We
    are trying to better understand customer views on social support experience, so your participation in this
    interview project would be greatly appreciated if you have time.
    Thanks for helping make community forums a great place.

  • I installed CS3 from backup to a new iMac when my old iMac failed.  How do I activate CS3 suite?

    I installed CS3 from backup to a new iMac when my old iMac failed.  How do I activate CS3 suite?
    When I try starting Photoshop, for example, it tells me uninstall then reinstall the product OR contact product support.
    However, when I phone product support, it says there is no product support for CS3 and to go to the Forums.
    Thank you.

    >from backup
    Mac Migration and Time Machine DO NOT WORK with Cloud program activations due to hidden files
    You need to uninstall and do a fresh install with your serial number

  • Yosemite will not upload on my MacPro, says I have to verify or repair, but when I do - it fails on that too. Am now stuck with a computer that doesn't work ! Have I lost everything ?

    Yosemite will not upload on my MacPro, says I have to verify or repair, but when I do - it fails on that too. Am now stuck with a computer that doesn't work ! Have I lost everything ?

    Hello BassoonPlayer,
    Since you are using one of the the school's Macbooks, it is quite possible that the time and date are not properly set on the computer that you are using.  FaceTime will not work if you do not have the proper time zone set up for the location that you are in.  This past week, there were a two other Macbook users I've helped by simply telling them to set the Date/Time properly.  By the way, you described your problem very well, which makes it easier for us to help you.  Hope this solves your problem -- if not, post back and I can suggest other remedies.
    Wuz

  • Sending mail to GROUP ID when a process chain fails.

    Hi All,
    Can one suggest me, how to send a failure/success mail to a Group mial id when a process chain fails.
    I am awere about sending mails to individual mail id's when a any process fails or succed. I want to know the group ID creation part & how to tag the same SOCT.
    Thanks in advance.
    BR,
    Kiron.

    hi,
    The Distribution List/Group_id is created in SO23 transaction.
    hope it is helpful to u
    thanks

  • How to send alert when receiver JMS adapter fails? Please help!

    Hi experts,
       I have the following Asynchronous scenario:
       SAP R/3 -
    >IDOC----->XI>JMS--->BizTalk.
       I am sending IDOC from a given SAP R/3 system to XI. XI then sends the same to BizTalk via JMS adapter. In SXMB_MONI the message is successfully processed as it shows checked flag. But if I see the JMS communication channel status in runtime workbench then there it shows error saying JMS queue user id or password not found.
    How to send this JMS adapter error as alert?
    I also tried configuring alert rule in runtime workbench but still it does not trigger any error.
    I have also verified the alert category and everything is fine with that.
    What could be the problem? How can I send an alert when an Async adapter fails?
    Thanks & Regards,
    Gopal

    Hi! GOPAL,
    Once make sure whther all the below mentioned steps are configured correctly or not ok
    1: First make sure whether you are working on SAP XI or PI 7.1
               a) If XI you need to create Alerts (ALert Category) in CCMS ABAP stack in the
                        Tcode. ALRTCATDEF
               b) Open the alert category/classification definition environment (transaction ALRTCATDEF).
         ensure you are in change mode.
               c) In the group box with the alert classifications, right-click All classifications to open the   
                    context menu, and choose Create.
               d) Under Classification, enter a name for the classification.
               e) Under Description, enter a description of the classification.
               f)  Save your entries.
               g) Then go to RWB-->Go to ALERT Configuation and ADD the RULES to your alert category gor 
         which created there in the abap stack.
    Note Suppose if you want those ALERTS to come to your MAIL then again go to ABAP STACK and go to Tcode.  ALRTCATDEF and select your alert category press FIxed Recepients and there give your SAP XI ID's then  u can see those alerts in RWB-->ALERT INBOX
    Suppoe if you want those to mail then ask the basis team to link your company mail or personal mail ID to your SAP ID.
    2. Supppose if you are working on PI 7.1 Server.
         Only difference is creating Alert Category...Here you can create your ALERT Classification I mean   
         alert caltegory in the ESR (Enterprise Service Repository )
         Software Component >S CVersion>NameSpace-->Alert Category.
         You can configure how u configure there in abap stack such as long and short text every thing 
          except Fixed Receipients you need to give that recepients there only in ABAP STACK.
          what ever ALERT CATEGORY you are creating will reflect there in the ABAP STACK
         even you can Use these alerts Category in BPM --> CONTROL STEP -->Configure here in this step
    You can also reach alerts like this.
    NOTE  Most Important point is You can also view your mails or Alerts in the T Code:: SOST.
    Regards:
    Amar Srinivas ELi

  • What can be done when applications and game fail to open in sonyericsson k550i?

    what can be done when applications and games fail to open in sonyericsson k550i?

    http://www.sonyericsson.com/cws/support/mobilephones/downloads/k550i?cc=gb&lc=en If this only happens with games/apps installed on the memory card but not with the ones in the phone memory, back these up on the PC and format the card.Otherwise, run the update service and failing that, try a master reset, remembering to back up your phone on PC/PC companion first.

  • Having installed Aperture iPhoto won't open. When I try it fails with the message "You can't open the iPhoto.app because it may be damaged or incomplete. Any help please?

    Having installed Aperture, iPhoto won't open. When I try it fails with the message "You can't open the iPhoto.app because it may be damaged or incomplete. Any help please?

    OK, fixed it.  Found that iPhoto is now BACK in the App store.
    Found iPhoto app in Finder and dragged it to Trash.
    Downloaded iPhoto from App store and all now back working again.
    Didnt expect to find iPhoto in App store as last time I looked it wasn't available.
    Nige

  • I keep getting a message about update to Photoshop Elements 9.  When I try, it fails to install.  I have Windows 8.1.

    I keep getting a message about an update to Photoshop Elements 9.  When I try, it fails to install.  I have Windows 8.1.

    See if you can get it from here:
    Adobe - Photoshop Elements : For Windows

  • BCP to pass an Error Message to SSIS when the BCP call fails?

    Hi,
    Within SSIS I have an Execute SQL Task which calls BCP via a source variable given the dynamic nature of the BCP call.
    When the BCP call fails it returns a number of records which give instructions on how to use BCP. SSIS then thinks that BCP has executed successfully, the component shows green and then the package continues to run.
    But of course what I want the BCP call to do is return an error message which would then trigger the standard on error event handler within SSIS. How do I do this please?
    It maybe the “Execute Process Task” could be a better SSIS component to use for this call
    Using BCP Utility in SSIS. Does anyone have experience of doing this type of thing?
    Thanks in advance,
    Kieran.
    Kieran Patrick Wood http://www.innovativebusinessintelligence.com http://uk.linkedin.com/in/kieranpatrickwood http://kieranwood.wordpress.com/

    Why don't you use the "Fast Load" option = BULK LOAD? Or the BULK LOAD stored proc?
    The only other way I can think of this can be done is by directing errors to an error file which can be interrogated from the package and then a precedence constraint used to trigger an error if there was one.
    Arthur My Blog

  • Just bought and installed elements 12.  Got message updates available.  When i updated it failed.  Error code u44mip2003.

    Just bought and installed elements 12.  Got message updates available.  When i updated it failed.  Error code u44mip2003.

    Update 12.1 installation errors | Photoshop Elements, Premiere Elements

  • Endpoint Assessment with ASA and Eset Smart Security

    Hi,
    I am trying to get ASA Endpoint Assessment working on a ASA 5510 with Eset Smart Secuirty VER 4.
    It works great with Eset Smart-Security Version 3., but I am unable to get it working with Version 4.
    From a "debug dap trace" it appears the variables are populated with bad information :
    endpoint.as["SpyBot"].timestamp="1223424000";
    endpoint.av["WmiAV"]={};
    endpoint.av["WmiAV"].exists="true";
    endpoint.av["WmiAV"].description="Eset unknown product";
    endpoint.av["WmiAV"].version="4.0";
    endpoint.av["WmiAV"].activescan="ok";
    endpoint.av["WmiAV"].lastupdate="";
    endpoint.av["WmiAV"].timestamp="";
    Is there anything I can do ?
    Any help, really appreciated.
    Thanks
    Matt
    I am running 8.0(4) with csd_3.4.0373.pkg.
    Endpoint Assessment 2.5.14.3

    Hello Tarik,
    Thanks for the info.
    The clients are able to login. And in the ESET Smart Security configuration, the nac client application is added to the firewall rules which make nac active whatever the ports is used by the client.
    Thanks
    Patrick Y.

  • ASA5500 disable endpoint assessment for webvpn.

    Hi,
    I want to use the endpoint assessment / prelogin policies to apply only for anyconnect. Are there any ways to configure this?
    I do not want the Secure Desktop to popup during webvpn.
    Thomas

    Hi Nathan,
    Are you using Ikev2 to connect. If not then can you please remove the following command and then try again:
    no crypto ikev2 enable outside client-services port 443
    Thanks
    Jeet Kumar

  • Anyconnect endpoint assessment with anyconnect phones

    Hello,
    We are rolling out any connect endpoint assessment & would like to know what the impact is to existing any connect phones.
    We are looking to check on the OS version/domain membership/ & file checks. I'm not sure how this would impact VoIP endpoints as they are running firmware opposed to an OS.

    Hello
    Please forgive the shameless bump. Was hoping someone could help?
    Many thanks

Maybe you are looking for