Guest

Cisco NAC Appliance (Clean Access)

Release Notes for Cisco NAC Appliance (Cisco Clean Access), Version 4.1(3)

Table Of Contents

Release Notes for Cisco NAC Appliance (Cisco Clean Access), Version 4.1(3)

Contents

Cisco NAC Appliance Releases

Cisco NAC Appliance Service Contract/Licensing Support

System and Hardware Requirements

System Requirements

Hardware Supported

Cisco NAC Network Module

NAC-3300 Series Appliances

Release 4.1(3) and Cisco NAC Profiler

Important Installation Information for NAC-3310

Additional Hardware Support Information

Supported Switches for Cisco NAC Appliance

VPN and Wireless Components Supported for Single Sign-On (SSO)

Software Compatibility

Software Compatibility Matrixes

Release 4.1(3) Compatibility Matrix

Release 4.1(3) CAM/CAS Upgrade Compatibility Matrix

Release 4.1(3) Clean Access Agent Upgrade Compatibility Matrix

Determining the Software Version

Clean Access Manager (CAM) Version

Clean Access Server (CAS) Version

Cisco NAC Appliance Agents Versioning

Cisco Clean Access Updates Versioning

New and Changed Information

Enhancements in Release 4.1.3.2

Windows Clean Access Agent Language Template Support Enhancement (Version 4.1.3.2)

Enhancements in Release 4.1.3.1

Enhancements in Release 4.1(3)

General Enhancements

Cisco NAC Web Agent

Support for Clients with Multiple Active NICs

Clean Access Server HA Heartbeat Link Enhancement

Clean Access Manager HA Configuration and Heartbeat Link Enhancements

Guest User Login and Registration Enhancements

LDAP Authentication Enhancement

Clean Access Server and WSUS Interaction Enhancement

Agent Restricted User Access Enhancement

Device Filter List Display and Import/Export Enhancement

Agent Report Information Display and Export Enhancement

VPN SSO Login Enhancement

VPN SSO Enhancement to Support Existing Clientless SSL VPN Users Launching the AnyConnect Client from a WebVPN Portal

Syslog Configuration Enhancement

Debug Log Download Enhancement

cisco_api.jsp Enhancement

CSRF Protection

Proxy Support Enhancements

ARP Broadcast Packet Handling Improvement

Clean Access Server HA ARP Broadcast Enhancement

Deprecated "Retag Trusted-side Egress Traffic with VLAN (In-Band)" Feature

Previously-Deprecated Features Removed from CAM/CAS Web Console Pages

Clean Access Agent Auto Remediation

Delay Agent Logoff on CAM/CAS

64-bit Windows Operating System Agent Support

Supported AV/AS Product List Enhancements (Version 67)

Out-of-Band Enhancements

Access to Authentication VLAN Change Detection Enhancement

SNMP Inform Notification Enhancement

SNMP "MAC Move Notification" Switch Port Configuration Support

Cisco NAC Appliance Agent Enhancements

Windows Clean Access Agent Language Template Support Enhancement (Version 4.1.3.0)

Cisco NAC Appliance Agents

Windows Clean Access Agent Enhancements

Windows Clean Access Agent Version 4.1.3.2

Windows Clean Access Agent Version 4.1.3.1

Windows Clean Access Agent Version 4.1.3.0

Mac OS X Clean Access Agent Enhancements

Mac OS X Clean Access Agent Version 4.1.3.1

Mac OS X Clean Access Agent Version 4.1.3.0

Cisco NAC Web Agent Enhancements

Cisco NAC Web Agent Version 4.1.3.10

Cisco NAC Web Agent Version 4.1.3.9

Clean Access Supported AV/AS Product List

Clean Access AV Support Chart (Windows Vista/XP/2000)

Clean Access AV Support Chart (Windows ME/98)

Clean Access AS Support Chart (Windows Vista/XP/2000)

Supported AV/AS Product List Version Summary

Caveats

Open Caveats - Release 4.1(3)

Resolved Caveats - Windows Clean Access Agent 4.1.3.2

Resolved Caveats - Mac OS X Agent 4.1.3.1

Resolved Caveats - Release 4.1.3.1

Resolved Caveats - Cisco NAC Web Agent 4.1.3.10

Resolved Caveats - Windows Clean Access Agent 4.1.3.1

Resolved Caveats - Release 4.1(3)

Known Issues for Cisco NAC Appliance

Known Issues with HP ProLiant DL140 G3 Servers

Known Issue with NAC-3310 CD Installation

Known Issues with NAC-3300 Series Appliances and Serial HA (Failover) Connection

Known Issues with Cisco NAC Profiler Release 2.1.7

Known Issues with Switches

Known Issue with Cisco 2200/4400 Wireless LAN Controllers (Airespace WLCs)

Known Issues with Broadcom NIC 5702/5703/5704 Chipsets

Known Issues for Windows Vista and Agent Stub

Use "No UI" or "Reduced UI" Installation Option

"Interactive Services Dialog Detection" and Uninstall

Known Issues with MSI Agent Installer

Known Issue with Windows 2000 Clean Access Agent/Local DB Authentication

Known Issue with Windows 98/ME/2000 and Windows Script 5.6

New Installation of Release 4.1(3)

Upgrading to 4.1(3)

Notes on 4.1(3) Upgrade

Settings That May Change With Upgrade

General Preparation for Upgrade

Upgrading from 3.6(x)/4.0(x)/4.1(0)+/4.1(1)+/4.1(2)+—Standalone Machines

Create CAM DB Backup Snapshot

Download the Upgrade File

Web Console Upgrade—Standalone Machines

Console/SSH Upgrade—Standalone Machines

Upgrading from 3.6(x)/4.0(x)/4.1(0)+/4.1(1)+/4.1(2)+—HA Pairs

Access Web Consoles for High Availability

Console/SSH Instructions for Upgrading HA-CAM and HA-CAS Pairs

Troubleshooting

Vista/IE 7 Certificate Revocation List

Windows Vista Agent Stub Installer Error

Agent Stub Upgrade and Uninstall Error

Clean Access Agent AV/AS Rule Troubleshooting

Generating Windows Installer Log Files for Agent Stub

MSI Installer

EXE Installer

Debug Logging for Cisco NAC Appliance Agents

Cisco NAC Web Agent Logs

Generate Windows Agent Debug Log

Generate Mac OS X Agent Debug Log

Creating CAM DB Snapshot

Creating CAM/CAS Support Logs

Recovering Root Password for CAM/CAS (Release 4.1.x/4.0.x/3.6.x)

No Web Login Redirect / CAS Cannot Establish Secure Connection to CAM

Troubleshooting Switch Support Issues

Troubleshooting Network Card Driver Support Issues

Other Troubleshooting Information

Documentation Updates

Related Documentation


Release Notes for Cisco NAC Appliance (Cisco Clean Access), Version 4.1(3)


Revised: June 24, 2008, OL-14508-01

Contents

These release notes provide late-breaking and release information for Cisco® NAC Appliance, formerly known as Cisco Clean Access (CCA), release 4.1(3). This document describes new features, changes to existing features, limitations and restrictions ("caveats"), upgrade instructions, and related information. These release notes supplement the Cisco NAC Appliance documentation included with the distribution. Read these release notes carefully and refer to the upgrade instructions prior to installing the software.

Cisco NAC Appliance Releases

Cisco NAC Appliance Service Contract/Licensing Support

System and Hardware Requirements

Software Compatibility

New and Changed Information

Cisco NAC Appliance Agents

Clean Access Supported AV/AS Product List

Caveats

Known Issues for Cisco NAC Appliance

New Installation of Release 4.1(3)

Upgrading to 4.1(3)

Troubleshooting

Documentation Updates

Obtaining Documentation and Submitting a Service Request

Cisco NAC Appliance Releases

Cisco NAC Appliance Version
Availability

4.1.3.2 (Windows Agent Only)

April 7, 2008

4.1.3.1 (Mac OS X Agent Only)

February 21, 2008

4.1.3.1 ED

February 18, 2008

4.1.3.10 (Cisco NAC Web Agent Only)

January 24, 2008

4.1.3.1 (Windows Agent Only)

January 15, 2008

4.1(3) ED

December 20, 2007



Note Any ED release of software should be utilized first in a test network before being deployed in a production network.


Cisco NAC Appliance Service Contract/Licensing Support

For complete details on service contract support, new licenses, evaluation licenses, legacy licenses and RMA, refer to the Cisco NAC Appliance Service Contract / Licensing Support.

System and Hardware Requirements

This section describes the following:

System Requirements

Hardware Supported

Supported Switches for Cisco NAC Appliance

VPN and Wireless Components Supported for Single Sign-On (SSO)

System Requirements

See Supported Hardware and System Requirements for Cisco NAC Appliance (Cisco Clean Access) for system requirement information for the Clean Access Manager (CAM), Clean Access Server (CAS), and Cisco NAC Appliance Agents.

Hardware Supported

This section describes the following:

Cisco NAC Network Module

NAC-3300 Series Appliances

Important Installation Information for NAC-3310

Additional Hardware Support Information

Cisco NAC Network Module

Release 4.1(3) supports the Cisco NAC Appliance network module (NME-NAC-K9) on the next generation service module for the Cisco 2811, 2821, 2851, 3825, and 3845 Integrated Services Routers (ISRs). The Cisco NAC Network Module for Integrated Services Routers supports the same software features as the Clean Access Server on a NAC Appliance, with the exception of high availability. NME-NAC-K9 does not support failover from one module to another.

For hardware installation instructions (how to install the NAC network module in an Integrated Service Router), refer to the following sections of the Cisco Network Modules Hardware Installation Guide.

Installing Cisco Network Modules in Cisco Access Routers

Connecting Cisco Network Admission Control Network Modules

For software installation instructions (how to install the Clean Access Server software on the NAC network module) refer to Getting Started with Cisco NAC Network Modules in Cisco Access Routers.


Note If introducing the Cisco NAC network module to an existing Cisco NAC Appliance network, you must upgrade all CAM/CAS appliances to release 4.1(2) or later for compatibility.

While upgrading to release 4.1(3) and later is not required to support Cisco NAC network modules, if you are supporting 64-bit Windows Vista client systems, you must upgrade to release 4.1.2.1 or later.


NAC-3300 Series Appliances

Release 4.1(3) supports Cisco NAC Appliance 3300 Series platforms.

Customers have the option to upgrade NAC-3310, NAC-3350, or NAC-3390 MANAGER and SERVER appliances to release 4.1(3) using a single upgrade file, cca_upgrade-4.1.3.x.tar.gz.

CD installation of release 4.1(3) is also supported:

For NAC-3310 and NAC-3350, the cca-4.1_3-K9.iso file is required for new CD installation of the Clean Access Server or Clean Access Manager.


Note The NAC-3310 appliance requires special installation directives, as well as a firmware upgrade. Refer to Important Installation Information for NAC-3310 for details.


For NAC-3390, a separate ISO file, supercam-cca-4.1_3-K9.iso, is required for CD installation of the Clean Access Super Manager.


Note Super CAM software is supported only on the NAC-3390 platform.


Release 4.1(3) and Cisco NAC Profiler

Release 4.1(3) includes the Cisco NAC Profiler Collector component that resides on Clean Access Server installations.

Refer to the Release Notes for Cisco NAC Profiler for updated product information.

See also Known Issues with Cisco NAC Profiler Release 2.1.7.

Important Installation Information for NAC-3310

NAC-3310 Required BIOS/Firmware Upgrade

NAC-3310 Required DL140 or serial_DL140 CD Installation Directive

NAC-3310 Required BIOS/Firmware Upgrade

The NAC-3310 appliance is based on the HP ProLiant DL140 G3 server and is subject to any BIOS/firmware upgrades required for the DL140 G3. Refer to Supported Hardware and System Requirements for Cisco NAC Appliance (Cisco Clean Access) for detailed instructions.

NAC-3310 Required DL140 or serial_DL140 CD Installation Directive

The NAC-3310 appliance (MANAGER and SERVER) requires you to enter the DL140 or serial_DL140 installation directive at the "boot:" prompt when you install new system software from a CD-ROM. For more information, refer ro Known Issue with NAC-3310 CD Installation.

Additional Hardware Support Information

See Supported Hardware and System Requirements for Cisco NAC Appliance (Cisco Clean Access) for details on:

Cisco NAC Appliance 3300 Series hardware platforms

Supported server hardware configurations

Pre-installation instructions for applicable server configurations

Troubleshooting information for network card driver support

See Troubleshooting for further details.

Supported Switches for Cisco NAC Appliance

See Switch Support for Cisco NAC Appliance for complete details on:

Switches and NME service modules that support Out-of-Band (OOB) deployment

Switches/NMEs that support VGW VLAN mapping

Known issues with switches/WLCs

Troubleshooting information

VPN and Wireless Components Supported for Single Sign-On (SSO)

Table 1 lists VPN and wireless components supported for Single Sign-On (SSO) with Cisco NAC Appliance. Elements in the same row are compatible with each other.

Table 1 VPN and Wireless Components Supported By Cisco NAC Appliance For SSO

Cisco NAC Appliance Version
VPN Concentrator/Wireless Controller
VPN Clients

4.1(3)

Cisco WiSM Wireless Service Module for the Cisco Catalyst 6500 Series Switches

N/A

Cisco 2200/4400 Wireless LAN Controllers (Airespace WLCs)1

N/A

Cisco ASA 5500 Series Adaptive Security Appliances, Version 8.0(3)7 or later2

AnyConnect

Cisco ASA 5500 Series Adaptive Security Appliances, Version 7.2(0)81 or later

Cisco SSL VPN Client (Full Tunnel)

Cisco VPN Client (IPSec)

Cisco WebVPN Service Modules for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers

Cisco VPN 3000 Series Concentrators, Release 4.7

Cisco PIX Firewall

1 For additional details, see also Known Issue with Cisco 2200/4400 Wireless LAN Controllers (Airespace WLCs).

2 Release 4.1(3) supports existing AnyConnect clients accessing the network via Cisco ASA 5500 Series devices running release 8.0(3)7 or later. For more information, see VPN SSO Enhancement to Support Existing Clientless SSL VPN Users Launching the AnyConnect Client from a WebVPN Portal and CSCsi75507.



Note Only the SSL Tunnel Client mode of the Cisco WebVPN Services Module is currently supported.


For further details, see the Cisco NAC Appliance - Clean Access Manager Installation and Configuration Guide, Release 4.1(3) and the Cisco NAC Appliance - Clean Access Server Installation and Configuration Guide, Release 4.1(3).

Software Compatibility

This section describes software compatibility for releases of Cisco NAC Appliance:

Software Compatibility Matrixes

Determining the Software Version

For details on Clean Access Agent and Cisco NAC Web Agent client software versions and AV integration support, see:

Cisco NAC Appliance Agents

Clean Access Supported AV/AS Product List

Software Compatibility Matrixes

This section describes the following:

Release 4.1(3) Compatibility Matrix

Release 4.1(3) CAM/CAS Upgrade Compatibility Matrix

Release 4.1(3) Clean Access Agent Upgrade Compatibility Matrix

Release 4.1(3) Compatibility Matrix

Table 2 shows Clean Access Manager and Clean Access Server compatibility and the Clean Access Agent version supported with each CCA 4.1(3) release (if applicable). CAM/CAS/Clean Access Agent versions displayed in the same row are compatible with one another. Cisco recommends that you synchronize your software images to match those shown as compatible in the table.

Table 2 Release 4.1(3) Compatibility Matrix  

Clean Access Manager
Clean Access Server
Cisco NAC Appliance Agents 1
Windows 2
Mac OS X 3
Web Agent 4

4.1.3.1 5
4.1(3)

4.1.3.1 5
4.1(3)

4.1.3.2
4.1.3.1
4.1.3.0

4.1.3.1
4.1.3.0

4.1.3.10
4.1.3.9

4.1.2.x
4.1.1.0
4.1.0.x 6

4.1.2.x
4.1.1.0
4.1.0.x 6

-

-

1 See Cisco NAC Appliance Agents for details on version updates for each Windows/Mac OS X/Web Agent.

2 Version 4.1.3.0 and later of the Windows Clean Access Agent is compatible with the 4.1(3) CAM and 4.1(3) and later CAS releases. See Cisco NAC Appliance Agents for details and caveats resolved for each Agent version.

3 Mac OS X Clean Access Agent supports authentication only (no posture assessment) and auto-upgrade starting from version 4.1.3.0. See Mac OS X Clean Access Agent Version 4.1.3.0 for details.

4 Cisco NAC Web Agent 4.1.3.9 is a new user access option introduced in release 4.1(3). See Cisco NAC Web Agent Enhancements for more information.

5 Cisco NAC Appliance Release 4.1.3.1 is a general and important bug fix release that resolves issues as described in Enhancements in Release 4.1.3.1.

6 Cisco strongly recommends running version 4.1.3.0 of the Clean Access Agent with release 4.1(3) of the CAM/CAS. If necessary, release 4.1(3) allows administrators to optionally configure the 4.1(3) CAM/CAS to allow 4.1.0.x Agent authentication and posture assessment (Windows only). Note that by default, 4.1.0.x Agents are not allowed to log into a 4.1(3) Cisco NAC Appliance system. However, an Agent upgraded to 4.1.3.0 and later can still log into a 4.1(0) CAM/CAS. See 4.1.0.x Agent Support on Release 4.1(1) in the 4.1(1) release notes for details.


Release 4.1(3) CAM/CAS Upgrade Compatibility Matrix

Table 3 shows 4.1(3) CAM/CAS upgrade compatibility. You can upgrade/migrate your CAM/CAS from the previous release(s) specified to the latest release shown in the same row. When you upgrade your system software, Cisco recommends you upgrade to the most current release available whenever possible.

Table 3 Release 4.1(3) CAM/CAS Upgrade Compatibility Matrix

Clean Access Manager
Clean Access Server

Upgrade From:

To:
Upgrade From:
To:

4.1(2)+
4.1(1)
4.1(0)+ 1
4.0(x)
3.6(x)
3.5(7)+ 2

4.1.3.1 3
4.1(3)

4.1(2)+
4.1(1)
4.1(0)+ 1
4.0(x)
3.6(x)
3.5(7)+ 2

4.1.3.1 3
4.1(3)

1 Release 4.1(0), 4.1.0.1, and 4.1.0.2 do not support and cannot be installed on Cisco NAC Appliance 3300 Series platforms.

2 "In-place" upgrade from version 3.5(11) to 4.1(3) is not supported. Customers wishing to upgrade a system from 3.5(11) to 4.1(3) must use the supported in-place upgrade procedure to upgrade from 3.5(11) to 4.0(6), and then upgrade to 4.1(3). (See CSCsl76977.)

3 Cisco NAC Appliance Release 4.1.3.1 is a general and important bug fix release that resolves issues as described in Enhancements in Release 4.1.3.1.


.

Release 4.1(3) Clean Access Agent Upgrade Compatibility Matrix

Table 4 shows Clean Access Agent upgrade compatibility when upgrading existing versions of the Agent after 4.1(3) CAM/CAS upgrade. You can auto-upgrade any 3.5.1+ Windows Agent directly to the latest 4.1.3.x Windows Agent. You can auto-upgrade Mac OS X Agents starting from version 4.1.3.0 and later.


Note The temporal Cisco NAC Web Agent is updated on the CAM under Device Management > Clean Access > Updates > Update only; auto-upgrade does not apply.


Refer to the "Cisco NAC Appliance Agents Systems Requirements" section of the Supported Hardware and System Requirements for Cisco NAC Appliance for additional compatibility details.

Table 4 Release 4.1.3.x Agent Upgrade Compatibility Matrix

Clean Access Manager
Clean Access Server
Clean Access Agent 1 , 2 , 3
Upgrade From:
To Latest Compatible Windows Version:
To Latest Compatible Mac OS X Version:

4.1.3.1
4.1(3)

4.1.3.1
4.1(3)

4.1.2.x
4.1.1.0
4.1.0.x 4

4.1.3.2
4.1.3.1 5
4.1.3.0

4.1.3.1 6
4.1.3.0

4.0.x.x
3.6.x.x
3.5.1 and later

4.1.3.1 5
4.1.3.0

1 Clean Access Agent versions are not supported across major releases. Do not use 4.1.3.x Agents with 4.0(x) or prior releases. However, auto-upgrade is supported from any 3.5.1 and later Agent directly to the latest 4.1.3.x Agent.

2 See Cisco NAC Appliance Agents for details on version updates for each Windows/Mac OS X/Web Agent.

3 For checks/rules/requirements, version 4.1.1.0 and later Clean Access Agents can detect "N" (European) versions of the Windows Vista operating system, but the CAM/CAS treat "N" versions of Vista as their US counterpart.

4 Cisco strongly recommends running the latest 4.1.3.x version of the Clean Access Agent with release 4.1(3) of the CAM/CAS. If necessary, release 4.1(3) allows administrators to optionally configure the 4.1(3) CAM/CAS to allow 4.1.0.x Agent authentication and posture assessment. Note that by default, 4.1.0.x Agents are not allowed to log into a 4.1(3) Cisco NAC Appliance system. However, an Agent upgraded to 4.1.3.0 and later can still log into a 4.1(0) CAM/CAS. See 4.1.0.x Agent Support on Release 4.1(1) in the 4.1(1) release notes for details.

5 Windows Clean Access Agent version 4.1.3.1 resolves caveat CSCsm05207. See Windows Clean Access Agent Version 4.1.3.1 and Resolved Caveats - Windows Clean Access Agent 4.1.3.1 for details.

6 Auto-upgrade of the Mac OS X Agent is supported starting from version 4.1.3.0 and later. Release 4.1(1) and release 4.1(2)+ do not support auto-upgrade for the Mac OS X Agent. Users can upgrade client machines to the latest Mac OS X Agent by downloading the Agent via web login and running the Agent installation. For more information, see Mac OS X Clean Access Agent Enhancements.


Determining the Software Version

There are several ways to determine the version of software running on your Clean Access Manager (CAM), Clean Access Server (CAS), or Clean Access Agent, as described below.

Clean Access Manager (CAM) Version

Clean Access Server (CAS) Version

Cisco NAC Appliance Agents Versioning

Cisco Clean Access Updates Versioning

Clean Access Manager (CAM) Version

The top of the CAM web console displays the software version installed. After you add the CAM license, the top of the CAM web console displays the license type (Lite, Standard, Super). Additionally, the Administration > CCA Manager > Licensing page displays the types of licenses present after they are added.

The software version is also displayed as follows:

From the CAM web console, go to Administration > CCA Manager > System Upgrade | Current Version

SSH to the machine and type: cat /perfigo/build

CAM Lite, Standard, Super

The NAC Appliance Clean Access Manager (CAM) is licensed based on the number of NAC Appliance Clean Access Servers (CASes) it supports. You can view license details under Administration > CCA Manager > Licensing. The top of CAM web console identifies the type of CAM license installed:

Cisco Clean Access Lite Manager supports 3 Clean Access Servers (or 3 HA-CAS pairs)

Cisco Clean Access Standard Manager supports 20 Clean Access Servers (or 20 HA-CAS pairs)

Cisco Clean Access Super Manager supports 40 Clean Access Servers (or 40 HA-CAS pairs)

Note the following:

The Super CAM software runs only on the Cisco NAC-3390 MANAGER.

Initial configuration is the same for the Standard CAM and Super CAM.

Software upgrades of the Super CAM use the same upgrade file and procedure as the Standard CAM. You can use web upgrade or console/SSH instructions to upgrade a Super CAM to the latest release. However, a new CD installation of the Super CAM requires a separate .ISO file.

Clean Access Server (CAS) Version

You can determine the CCA software version running on the Clean Access Server (whether NAC-3300 appliances or Cisco NAC network modules) using the following methods:

From the CAM web console, go to Device Management > CCA Servers > List of Servers > Manage [CAS_IP] > Misc > Update | Current Version

From CAS direct access console, go to Administration > Software Update | Current Version (CAS direct console is accessed via https://<CAS_eth0_IP_address>/admin)

SSH or console to the machine (or network module) and type cat /perfigo/build


Note If configuring High Availability CAM or CAS pairs, see also Access Web Consoles for High Availability for additional information.


Cisco NAC Appliance Agents Versioning

On the CAM web console, you can determine versioning for the Cisco NAC Appliance Agents from the following pages:

Monitoring > Summary (Windows Setup/Patch, Mac OS X Agent, Web Agent)

Device Management > Clean Access > Clean Access Agent > Distribution (persistent Agents only)

Device Management > Clean Access > Updates > Summary (all Cisco Updates versioning and Agent Patch Version; see also Cisco Clean Access Updates Versioning)

Device Management > Clean Access > Clean Access Agent > Reports | View (individual report shows username, operating system, Clean Access Agent version and type, System/User domain information, client AV/AS version)

From the Clean Access Agent itself on the client machine, you can view the following information from the Agent taskbar menu icon:

Right-click About to view the Agent version.

Right-click Properties to view AV/AS version information for any AV/AS software installed, and the Discovery Host (used for L3 deployments)

Cisco Clean Access Updates Versioning

To view the latest version of Updates downloaded to your CAM, including Cisco Checks & Rules, Cisco NAC Web Agent, Clean Access Agent Upgrade Patch, Supported AV/AS Product List, go to Device Management > Clean Access > Update > Summary on the CAM web console. See Clean Access Supported AV/AS Product List and Clean Access Supported AV/AS Product List for additional details.

New and Changed Information

This section describes enhancements added to the following releases of Cisco NAC Appliance for the Clean Access Manager and Clean Access Server.

Enhancements in Release 4.1.3.2

Enhancements in Release 4.1.3.1

Enhancements in Release 4.1(3)

See Cisco NAC Appliance Agents for new features and enhancements to Cisco NAC Appliance Agents.

For additional details, see also:

Hardware Supported

Clean Access Supported AV/AS Product List

Caveats

Known Issues for Cisco NAC Appliance

Enhancements in Release 4.1.3.2

Windows Clean Access Agent Language Template Support Enhancement (Version 4.1.3.2)

Added Agent language template support for Russian, Turkish, and Serbian (Cyrillic) for Windows Agents. The Agent will display localized text for these languages if run from localized Windows operating system.


Note The Agent picks the correct language template based on the local computer Locale (under Control Panel > Regional and Language Options). Cisco recommends using the localized Agent in the localized version of Windows (e.g. French Agent in French Windows). Agent language template support only controls what the viewer sees after the Agent is installed; it does not include support for different client operating systems for the Agent Installer or for AV/AS products.



Note If the administrator includes non-English text in the CAM configuration (e.g. non-English characters in a requirement description or registry value check), it may not be displayed correctly or run correctly.


See Cisco NAC Appliance Agents for enhancement details per Agent version.

Enhancements in Release 4.1.3.1

Release 4.1.3.1 is a general and important bug fix release for the Clean Access Manager and Clean Access Server that addresses the caveats described in Resolved Caveats - Release 4.1.3.1. No new features are added.

For upgrade instructions, please refer to Upgrading to 4.1(3).

Enhancements in Release 4.1(3)

This section details the enhancements delivered with Cisco NAC Appliance release 4.1(3) for the Clean Access Manager and Clean Access Server.

General Enhancements

Cisco NAC Web Agent

Support for Clients with Multiple Active NICs

Clean Access Server HA Heartbeat Link Enhancement

Clean Access Manager HA Configuration and Heartbeat Link Enhancements

Guest User Login and Registration Enhancements

LDAP Authentication Enhancement

Clean Access Server and WSUS Interaction Enhancement

Agent Restricted User Access Enhancement

Device Filter List Display and Import/Export Enhancement

Agent Report Information Display and Export Enhancement

VPN SSO Login Enhancement

VPN SSO Enhancement to Support Existing Clientless SSL VPN Users Launching the AnyConnect Client from a WebVPN Portal

Syslog Configuration Enhancement

Debug Log Download Enhancement

cisco_api.jsp Enhancement

CSRF Protection

Proxy Support Enhancements

ARP Broadcast Packet Handling Improvement

Clean Access Server HA ARP Broadcast Enhancement

Deprecated "Retag Trusted-side Egress Traffic with VLAN (In-Band)" Feature

Previously-Deprecated Features Removed from CAM/CAS Web Console Pages

Clean Access Agent Auto Remediation

Delay Agent Logoff on CAM/CAS

64-bit Windows Operating System Agent Support

Supported AV/AS Product List Enhancements (Version 67)

Out-of-Band Enhancements

Access to Authentication VLAN Change Detection Enhancement

SNMP Inform Notification Enhancement

SNMP "MAC Move Notification" Switch Port Configuration Support

Cisco NAC Appliance Agent Enhancements

Windows Clean Access Agent Language Template Support Enhancement (Version 4.1.3.0)

General Enhancements

Cisco NAC Web Agent


Warning Cisco does not recommend using the Cisco NAC Web Agent on client machines connecting with link speeds slower than 56Kbits/s.


Cisco NAC Appliance release 4.1(3) introduces a new temporal Agent for Windows client machines. Unlike the Clean Access Agent, the Cisco NAC Web Agent is not a "persistent" entity, thus it only exists on the client machine long enough to accommodate a single user session. Instead of downloading and installing an Agent application, once the user opens a browser window, logs in to the Cisco NAC Appliance web login page, and chooses to launch the Cisco NAC Web Agent, an ActiveX control or Java applet (you specify the preferred method using the Web Client (Active X/Applet) option in the Administration > User Pages > Login Page configuration page) initiates a self-extracting stub installer on the client machine to install Agent files in a client's temporary directory, perform posture assessment/scan the system to ensure security compliance, and report compliance status back to the Cisco NAC Appliance system. During this period, the user is granted access only to the Temporary Role and if the client machine is not compliant for one or more reasons, the user is informed of the issues preventing network access and may do one of the following:

Users must manually remediate/update their client machine and try to test compliance again before the Temporary Role times out

Accept "restricted" network access for the time being and try to ensure the client machine meets requirements for the next login session


Note The Cisco NAC Web Agent does not perform client remediation. Users must adhere to Cisco NAC Appliance requirement guidelines independent of the Web Agent session to ensure compliance before they can gain access to the internal network. If users are able to correct/update their client machine to be compliant before the Temporary Role time-out expires, they can choose to "Re-scan" the client machine and successfully log in to the network.


Once the user has provided appropriate login credentials and the Web Agent ensures the client machine meets the NAC Appliance security requirements, the browser session remains open and the user is logged in to the network until the user clicks the Logout button in the Web Agent browser window, shuts off their system, or the NAC Appliance administrator terminates the session from the CAM. After the session terminates, the Web Agent "removes" itself from the client machine and the temporary files used to install are deleted from the system.


Note Security restrictions for the "Guest" user profile in Windows Vista operating systems prevent ActiveX controls and Java applets from running properly. Therefore, you must log into the Windows Vista client machine as a known user (not a "Guest") in order to log into Cisco NAC Appliance via the Web Agent.


The Cisco NAC Web Agent enhancement affects the following page of the CAM web console:

Device Management > Clean Access > General Setup > Agent Login—new Require use of Cisco NAC Web Agent option to enable the Cisco NAC Web Agent for user login


Note For system requirements and details on version updates, refer to Cisco NAC Web Agent Enhancements.


Support for Clients with Multiple Active NICs

Cisco NAC Appliance release 4.1(3) includes an enhancement to help stabilize connection problems from client machines with more than one active Network Interface Card (NIC). For example, a client machine may have an active LAN Ethernet connection and an active wireless NIC connection where each interface sends SWISS UDP discovery packets to initiate a connection to a network CAS. To address this potential situation, the CAS now examines the SWISS packets from the client machine to record the requesting NIC IP address and verifies all subsequent SWISS UDP packets for the NIC IP address to ensure the same client only logs in from one interface.

Without this enhancement, the following scenario can occur:

The client machine A sends out SWISS UDP discovery packets to the CAS and receives a response directing the user to enter their authentication credentials. During this process, another active NIC on client machine A sends SWISS UDP discovery plackets to the same CAS even though the first interface is already establishing a connection. After the first client session is established, the user sees a login screen again, despite having already successfully established connection. Until the secondary NIC is disabled or the client machine does something to halt SWISS UDP packet transmission, the user can continually see login screen after login screen.

For information regarding clients with multiple active NICs and how to configure them to interoperate with the Access to Authentication VLAN change detection feature, see Access to Authentication VLAN Change Detection Interoperability with Clients Featuring More Than One Active NIC.

For more information, see the "Supporting Multiple Active NICs on the Clean Access Agent Client Machine" section in the Cisco NAC Appliance - Clean Access Server Installation and Configuration Guide, Release 4.1(3).

Clean Access Server HA Heartbeat Link Enhancement

Clean Access Server HA heartbeat link capabilities have been enhanced in release 4.1(3). In addition to the existing serial interface and optional trusted (eth0 and eth2/eth3) interface heartbeat connections, you can now also configure the CAS to employ the (untrusted side) eth1 interface to provide redundant HA heartbeat monitoring.

This enhancement affects the following page of the CAS web console:

Administration > Failover > General | HA-Primary Mode and HA-Secondary Mode CAS mode configuration pages now allow for up to three optional Heartbeat UDP Interfaces: one dedicated on the (trusted side) eth0; one dedicated on the (untrusted side) eth1 interface; and a third on either of the eth2 or eth3 interfaces, if installed and enabled.

Clean Access Manager HA Configuration and Heartbeat Link Enhancements

In release 4.1(3), the Clean Access Manager web console interface now features a new (separate) Failover tab as well as additional failover configuration settings to support up to three optional redundant Heartbeat UDP Interfaces. In addition to the existing optional serial interface and dedicated eth1 interface heartbeat connections, you can now also configure the CAM to employ the (trusted side) eth0 interface and an additional optional Ethernet link to provide redundant HA heartbeat monitoring.

This enhancement affects the following pages of the CAM web console:

Administration > CCA Manager > Network (formerly Network & Failover) no longer features any CAM HA/failover configuration settings

Administration > CCA Manager | new Failover tab featuring HA-Primary Mode and HA-Secondary Mode CAM mode configuration pages that allow for up to three optional Heartbeat UDP Interfaces: one dedicated/preconfigured heartbeat link on eth1; one dedicated link on eth0; and a third on either of the eth2 or eth3 interfaces, if installed and enabled.

Guest User Login and Registration Enhancements

Release 4.1(3) enhances the way the CAM handles Guest user login, registration, and access with a new Guest Registration feature. Rather than allow users to simply gain undifferentiated Guest access to the system, the administrator can now configure guest users to register their own local accounts on the CAM using a variety of fields, including email, phone number, or affiliation. The new feature provides a customizable level of guest authentication using a new Guest Auth Server Type, new Guest Registration configuration pages, and the default guest role.

The CAM can automatically time out guest accounts using token expiration, or flush out unused guest accounts from the local database after a configurable number of days. Administrators can view newly created guest accounts on a new Guest Users local users list, and on the Certified Device List and Online Users List by configured Guest Auth Provider and Guest role.


Note Guest Registration on the CAM in 4.1(3) is independent of the Cisco NAC Guest Server solution. For details on Cisco NAC Guest Server, refer to the Release Notes for Cisco NAC Guest Server, Release 1.0.0.


To update any existing Guest user access model on the CAM to take advantage of the enhancements in release 4.1(3), administrators can perform the following tasks:

1. Disable/remove previous Guest user account(s)—You can accomplish this by either removing all existing guest users from the CAM's user database or (if all existing guest registration information is accessible from the same authentication source, removing the authentication server from the CAM

2. Create a new Guest user role—You can create a new Guest user role just as you would any other login account with which users can access the NAC Appliance system

3. Configure the Guest authentication server—You can configure a Guest authentication server just as you would any other standard authorization server, with the addition of two "housekeeping" features designed for Guest user authentication: an account lifetime setting and an option that enables you to automatically remove invalid guest accounts once a specified period of inactivity has passed

4. Configure Guest login page(s)—This function allows you to require Guest registration and add existing Guest provider options to the login page

5. Customize the Guest page—You can also specify the content and type of information Guest users must provide during the registration process

This enhancement affects the following pages of the CAM web console:

User Management > Auth Servers > New | new "Guest" Authentication Type and respective settings

User Management > Local Users: now features a new Guest Users tab (formerly a subtab of existing Local Users) with which you can view Guest user information more exclusively

Administration > User Pages | new Guest Registration Page tab with Content and Guest Info subtabs

LDAP Authentication Enhancement

Release 4.1(3) enhances the authentication settings available when authenticating user credentials against an LDAP server. Administrators can now specify either the "Simple" or Generic Security Services Application Programming Interface (GSSAPI) authentication mechanism to better provide secure credential authentication in the network.

This enhancement affects the following pages of the CAM web console:

User Management > Auth Servers > New/Edit | Authentication Type | LDAP and User Management > Auth Servers > Lookup Servers > New both feature the following new user interface settings/options:

New GSSAPI Authentication Mechanism option with associated KDC Timeout (in seconds), KDC/Realm Mapping, Domain/Realm Mapping settings. and Description

New Default Realm LDAP configuration setting

Clean Access Server and WSUS Interaction Enhancement

Release 4.1(3) improves message text for Windows Server Update Services (WSUS) requirements. When the Clean Access Agent encounters a WSUS requirement compliance issue, the Agent launches a secondary client remediation frame from which the user can download the required Windows Update during client posture assessment.


Note For non-admin users of client machines, use of the Stub Agent is mandatory for WSUS requirements.


Agent Restricted User Access Enhancement

Cisco NAC Appliance Agent login behavior has been enhanced in release 4.1(3) to allow users "restricted" network access if/when their client machine does not pass posture assessment as configured in the requirements associated with the user's login role. If this function is enabled by the administrator, a new button labeled "Limited" now appears in the Clean Access Agent login dialog and "Get Restricted Network Access" (or another configurable text string) in the Cisco NAC Web Agent dialog to give the user the option to gain access to a restricted set of network resources via the NAC Appliance system. The administrator has control over which resources are available to users with restricted network access, according to the configuration settings specified in an existing user role. For example, the administrator can create a new user role called "Restricted" in User Management > User Roles that allows users who choose to accept restricted network access to launch their Email program and gain access to the WWW, but nothing else.

This enhancement affects the following web console page:

Device Management > Clean Access > General Setup > Agent Login | Allow restricted network access in case user cannot use Clean Access Agent or Cisco NAC Web Agent

Device Filter List Display and Import/Export Enhancement

Starting from release 4.1(3), Cisco NAC Appliance administrators can export device filter lists to CSV files that can be searched, viewed, and manipulated in Microsoft Excel spreadsheets whenever the administrator needs them to troubleshoot connection issues or compile statistical reports, and the administrator can import device filter list information to populate (or repopulate) the CAMs device filter database from existing CSV files. In addition, the layout and function of the device filter list display (Device Management > Filters > Devices > List) has been updated in release 4.1(3) to give the administrator more direct control over the specific device entries displayed.

This enhancement affects the following page of the CAM web console:

Device Management > Filters > Devices > List—display page options have been reorganized and the page features two new Import and Export buttons

Agent Report Information Display and Export Enhancement

Starting from release 4.1(3), Cisco NAC Appliance administrators can export Agent report information to CSV files that can be searched, viewed, and manipulated in Microsoft Excel spreadsheets whenever the administrator needs them to troubleshoot connection issues or compile statistical reports. In addition, the layout and function of the Agent report display list (Device Management > Clean Access > Clean Access Agent > Reports) has been updated in release 4.1(3) to give the administrator more direct control over the specific Agent report entries displayed.

This enhancement affects the following page of the CAM web console:

Device Management > Clean Access > Clean Access Agent > Reports—display page options have been reorganized and the page features two new Export and Export (with text) buttons


Note The Export option creates an Excel file containing the columns displayed in the report viewer (Status, User, Agent, IP, MAC, OS, etc.).

The Export (with text) option provides an extra column containing the raw HTML code of the full Agent report that you can open for each report by clicking on view in the viewer.


VPN SSO Login Enhancement

Release 4.1(3) features a VPN SSO enhancement to ensure that users logging in via VPN are not erroneously presented with the Agent login dialog when signing in. When the user initiates a login session, the CAS passes information alerting the Agent that the user is already part of the VPN login list, thus enabling the CAM to avoid presenting the Agent login screen on the client machine. In network topologies that employ VPN concentrators, this potential situation can be made even more complex if the VPN concentrator delays sending the appropriate VPN login list notification to the CAS. To address this problem, the CAS is now able to specify a delay in the SWISS packet that tells the Agent to wait a short time before presenting the login screen.

VPN SSO Enhancement to Support Existing Clientless SSL VPN Users Launching the AnyConnect Client from a WebVPN Portal

Release 4.1(3) adds accounting update functionality to support existing AnyConnect clients accessing the network via Cisco ASA 5500 Series Adaptive Security Appliances platforms. To support VPN SSO, you must be running Cisco NAC Appliance release 4.1(3) or later and the Cisco ASA 5500 Series device must be running release 8.0(3)7 or later and be configured to send interim accounting update packets.

For example, your Cisco ASA 5500 Series configuration should include:

aaa-server radius protocol radius
interim-accounting-update

For VPN/Wireless SSO support information, refer to VPN and Wireless Components Supported for Single Sign-On (SSO)


Note For additional details on the Cisco ASA enhancement, refer to http://tools.cisco.com/Support/BugToolKit/search/getBugDetails.do?method=fetchBugDetails&bugId=CSCsi75507.


Syslog Configuration Enhancement

Release 4.1(3) features a Syslog Settings page configuration enhancement allowing you to specify the Syslog Facility setting for a designated Syslog server where you direct Syslog messages originating from the CAM. You can use the default "User-Level" facility type, or you can assign any of the "local use" Syslog facility types defined in the Syslog RFC ("Local use 0" to "Local use 7"). This feature gives you the ability to differentiate Cisco NAC Appliance Syslog messages from "User-Level" Syslog entries you may already generate and direct to your Syslog server from other network components.

This enhancement affects the following page of the CAM web console:

Monitoring > Event Logs > Syslog Settings | new Syslog Facility dropdown menu and CPU Utilization Interval field

Debug Log Download Enhancement

With release 4.1(3), you can now specify the number of days of collected debug logs to download in order to aid troubleshooting efforts when working with Cisco technical support. The default setting is one week (7 days). Previously, debug logs included all recorded log entries in the CAM/CAS database.

This enhancement adds a new field, "Download technical support logs for the last [] days" to the following web console pages:

CAM web console: Administration > Clean Access Manager > Support Logs

CAS web console: Monitoring > Support Logs

cisco_api.jsp Enhancement

In Release 4.1(3), the Cisco NAC Appliance API (https://<CAM-IP-address or hostmame>/admin/cisco_api.jsp) adds the following new functions which provide support for Cisco NAC Profiler deployments:

bounceport—bounces an OOB switch port according to the switch and/or port ID

bounceportbymac—bounces an OOB switch port according to the associated client machine MAC address

addsubnet—Adds a subnet to the Device Filters list

updatesubnet—Updates a subnet entry in the Device Filters list

removesubnet—Removes a subnet entry from the Device Filters list

The API also includes the following enhancements:

getversion—(new function) returns the version of the CAM

getreports—(modified function) userKey query parameter is removed; agentType (web/win/mac) query parameter is added

See also CSRF Protection. For further details on the Cisco NAC Appliance API, see Appendix B "API Support" in the Cisco NAC Appliance - Clean Access Manager Installation and Configuration Guide, Release 4.1(3).

CSRF Protection

Release 4.1(3) enhances protection from Cross-Site Request Forgery attacks, which maliciously exploit web browser sessions. Release 4.1(3) provides the following enhancements:

Upon admin login to the CAM web console, each session receives a randomly-generated token (CCA_TOKEN) which is appended to the login URL and all static links. For example, a link such as https://<cam-ip>/admin/authlist.jsp can no longer be accessed directly without the session token. Note that direct link access displays an error message but does not log the user out of the admin console. The user can simply click the browser's "Back" button to go back to the original page.

The CAS web console login now presents a form-based login page instead of a basic HTTP browser-based popup dialog to authenticate the admin user to the CAS (similar to current CAM web console login).

The Cisco NAC Appliance API (cisco_api.jsp) is further protected against crossovers from sessions initiated via the CAM admin console.

Proxy Support Enhancements

Starting with release 4.1(3), proxy-related enhancements enable you to configure the Clean Access Server to allow proxy support for user login sessions using the Unauthenticated role:

Client machines requiring a preconfigured Proxy PAC (Proxy Auto Config) file to access network resources can now get the file via the CAS, rather than directly from a dedicated Enterprise Proxy server. Previously, allowing user access through the CAS to an Enterprise Proxy server would have required allowing all traffic for the Unauthenticated role, which does not allow all traffic by design.


Note A Proxy PAC file is only required when the URL has the same IP address and port assignment as the proxy server. Otherwise, Cisco recommends using the existing IP or Host Traffic Policy to specify the Proxy PAC URL.


You can now configure CAS Host Policies to validate users assigned to the Unauthenticated role using a proxy server, where before you could not.

You can now redirect traffic to a login web page for HTTPS requests via a proxy server (previously was HTTP requests only).

Port 80 is supported as the proxy port.


Note You must "exempt" the CAS from proxy settings. That is, client machines should access the CAS directly without passing traffic through a proxy server.


These enhancements affect the following pages of the CAM web console:

Device Management > CCA Servers > Manage [CAS_IP] > Advanced > Proxy—new PAC (Proxy Auto Config) file URL field

Device Management > CCA Servers > Manage [CAS_IP] > Filter > Roles > Allowed Hosts—updated Parse Proxy Traffic option (no longer excludes Unauthenticated Role)

ARP Broadcast Packet Handling Improvement

Release 4.1(3) features an ARP broadcast enhancement that helps alleviate erroneous ARP broadcast "re-broadcasting." When an ARP broadcast packet arrives at the untrusted eth1 interface on the CAS, the CAS now checks to verify the nature of the broadcast packet. If the destination IP address is a known IP address or a valid IP address as part of a managed subnet, the CAS "re-broadcasts" the packet on to the appropriate managed subnet. If the packet in question is an ARP broadcast itself (a request for the owner of x.y.z.255, for example), then the CAS does not forward/rebroadcast the request because no host on the managed subnet will be able to respond appropriately.

Therefore, the NAC Appliance system now performs as follows when we receive a broadcast message (with a broadcast destination IP address) at the trusted side of the CAS:

1. If the broadcast destination IP address is 255.255.255.255, NAC Appliance rebroadcasts the packet to all subnets on the untrusted side

2. If the broadcast destination IP address is the untrusted (eth1) interface's main subnet broadcast IP address, NAC Appliance rebroadcasts the packet to that subnet on the untrusted side

3. If the broadcast destination IP address is the broadcast IP address of one of the managed subnets on the untrusted (eth1) interface's managed subnet, rebroadcast the packet to that subnet on the untrusted side

Clean Access Server HA ARP Broadcast Enhancement

Release 4.1(3) features an ARP broadcast enhancement to improve Clean Access Server HA capabilities. In the event of a CAS failover, the HA-Secondary CAS (which assumes the HA-Primary role) now sends ARP request broadcast messages to all managed subnets on the untrusted (eth1) interface instead of just the primary subnet. These gratuitous ARPs help ensure that all clients on the untrusted side of the NAC Appliance network have a chance to update their ARP tables with the IP and MAC address of the new active CAS instead of first experiencing a session time-out and having to re-establish connection to the new active CAS.

Deprecated "Retag Trusted-side Egress Traffic with VLAN (In-Band)" Feature

The "Retag Trusted-side Egress Traffic with VLAN (In-Band)" feature for User Roles is deprecated in Release 4.1(3) and will be removed completely in a future release.

This affects the following page of the CAM web console:

User Management > User Roles > New Role | Edit Role

Previously-Deprecated Features Removed from CAM/CAS Web Console Pages

The "Roaming" and "IPSec/L2TP/PPTP/PPP" features that have been deprecated in previous Cisco NAC Appliance releases now no longer appear in the web console interface for release 4.1(3). This change affects many pages of the CAM and CAS web user interfaces, most notably:

The CAM web console Device Management node no longer features the Roaming menu item

The CAS Status module list (Device Management > CCA Servers > Manage [CAS_IP] > Status) no longer features the IPSec Server category

The CAS Network tab (Device Management > CCA Servers > Manage [CAS_IP] > Network) no longer features the IPSec, L2TP, PPTP, or PPP subtab headings

The CAM User Roles list (User Management > User Roles > List of Roles) no longer features the IPSec or Roam column headings

The CAM User Roles configuration screen list (User Management > User Roles > List of Roles > Edit) no longer features the VPN Policy dropdown menu, Roam Policy configuration radio buttons, or the IPSec info or PPP info options for the Show Logged-on Users display settings

The CAM Online Users display options configuration page (Monitoring > Online Users > Display Settings) no longer features the IPSec Key, IPSec Type, or Foreign CCA Server options

Clean Access Agent Auto Remediation

Release 4.1(3) introduces a new configurable Remediation Type[Manual | Automatic] option when configuring Clean Access Agent Requirements for the following requirement types:

Link Distribution

AV Definition Update

AS Definition Update

Windows Update

Launch Programs

Windows Server Update Services

Choosing the Manual Remediation Type preserves the previous Agent behavior. The user has to click through each of the requirements using the Next button.

Choosing the Automatic Remediation Type sets the Agent to perform Auto Remediation. When Auto Remediation is configured, the Clean Access Agent automatically performs updates or launches required programs on the client after the user logs in.

During Auto Remediation, the Agent dialog displays only two buttons: Details and Manual. Clicking Details shows additional progress messages for the auto remediation. Clicking Manual changes the Agent back to Manual mode, where the user has to click through each requirement.

The auto-remediation actions the Agent performs depend on the requirement type, such as:

Auto launching of URL in default browser for Link Distribution

Auto-update of AV/AS definition files

Auto launching of Windows Auto Update(s) (in background)

Auto launching of programs for Launch Programs

Auto installation of WSUS client updates

This enhancement affects the following pages of the CAM web console:

Device Management > Clean Access > Clean Access Agent > Requirements > New Requirement (adds new fields Remediation Type: [Manual | Automatic]/ Interval[] Secs/Retry Count [] to all requirement types except File Distribution and Local Check)


NoteThe Remediation Type configuration option is available for all Enforcement Types (Mandatory, Optional, Audit)

File Distribution and Local Check requirement types do not support the new Automatic Remediation Type, and for these requirement types, the new Remediation Type: [Manual | Automatic]/ Interval[] Secs/Retry Count [] entry does not appear at all on the UI.



Note For Download/Next/Cancel buttons, if the requirement is Mandatory, the "Next" button is disabled until the requirement is met.


Delay Agent Logoff on CAM/CAS

User logoff behavior for the Windows Clean Access Agent in In-Band deployments has been enhanced in release 4.1(3) to ensure that all scripts necessary to log the user out of the NAC Appliance system have had a chance to complete before the CAS restricts user traffic. The drawback of users not having had a chance to successfully log out of the CAM/CAS before Windows shuts down is that the user session may remain "active" on the CAM (the user ID and session information still appear in the Monitoring > Online Users > View Online Users display) and the user suffers connection issues the next time they attempt to connect to the network from the same client machine. To address this situation, the administrator can now configure a period of time to delay Agent logout from the CAS/CAM to ensure enough time to complete the logout script(s).

This enhancement affects the following page CAM web console:

Device Management > Clean Access > General Setup > Agent Login | Logoff Clean Access Agent users from network on their machine logoff or shutdown after <x> secs (for Windows & In-Band setup) option now reflects the capability to specify a delay for Agent logout

64-bit Windows Operating System Agent Support

In release 4.1(3), the Windows Clean Access Agent and Cisco NAC Web Agent perform authentication only on 64-bit Windows Vista and Windows XP client operating systems.


Note The 4.1.3.0 Clean Access Agent performs authentication only for 64-bit Windows Vista and Windows XP client operating systems. Once the user is authenticated, the Agent does not perform posture assessment or remediation. To support 64-bit operating system Agents, the CAM and CAS must also be running release 4.1.2.1 or later. Because Cisco NAC Appliance provides authentication-only support for 64-bit operating system Agents, Nessus scanning via the Clean Access Agent does not perform posture assessment/remediation on the client machine.


Supported AV/AS Product List Enhancements (Version 67)

See Clean Access Supported AV/AS Product List for the latest AV/AS product charts.

See Supported AV/AS Product List Version Summary for details on each update to the list.

Out-of-Band Enhancements

Access to Authentication VLAN Change Detection Enhancement

Cisco NAC Appliance release 4.1(3) further enhances VLAN change detection mechanisms for Clean Access Agent machines in Out-of-Band (OOB) deployments to allow the client port to change from the Access to the Authentication VLAN without having to bounce the port.


Caution The Access to Authentication VLAN Change Detection feature should only be used for OOB deployments that require client DHCP IP refresh/renew. DHCP refresh/renew is configured under Administration > User Pages > Login Page > List > Edit > General | Use web client to release and renew IP address when necessary (OOB). If your OOB deployment makes use of port bouncing, this feature is not needed and should not be configured.

This feature applies to the Clean Access Agent only and does not apply to web login or to the Cisco NAC Web Agent. This feature is designed to enhance support for the following deployments:

L3 OOB (Real-IP or Virtual Gateway)

L2 OOB Real IP Gateway

L2 OOB Virtual Gateway with user-role based VLAN assignment

In OOB, when the user is logged out and the client port changes from the Access VLAN to the Authentication VLAN, the IP address for the client machine typically needs to change to coincide with the Authentication VLAN. In OOB, when the user is in the Access VLAN, the Clean Access Agent no longer communicates with the CAM or CAS, so the Agent is not aware when the CAM changes the VLAN for the client port. Although the CAM can bounce the port to change the IP address on the client, this solution is not recommended for IP Phone environments, as it can disrupt voice services.

Versions earlier than 4.1.3.0 of the Windows Clean Access Agent could only learn of a change from the Access VLAN to the Authentication VLAN once the current DHCP lease had expired and the client was forced to re-establish connection. With release 4.1(3), the Agent detects that the client has the wrong IP address for the current VLAN and automatically triggers an IP address change (release/renew) to maintain connection. No additional configuration on the CAM is required to use this enhancement.


Note This feature requires the user to have administrative privileges to the client machine. If the user does not have administrative privileges, then the Agent must be installed via the Clean Access Agent Stub service to ensure the Agent can perform an IP release/renew on the client.


Version 4.1.3.2 of the Windows Clean Access Agent modifies the Access to Authentication VLAN Change Detection feature as follows:

The feature is turned off by default (version 4.1.3.1 and later)

The Agent mechanism for detection changes from ARP to ICMP (ping) by default, and is configurable: ICMP, or ARP, or ICMP then ARP.

There is a new retry detection interval which is configurable. The Agent retries gateway detection a default of 5 times before performing IP refresh.

SWISS VLAN detection checks are enhanced to take multi-NIC configurations into account.

net dhcp stop/start is turned off by default and is configurable with the 4.1.3.2 Agent. Only HKLM settings are now read instead of both HKCU and HKLM settings, and the registry settings will take effect after an Agent login.


NoteWhen using ICMP, the client's default gateway must also allow ICMP responses to client pings.

If the default gateway cannot accommodate responses to Agent ICMP requests, the client machine and the default gateway must be configured to use ARP.

When using ARP with Windows XP and Windows 2000 client machines, use of the Clean Access Agent Stub is required, because standard users typically do not have privileges to alter the ARP cache.

Cisco does not recommend configuring your system to use ARP for client-to-gateway communications, as it can generate unnecessary ARP traffic on the network.


Agent users with non-admin privileges and no Clean Access Agent Stub service installed on the client can use ICMP to detect the VLAN and then enable DHCP services (net dhcp stop/start) to change the client IP address. In order to utilize the option, however, you must configure a Group Policy Object (GPO) granting domain users full control of the DHCP client. Once DHCP control is enabled, the Agent attempts to restart the DHCP client to get a new IP address after failing IP address release/renew. See Table 5 for more information.


Note Agent versions 4.1.3.1 and 4.1.3.2 disable DHCP services (net dhcp stop/start) by default. Enabling this option may result in unexpected behavior, because the Agent refreshes IP addresses on all NICs, not just the one requiring refresh. Therefore, Agent IP refresh/renew is the preferred method for changing the client IP address.



Note Due to a characteristic of Windows 2000, users logged in with standard user privileges can take up to 15 minutes to refresh their IP address. Installing the Clean Access Agent Stub service does not resolve this issue.

This feature may not be compatible with all Cisco NAC Appliance deployments (such as VPN deployments). Therefore, although you can still enable and configure this feature, versions 4.1.3.1 and 4.1.3.2 of the Clean Access Agent disable this feature by default. Refer to Windows Clean Access Agent Version 4.1.3.1 and Windows Clean Access Agent Version 4.1.3.2 for additional details.


Access to Authentication VLAN Change Detection Interoperability with Clients Featuring More Than One Active NIC

If you use the Access to Authentication VLAN change detection feature on a client machine with more than one active NIC, all active NICs on the client use the feature. By design, the NIC with the lowest metric always takes precedence for routing purposes, and you can determine the metric using the route print command from a command prompt. Client-to-CAS communication depends on the specific scenario:

If both active NICs are can simultaneously contact two different CASs, then the Port Profiles configured for the two CASs should feature the same port bouncing and/or IP refresh behavior.

If one of the CASs is in Layer 2 OOB Virtual Gateway mode, and the client somehow switches back to the authentication VLAN (if the client is deleted form the Certified Device List, for example), then the client can no longer ping its default gateway. This situation can result in the client performing unnecessary, repetitive IP refreshes even though that NIC is not the one the client is currently using for traffic.

If this configuration is required, you must configure a traffic policy on the CAM to allow ICMP traffic to the default gateway for the Unauthenticated Role.

If one of the NICs connects to an In-Band CAS and the other connects to an Out-of-Band CAS, then both NICs should function properly whether the Access to Authentication VLAN change detection feature is required or not.

Configuring Registry Keys on the Windows Client

In order to configure a client machine with multiple NICs to appropriately interact with the Cisco NAC Appliance Access to Authentication VLAN detect feature, you must define the appropriate registry keys on the client, as shown in Table 5. The following required DWORD registry keys are all located in the same HKEY_LOCAL_MACHINE\Software\Cisco\Clean Access Agent\ registry location.

Table 5 Required DWORD Registry Key Settings for Access to Authentication VLAN Change Detection on Clients with Multiple Active NICs

Registry Key
Default Value (Decimal)
Valid Range
Behavior

RetryDetection

5

Any

If ICMP or ARP polling fails, this setting configures the Agent to retry <x> times before refreshing the client IP address.

PingArp

0

0-2

If this value is set to 0, poll using ICMP.

If this value is set to 1, poll using ARP.

If this value is set to 2, poll using ICMP first, then (if ICMP fails) use ARP.

PingMaxTimeout

1

1-10

Poll using ICMP and if no response in <x> seconds, then declare ICMP polling failure.

DHCPServiceStartStop

0

Any

If this setting is 0, do not perform DHCP services (net dhcp stop/start) when IP refresh fails with API.

If any value other than 0, perform DHCP services.

VlanDetectInterval

0

0, 5-60

If this setting is 0, the Access to Authentication VLAN change feature is disabled.

If this setting is 1-5, the Agent sends ICMP/ARP queries every 5 seconds.

If this setting is 6-60, ICMP/ARP every <x> seconds. (Any value greater than 60 seconds automatically reverts to 60.)


For more information on multiple-NIC client support, see Support for Clients with Multiple Active NICs.

SNMP Inform Notification Enhancement

SNMP notification behavior has been enhanced in release 4.1(3) to feature SNMP "inform request" behavior. Because SNMP traps can be unreliable due to the fact that the SNMP receiver is not required to send an acknowledgment when it receives a trap, the sender cannot determine if the trap was received. In release 4.1(3), the CAM is able to transmit SNMP inform acknowledgements in response to switch SNMP inform requests to ensure reliable information delivery between the switch and the CAM. (The inherent SNMP "inform request/acknowledgement" retry mechanism helps increase the chances of successful information delivery from the managed switch to the CAM.)

SNMP "MAC Move Notification" Switch Port Configuration Support

With release 4.1(3), Cisco NAC Appliance now supports the "MAC Move Notification" switch port configuration and notification feature. When the managed switch sends out a notification trap announcing that a connected host has moved from one port to another within the same VLAN, the CAM responds to the notification by updating the discovered client information and, if necessary, changing the VLAN assignment for the host port to reflect the information in the switch trap notification.

Releases earlier than 4.1(3) depend on "MAC Changed Notification" to detect the client device when it connects to the switch. From the notification, the switch learns a new MAC address on the port, and the Clean Access Manager learns from the switch what device is connected to which port. Based on this learned information, the CAM changes the VLAN for that switch port.

However, when the MAC Move Notification Trap is configured on the switch, the switch sends out the trap when a connected device moves from one port to another on the same VLAN. With CCA versions earlier than 4.1(3), the MAC Move Notification is not supported, and the CAM does not update connected device information when a MAC Move event occurs. As a result, CAM can end up incorrectly setting the VLAN on the switch port from which the device has already disconnected.

With release 4.1(3) and later, OOB deployments now support:

Linkup/linkdown

MAC change notification—when the switch learns a new MAC address on a managed port

MAC move notification—when a device/host moves from one managed port to another

Cisco NAC Appliance Agent Enhancements

Windows Clean Access Agent Language Template Support Enhancement (Version 4.1.3.0)

Added Agent language template support for Dutch, Hungarian, and Portuguese for Windows Agents. The Agent will display localized text for these languages if run from localized Windows operating system.


Note The Agent picks the correct language template based on the local computer Locale (under Control Panel > Regional and Language Options). Cisco recommends using the localized Agent in the localized version of Windows (e.g. French Agent in French Windows). Agent language template support only controls what the viewer sees after the Agent is installed; it does not include support for different client operating systems for the Agent Installer or for AV/AS products.



Note If the administrator includes non-English text in the CAM configuration (e.g. non-English characters in a requirement description or registry value check), it may not be displayed correctly or run correctly.


See Cisco NAC Appliance Agents for enhancement details per Agent version.

Cisco NAC Appliance Agents

This section consolidates information for Clean Access Agent and Cisco NAC Web Agent client software versions, as follows:

Windows Clean Access Agent Enhancements

Mac OS X Clean Access Agent Enhancements

Cisco NAC Web Agent Enhancements

Enhancements are cumulative and apply both to the version introducing the feature and to subsequent later versions, unless otherwise noted. For all Agents:

See Release 4.1(3) Compatibility Matrix and Release 4.1(3) Clean Access Agent Upgrade Compatibility Matrix for compatibility details.

See Clean Access Supported AV/AS Product List for details on related AV/AS support.


Note Cisco strongly recommends running version 4.1.3.0 of the Clean Access Agent with release 4.1(3) and later of the CAM/CAS. However, administrators can optionally configure the 4.1(3) CAM/CAS to allow login and posture assessment from 4.1.0.x Agents. Refer to the "Supported AV/AS Product List Version Summary" of the applicable Release Notes for complete details on 4.1.0.x Agent AV/AS support.



Note See the "Clean Access Agent Version Summary" section in the Release Notes for Cisco NAC Appliance (Cisco Clean Access) Version 4.1(2) for details on the 4.1.2.x Agent.
See the "Clean Access Agent Version Summary" section in the Release Notes for Cisco NAC Appliance (Cisco Clean Access) Version 4.1(1) for details on the 4.1.1.0 Agent.


For additional details refer to Known Issues for Cisco NAC Appliance and Troubleshooting for Agent-related information.

Windows Clean Access Agent Enhancements

This section contains the latest enhancements per version of the Windows Clean Access Agent.

Windows Clean Access Agent Version 4.1.3.2

Windows Clean Access Agent Version 4.1.3.1

Windows Clean Access Agent Version 4.1.3.0

Enhancements are cumulative and apply both to the version introducing the feature and to subsequent later versions, unless otherwise noted.

Windows Clean Access Agent Version 4.1.3.2

Version 4.1.3.2 of the Windows Clean Access Agent resolves caveats CSCsl77778 CSCsl77801, CSCsm04923, CSCsm38529, CSCsm39238, CSCsm54763, CSCsm42572, CSCsm62326, CSCsm67052, and CSCso22399. Refer to Resolved Caveats - Windows Clean Access Agent 4.1.3.2 for additional details.

New features or enhancements for Windows Clean Access Agent version 4.1.3.2 (persistent):

Version 4.1.3.2 of Windows the Clean Access Agent modifies the Access to Authentication VLAN Change Detection feature as follows:

The feature is turned off by default (version 4.1.3.1 and later)

The Agent mechanism for detection changes from ARP to ICMP (ping) by default, and is configurable: ICMP, or ARP, or ICMP and ARP.

There is a new retry detection interval which is configurable. The Agent retries CAS detection a default of 5 times before performing IP refresh.

SWISS VLAN detection checks are enhanced so that VLAN change detection is not performed for 0.0.0.0, IP address = default gateway (VPN), or auto-assigned IP address deployments.

net dhcp stop/start is turned off by default and is configurable with the 4.1.3.2 Agent. HKLM settings are now used instead of HKCU settings, and the registry settings will take effect after an Agent login.


Note See Table 5 under Access to Authentication VLAN Change Detection Enhancement for details on the registry settings required to configure the Windows client for Access to Authentication VLAN change detection.


Enhancements to Support for Clients with Multiple Active NICs

Enhancements to Access to Authentication VLAN Change Detection Enhancement (including new "Access to Authentication VLAN Change Detection Interoperability with Clients Featuring More Than One Active NIC" section)

Added language template support for Russian, Turkish, and Serbian (Cyrillic) for Windows Agents.

Supported AV/AS Product List Enhancements (Version 68)

See Clean Access Supported AV/AS Product List for the latest AV/AS product charts.

See Supported AV/AS Product List Version Summary for details on each update to the list.

Windows Clean Access Agent Version 4.1.3.1

Version 4.1.3.1 of the Windows Clean Access Agent resolves caveat CSCsm05207. Refer to Resolved Caveats - Windows Clean Access Agent 4.1.3.1 and Access to Authentication VLAN Change Detection Enhancement for additional details.


Note MSI Package Installation:

When using MSI package installation/upgrade for the Clean Access Agent, minor version (4th digit) upgrades are affected by caveat CSCsm20655. Refer to the workaround for details.

Also refer Known Issues with MSI Agent Installer before downloading the MSI installer for the full Agent from Cisco Secure Downloads.


Windows Clean Access Agent Version 4.1.3.0

New features or enhancements for Windows Agent version 4.1.3.0 (persistent):

Agent behavior supports multiple active NICs on the client machine. See Support for Clients with Multiple Active NICs for details.

User logoff behavior via the Windows Clean Access Agent has been enhanced to ensure that all scripts necessary to log the user out of the Cisco NAC Appliance system have had a chance to complete before the CAS restricts user traffic. See Delay Agent Logoff on CAM/CAS for details.

In an OOB environment, the Agent can detect the VLAN change and switch from the Access to the Authentication VLAN automatically. See Access to Authentication VLAN Change Detection Enhancement for details.

You can configure the Agent to delay a specified period of time before performing VPN SSO. See VPN SSO Login Enhancement for details.

Windows Clean Access Agents support requirement types that the administrator configures to employ automatic remediation. See Clean Access Agent Auto Remediation for details.

Added language template support for Dutch, Hungarian, and Portuguese for Windows Agents.

Support for Stub installer on Windows Vista operating system.


Note For checks/rules/requirements, the Agent can detect "N" (European) versions of the Windows Vista operating system, but the CAM/CAS treat "N" versions of Vista as their US counterpart.



Note When installing the 4.1.3.0 Clean Access Agent via stub installation on Windows Vista machines only, Cisco recommends not to use the Full UI Stub Installation Option. To avoid the appearance of 5-minute installation dialog delays caused by the Vista Interactive Service Detection Service, do not use the No UI or Reduced UI option when configuring Stub Installation Options for Windows Vista client machines.



Note When non-admin users install/uninstall the Agent through stub service on Windows Vista, they will see an "Interactive Services Dialog Detection" dialog. If the user is installing, no input is required in the dialog session—it will automatically disappear. If the client machine is fast, the user may not even see the dialog appear at all, so the resulting behavior is as if the Agent gets silently installed after a few seconds. When uninstalling, however, the uninstall process does not complete until the user responds to a prompt inside the dialog.

This is expected behavior because, unlike earlier Windows operating systems, Windows Vista services run in an isolated session (session 0) from user sessions, and thus do not have access to video drivers. As a workaround for interactive services like the Agent stub installer, Windows Vista uses an Interactive Service Detection Service to prompt users for user input for interactive services and enable access to dialogs created by interactive services. The "Interactive Service Detection Service" will automatically launch by default and, in most cases, users are not required to do anything. If the service is disabled for some reason, however, Agent installation by non-admin users will not function.


For more information on the stub installer and its behavior, see the "Configuring Agent Distribution/Installation" section of the Cisco NAC Appliance - Clean Access Manager Installation and Configuration Guide, Release 4.1(3). See also Known Issues with MSI Agent Installer.

Performs authentication on 64-bit Windows Vista and Windows XP client operating systems. See 64-bit Windows Operating System Agent Support for details.


Note The 4.1.3.0 Agent performs authentication only for 64-bit Windows Vista and Windows XP client operating systems. Once the user is authenticated, the Agent does not perform posture assessment or remediation. To support 64-bit operating system Agents, the CAM and CAS must also be running release 4.1.2.1 or later. Because Cisco NAC Appliance provides authentication-only support for 64-bit operating system Agents, nessus scanning via the Clean Access Agent does not perform remediation on the client machine.


Mac OS X Clean Access Agent Enhancements

This section contains the latest enhancements per version of the Mac OS X Clean Access Agent:

Mac OS X Clean Access Agent Version 4.1.3.1

Mac OS X Clean Access Agent Version 4.1.3.0

Enhancements are cumulative and apply both to the version introducing the feature and to subsequent later versions, unless otherwise noted.


Note Cisco NAC Appliance supports basic web login on Macintosh operating systems—whether Mac OS X, iPhone, or iPod Touch—as long as clients use Safari or Firefox browsers. Refer to Supported Hardware and System Requirements for Cisco NAC Appliance (Clean Access) for additional details.


Mac OS X Clean Access Agent Version 4.1.3.1

Version 4.1.3.1 of the Clean Access Agent resolves caveats CSCsl83353, CSCsl88985, CSCsl98060, CSCsm10311, CSCsm20813, CSCsm26806, and CSCsm47276 for Mac OS X Agents. Refer to Resolved Caveats - Mac OS X Agent 4.1.3.1 for additional details.

Mac OS X Clean Access Agent Version 4.1.3.0

New features or enhancements in Macintosh OS X Clean Access Agent version 4.1.3.0:

Mac Agent directory has been changed from /Library/Application Support/Cisco Systems/ folder to /Applications/ folder. See also Generate Mac OS X Agent Debug Log for additional details.

Mac Agent logo and status icons have been redesigned. For details, see the "Cisco NAC Appliance Agents" chapter in the Cisco NAC Appliance - Clean Access Manager Installation and Configuration Guide, Release 4.1(3).

The Mac OS X Agent features auto-upgrade for version 4.1.3.0 and later. During user login, when the 4.1.3.0 Mac Agent is in the process of establishing a connection to the CAS (SWISS UDP packet exchange), the Agent currently installed on the Mac client machine determines whether or not a newer version of the Mac OS X Clean Access Agent is available and, if so, automatically begins downloading and installing the newer Agent version. Once installed and initiated, the set-up process requires only very little user interaction. Once completely installed, the newer version of the Agent launches automatically.

Mac OS X Agent version 4.1.3.0 features login support for Macintosh users running Mac OS X version 10.5 and 10.5.1 ("Leopard").


Note You must install release 4.1(3) on your CAM and CAS to enable Mac OS X version 10.5 or 10.5.1 users to access the network via Cisco NAC Appliance. Mac OS X version 10.5 and 10.5.1 users cannot log into earlier releases of Cisco NAC Appliance due to a mismatch in NIC MAC address identification from the client machine.


Agent behavior supports multiple active NICs on the client machine. See Support for Clients with Multiple Active NICs for details.

In an OOB environment, the Agent can detect the VLAN change from the Access to the Authentication VLAN automatically. See Access to Authentication VLAN Change Detection Enhancement.

VLAN change can be configured so the Agent will display a count down progress bar for the login until the delay times out.

You can configure the Agent to delay a specified period of time before performing VPN SSO. See VPN SSO Login Enhancement

Cisco NAC Web Agent Enhancements

This section contains the latest enhancements per version of the Cisco NAC Web Agent:

Cisco NAC Web Agent Version 4.1.3.10

Cisco NAC Web Agent Version 4.1.3.9

Enhancements are cumulative and apply both to the version introducing the feature and to subsequent later versions, unless otherwise noted.

See Release 4.1(3) Compatibility Matrix for general compatibility details.

Cisco NAC Web Agent Version 4.1.3.10

For release 4.1(3) and later, new versions of the Cisco NAC Web Agent are available from the Clean Access Manager via the Updates mechanism (Device Management > Clean Access > Updates > Update). If use of the Cisco NAC Web Agent is required for the role, users will automatically download the latest version that is available on the CAM. If you do not want to distribute the latest version of the Web Agent, you can deselect the "Check for Cisco NAC Web Agent updates" checkbox on the Updates page.

New features or enhancements for Windows Agent version 4.1.3.10:

Signed Certificate Requirements

Resolves caveats CSCsm03961 and CSCsm17435. See Resolved Caveats - Cisco NAC Web Agent 4.1.3.10.

For general Web Agent system requirements, refer to Cisco NAC Web Agent Version 4.1.3.9

Signed Certificate Requirements

For version 4.1.3.10, the ActiveX control and Java Applet are signed by a certificate ("Cisco Systems") which is signed by "Thawte Server CA," and should be included in the Trusted Root Certificate Authority store.

If the certificate is not included in the Trusted Root Certificate Authority store, users will see a security alert dialog whenever they launch the Cisco NAC Web Agent. The dialog indicates a secure connection is required, but the certificate issuer is untrusted or unknown. The user can accept the certificate for this session, or install this certificate in the certificate store.

To install the certificate:

Step 1 During the login session, users can select View Certificate from the Security Alert (or similar) dialog.

Step 2 Select the Certificate Path tab.

Step 3 Select the "www.perfigo.com" certificate entry and click View Certificate.

Step 4 In the configuration wizard, click Install Certificate to launch the certificate wizard.

Step 5 In the wizard introduction page, click Next.

Step 6 In the wizard "Certificate Store" page, choose the Automatically select... radio button, click Next, and then click Finish. (If you are prompted to confirm the import, click Yes.)


For additional information, see also Vista/IE 7 Certificate Revocation List.

Cisco NAC Web Agent Version 4.1.3.9

Release 4.1(3) introduces the new (temporal) Cisco NAC Web Agent version 4.1.3.9.

Refer to Cisco NAC Web Agent for feature details.

Versions 4.1.3.9 and later of the Cisco NAC Web Agent have the following system requirements:

Operating System Dependencies

Browser Support

ActiveX and Java Applet Requirements

Microsoft Internet Explorer 7 in Windows Vista

Operating System Dependencies

You can install and launch the Cisco NAC Web Agent on the following operating systems:

Windows 2000 (Service Packs 4 and 6)

Windows XP Professional/Home (Service Packs 1 and 2)

Windows Vista Home Premium/Ultimate (authentication only)


Note Security restrictions for the "Guest" user profile in Windows Vista operating systems prevent ActiveX controls and Java applets from running properly. Therefore, you must be logged into the Windows Vista client machine as a known user (not a "Guest") in order to log into Cisco NAC Appliance via the Web Agent.


Browser Support

You can install and launch the Cisco NAC Web Agent from the following web browsers:

Microsoft Internet Explorer versions 6 or 7 (ActiveX or Java applet)

Firefox versions 1.5 or 2.0 (Java applet only)

ActiveX and Java Applet Requirements

If you plan to use the Java applet version to install the Web Agent files, the client must already have Java version 1.4.2 or higher installed.

If you plan to install the Web Agent files via ActiveX, the client machine must be using Microsoft Internet Explorer. You cannot install via ActiveX on a Firefox web browser.

The user must have permissions for ActiveX download or admin privileges on the client machine to enable installation of ActiveX controls.


Note The Web Agent Java applet might fail to launch when the CPU load on the client machine approaches 100%. (ActiveX runs successfully under these conditions.)


Microsoft Internet Explorer 7 in Windows Vista

By default, Windows Vista checks the server certificate revocation list and prevents the Web Agent from launching on the client machine.

To disable this functionality:


Step 1 In Internet Explorer 7, navigate to Menu > Tools > Internet Options.

Step 2 Click the Advanced tab.

Step 3 Under Security, uncheck (disable) the Check for server certificate revocation option.

Step 4 Click OK.


For additional information, see also Vista/IE 7 Certificate Revocation List.

Clean Access Supported AV/AS Product List

This section describes the Supported AV/AS Product List that is downloaded to the Clean Access Manager via Device Management > Clean Access > Updates > Update to provide the latest antivirus (AV) and anti-spyware (AS) product integration support for Cisco NAC Appliance Agents that support AV/AS posture assessment/remediation. The Supported AV/AS Product List is a versioned XML file distributed from a centralized update server that provides the most current matrix of supported AV/AS vendors and product versions used to configure AV/AS Rules and AV/AS Definition Update requirements.

The Supported AV/AS Product List contains information on which AV/AS products and versions are supported in each Windows Clean Access Agent release along with other relevant information. It is updated regularly to bring the relevant information up to date and to include newly added products for new releases. Cisco recommends keeping your list current, especially when you upload a new Agent Setup version or Agent Patch version to your CAM. Having the latest Supported AV/AS list ensures your AV/AS rule configuration pages list all the new products supported in the new Agent.


Note Cisco recommends keeping your Supported AV/AS Product List up-to-date on your CAM by configuring the Update Settings under Device Management > Clean Access > Updates > Update to Automatically check for updates starting from <x> every <y> hours.


The following charts list the AV and AS product/version support per client OS as of the latest Clean Access release:

Clean Access AV Support Chart (Windows Vista/XP/2000)

Clean Access AV Support Chart (Windows ME/98)

Clean Access AS Support Chart (Windows Vista/XP/2000)

The charts show which AV/AS product versions support virus or spyware definition checks and automatic update of client virus/spyware definition files via the user clicking the Update button on the Clean Access Agent.

For a summary of the product support that is added per version of the Supported AV/AS Product List or Clean Access Agent, see also:

Cisco NAC Appliance Agents

Supported AV/AS Product List Version Summary

You can access additional AV and AS product support information from the CAM web console under Device Management > Clean Access > Clean Access Agent > Rules > AV/AS Support Info.


Note Where possible, Cisco recommends using AV Rules mapped to AV Definition Update Requirements when checking antivirus software on clients, and AS Rules mapped to AS Definition Update Requirements when checking anti-spyware software on clients. In the case of non-supported AV or AS products, or if an AV/AS product/version is not available through AV Rules/AS Rules, administrators always have the option of creating their own custom checks, rules, and requirements for the AV/AS vendor (and/or using Cisco provided pc_ checks and pr_rules) through Device Management > Clean Access > Clean Access Agent (use New Check, New Rule, and New File/Link/Local Check Requirement). See the Cisco NAC Appliance - Clean Access Manager Installation and Configuration Guide, Release 4.1(3) for configuration details.

Note that Clean Access works in tandem with the installation schemes and mechanisms provided by supported AV/AS vendors. In the case of unforeseen changes to underlying mechanisms for AV/AS products by vendors, the Cisco NAC Appliance team will update the Supported AV/AS Product List and/or Clean Access Agent in the timeliest manner possible in order to support the new AV/AS product changes. In the meantime, administrators can always use the "custom" rule workaround for the AV/AS product (such as pc_checks/pr_ rules) and configure the requirement for "Any selected rule succeeds."


Clean Access AV Support Chart (Windows Vista/XP/2000)

Table 6 lists Windows Vista/XP/2000 Supported AV Products as of the latest release of the Cisco NAC Appliance software. (See Table 7 for Windows ME/98).

Table 6 Clean Access Antivirus Product Support Chart (Windows Vista/XP/2000)
Version 68,
4.1.3.2 Agent, CAM/CAS Release 4.1.3.1 (Sheet 1 of 12)

Product Name
Product Version
AV Checks Supported
(Minimum Agent Version Needed)1
Live Update 2 , 3
Installation
Virus Definition
AEC, spol. s r.o.

TrustPort Antivirus

2.x

yes (4.0.6.0)

-

yes

AhnLab, Inc.

AhnLab Security Pack

2.x

yes (3.5.10.1)

yes (3.5.10.1)

yes

AhnLab V3 Internet Security 2007

7.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

AhnLab V3 Internet Security 2007 Platinum

7.x

yes (3.6.5.0)

yes (3.6.5.0)

yes

AhnLab V3 Internet Security 2008 Platinum

7.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

AhnLab V3 Internet Security 7.0 Platinum Enterprise

7.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

V3Pro 2004

6.x

yes (3.5.10.1)

yes (3.5.12)

yes

V3 VirusBlock 2005

6.x

yes (4.1.2.0)

yes (4.1.2.0)

-

ALWIL Software

avast! Antivirus

4.x

yes (3.5.10.1)

yes (3.5.10.1)

yes

avast! Antivirus (managed)

4.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

avast! Antivirus Professional

4.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

America Online, Inc.

Active Virus Shield

6.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

AOL Safety and Security Center Virus Protection

102.x

yes (4.0.4.0)

yes (4.0.4.0)

-

AOL Safety and Security Center Virus Protection

1.x

yes (3.5.11.1)

yes (3.5.11.1)

-

AOL Safety and Security Center Virus Protection

210.x

yes (4.0.4.0)

yes (4.0.4.0)

-

AOL Safety and Security Center Virus Protection

2.x

yes (4.1.0.0)

yes (4.1.0.0)

-

Authentium, Inc.

Command Anti-Virus Enterprise

4.x

yes (3.5.0)

yes (3.5.0)

yes

Command AntiVirus for Windows

4.x

yes (3.5.0)

yes (3.5.0)

yes

Command AntiVirus for Windows Enterprise

4.x

yes (3.5.2)

yes (3.5.2)

yes

Cox High Speed Internet Security Suite

3.x

yes (4.0.4.0)

yes (4.0.4.0)

yes

AVG Technologies

AVG 8.0 [AntiVirus]

8.x

yes (4.1.3.2)

-

yes

Avira GmbH

Avira AntiVir PersonalEdition Classic

7.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

Avira AntiVir PersonalEdition Premium

7.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Avira AntiVir Windows Workstation

7.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Avira Premium Security Suite

7.x

yes (3.6.5.0)

yes (3.6.5.0)

yes

Beijing Rising Technology Corp. Ltd.

Rising Antivirus Software AV

17.x

yes (3.5.11.1)

yes (3.5.11.1)

yes

Rising Antivirus Software AV

18.x

yes (3.5.11.1)

yes (3.5.11.1)

yes

Rising Antivirus Software AV

19.x

yes (4.0.5.0)

yes (4.0.5.0)

yes

Rising Antivirus Software AV

20.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

BellSouth

BellSouth Internet Security Anti-Virus

5.x

yes (4.0.5.1)

yes (4.0.5.1)

-

BullGuard Ltd.

BullGuard 7.0

7.x

yes (4.1.2.0)

yes (4.1.2.0)

-

BullGuard 8.0

8.x

yes (4.1.3.2)

yes (4.1.3.2)

-

Cat Computer Services Pvt. Ltd.

Quick Heal AntiVirus Lite

9.5.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

Quick Heal AntiVirus Plus

9.5.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

Check Point, Inc

ZoneAlarm Anti-virus

7.0.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

ZoneAlarm Anti-virus

7.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

ZoneAlarm (AntiVirus)

7.0.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

ZoneAlarm (AntiVirus)

7.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

ZoneAlarm Security Suite Antivirus

7.0.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

ZoneAlarm Security Suite Antivirus

7.x

yes (4.0.5.0)

yes (4.0.5.0)

yes

ClamAV

ClamAV

devel-x

yes (4.0.6.0)

yes (4.0.6.0)

yes

ClamWin

ClamWin Antivirus

0.x

yes (3.5.2)

yes (3.5.2)

yes

ClamWin Free Antivirus

0.x

yes (3.5.4)

yes (3.5.4)

yes

Computer Associates International, Inc.

CA Anti-Virus

8.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

CA Anti-Virus

9.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

CA eTrust Antivirus

7.x

yes (3.5.0)

yes (3.5.0)

yes

CA eTrust Internet Security Suite AntiVirus

7.x

yes (3.5.11)

yes (3.5.11)

yes

CA eTrustITM Agent

8.x

yes (3.5.12)

yes (3.5.12)

yes

eTrust Antivirus

6.0.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

eTrust EZ Antivirus

6.1.x

yes (3.5.3)

yes (3.5.8)

yes

eTrust EZ Antivirus

6.2.x

yes (3.5.0)

yes (3.5.0)

yes

eTrust EZ Antivirus

6.4.x

yes (3.5.0)

yes (3.5.0)

yes

eTrust EZ Antivirus

7.x

yes (3.5.0)

yes (3.5.0)

yes

eTrust EZ Armor

6.1.x

yes (3.5.0)

yes (3.5.8)

yes

eTrust EZ Armor

6.2.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

eTrust EZ Armor

7.x

yes (3.5.0)

yes (3.5.0)

yes

Defender Pro LLC

Defender Pro Anti-Virus

5.x

yes (4.0.4.0)

yes (4.0.4.0)

yes

EarthLink, Inc.

Aluria Security Center AntiVirus

1.x

yes (4.1.0.0)

yes (4.1.0.0)

-

EarthLink Protection Control Center AntiVirus

1.x

yes (3.5.10.1)

yes (3.5.10.1)

-

EarthLink Protection Control Center AntiVirus

2.x

yes (4.0.5.1)

yes (4.0.5.1)

-

EarthLink Protection Control Center AntiVirus

3.x

yes (4.1.3.0)

yes (4.1.3.0)

-

eEye Digital Security

eEye Digital Security Blink Personal

3.x

yes (4.0.6.0)

yes (4.0.6.0)

yes

eEye Digital Security Blink Professional

3.x

yes (4.0.6.0)

yes (4.0.6.0)

-

Eset Software

ESET NOD32 Antivirus

3.x

yes (4.1.3.2)

yes (4.1.3.2)

-

NOD32 antivirus system

2.x

yes (3.5.5)

yes (3.5.5)

yes

NOD32 antivirus system

x

yes (4.1.3.2)

yes (4.1.3.2)

yes

NOD32 antivirus System

x

yes (4.1.3.2)

yes (4.1.3.2)

yes

NOD32 Antivirus System

x

yes (4.1.3.2)

yes (4.1.3.2)

yes

Fortinet Inc.

FortiClient Consumer Edition

3.x

yes (4.0.6.0)

yes (4.0.6.0)

yes

Frisk Software International

F-PROT Antivirus for Windows

6.0.x

yes (4.0.5.1)

yes (4.0.5.1)

-

F-Prot for Windows

3.14e

yes (3.5.0)

yes (3.5.0)

yes

F-Prot for Windows

3.15

yes (3.5.0)

yes (3.5.0)

yes

F-Prot for Windows

3.16c

yes (3.5.11)

yes (3.5.11)

yes

F-Prot for Windows

3.16d

yes (3.5.11)

yes (3.5.11)

yes

F-Prot for Windows

3.16x

yes (3.5.11.1)

yes (3.5.11.1)

yes

F-Secure Corp.

F-Secure Anti-Virus

5.x

yes (3.5.0)

yes (3.5.0)

yes

F-Secure Anti-Virus

6.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

F-Secure Anti-Virus

7.x

yes (4.0.4.0)

yes (4.0.4.0)

-

F-Secure Anti-Virus 2005

5.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

F-Secure Anti-Virus Client Security

6.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

F-Secure Anti-Virus for Windows Servers

5.x

yes (4.1.3.2)

yes (4.1.3.2)

-

F-Secure Internet Security

6.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

F-Secure Internet Security

7.x

yes (4.0.4.0)

yes (4.0.4.0)

-

F-Secure Internet Security 2005

5.x

yes (4.1.3.0)

yes (4.1.3.0)

-

F-Secure Internet Security 2006 Beta

6.x

yes (3.5.8)

yes (3.5.8)

yes

GData Software AG

AntiVirusKit 2006

2006.x

yes (4.1.0.0)

yes (4.1.0.0)

-

G DATA AntiVirus 2008

18.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

G DATA AntiVirusKit

17.x

yes (4.1.3.0)

yes (4.1.3.0)

-

G DATA InternetSecurity [Antivirus]

17.x

yes (4.1.3.0)

yes (4.1.3.0)

-

G DATA InternetSecurity [Antivirus]

18.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

G DATA TotalCare [Antivirus]

18.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

Grisoft, Inc.

Antivirussystem AVG 6.0

6.x

yes (3.5.0)

yes (3.5.0)

-

AVG 6.0 Anti-Virus - FREE Edition

6.x

yes (3.5.0)

yes (3.5.0)

-

AVG 6.0 Anti-Virus System

6.x

yes (3.5.0)

yes (3.5.0)

-

AVG 7.5

7.x

yes (4.0.4.0)

yes (4.0.4.0)

yes

AVG Antivirensystem 7.0

7.x

yes (3.5.0)

yes (3.5.0)

yes

AVG Anti-Virus 7.0

7.x

yes (3.5.0)

yes (3.5.0)

yes

AVG Anti-Virus 7.1

7.x

yes (3.6.3.0)

yes (3.6.3.0)

yes

AVG Free Edition

7.x

yes (3.5.0)

yes (3.5.0)

yes

HAURI, Inc.

ViRobot Desktop

5.0.x

yes (4.0.5.1)

yes (4.0.5.1)

-

ViRobot Desktop

5.x

yes (4.1.3.0)

yes (4.1.3.0)

-

H+BEDV Datentechnik GmbH

AntiVir PersonalEdition Classic Windows

7.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

AntiVir/XP

6.x

yes (3.5.0)

yes (3.5.0)

yes

IKARUS Software GmbH

IKARUS Guard NT

2.x

yes (4.0.6.0)

yes (4.0.6.0)

-

IKARUS virus utilities

5.x

yes (4.0.6.0)

yes (4.0.6.0)

-

Internet Security Systems, Inc.

Proventia Desktop

8.x

yes (4.0.6.0)

-

-

Proventia Desktop

9.x

yes (4.0.6.0)

yes (4.0.6.0)

-

Jiangmin, Inc.

Jiangmin AntiVirus KV2007

10.x

yes (4.1.3.0)

-

yes

Kaspersky Labs

Kaspersky Anti-Virus 2006 Beta

6.0.x

yes (3.5.8)

yes (3.5.8)

-

Kaspersky Anti-Virus 6.0

6.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Kaspersky Anti-Virus 6.0 Beta

6.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Kaspersky Anti-Virus 7.0

7.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

Kaspersky Anti-Virus for Windows File Servers

5.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

Kaspersky Anti-Virus for Windows File Servers

6.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

Kaspersky Anti-Virus for Windows Servers

6.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

Kaspersky Anti-Virus for Windows Workstations

5.0.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

Kaspersky Anti-Virus for Windows Workstations

6.x

yes (4.0.6.0)

yes (4.0.6.0)

yes

Kaspersky Anti-Virus for Workstation

5.0.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

Kaspersky Anti-Virus Personal

4.5.x

yes (3.5.0)

yes (3.5.0)

yes

Kaspersky Anti-Virus Personal

5.0.x

yes (3.5.0)

yes (3.5.0)

yes

Kaspersky Anti-Virus Personal Pro

5.0.x

yes (3.5.11)

yes (3.5.11)

yes

Kaspersky Internet Security

6.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Kaspersky Internet Security 7.0

7.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

Kaspersky Internet Security 8.0

8.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

Kaspersky(TM) Anti-Virus Personal 4.5

4.5.x

yes (3.5.0)

yes (3.5.0)

yes

Kaspersky(TM) Anti-Virus Personal Pro 4.5

4.5.x

yes (3.5.0)

yes (3.5.0)

yes

Kingsoft Corp.

Kingsoft AntiVirus 2004

2004.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Kingsoft AntiVirus 2007 Free

2007.x

yes (4.1.3.2)

yes (4.1.3.2)

-

Kingsoft Internet Security

7.x

yes (3.6.5.0)

yes (3.6.5.0)

yes

Kingsoft Internet Security 2006 +

2006.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

McAfee, Inc.

McAfee VirusScan Enterprise

8.x

yes (3.6.5.0)

yes (3.6.5.0)

yes

McAfee VirusScan Home Edition

7.x

yes (4.0.6.1)

yes (4.0.6.1)

yes

McAfee VirusScan Professional

8.x

yes (3.5.1)

yes (3.5.1)

yes

McAfee VirusScan Professional

8xxx

yes (3.5.0)

yes (3.5.0)

yes

McAfee VirusScan Professional

9.x

yes (3.5.1)

yes (3.5.1)

yes

McAfee VirusScan Professional Edition

7.x

yes (3.5.0)

yes (3.5.0)

yes

Total Protection for Small Business

4.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

McAfee Internet Security 6.0

8.x

yes (3.5.4)

yes (3.5.4)

yes

McAfee Managed VirusScan

3.x

yes (3.5.8)

yes (3.5.8)

yes

McAfee Managed VirusScan

4.x

yes (4.0.4.0)

yes (4.0.4.0)

yes

McAfee VirusScan

10.x

yes (3.5.4)

yes (3.5.4)

yes

McAfee VirusScan

11.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

McAfee VirusScan

12.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

McAfee VirusScan

4.5.x

yes (3.5.0)

yes (3.5.0)

yes

McAfee VirusScan

8.x

yes (3.5.1)

yes (3.5.1)

yes

McAfee VirusScan

8xxx

yes (3.5.0)

yes (3.5.0)

yes

McAfee VirusScan

9.x

yes (3.5.1)

yes (3.5.1)

yes

McAfee VirusScan

9xxx

yes (3.5.0)

yes (3.5.0)

yes

McAfee VirusScan Enterprise

7.0.x

yes (3.5.0)

yes (3.5.0)

yes

McAfee VirusScan Enterprise

7.1.x

yes (3.5.0)

yes (3.5.0)

yes

McAfee VirusScan Enterprise

7.5.x

yes (3.5.0)

yes (3.5.0)

yes

McAfee VirusScan Enterprise

8.0.x

yes (3.5.0)

yes (3.5.0)

yes

Microsoft Corp.

Microsoft Forefront Client Security

1.5.x

yes (4.0.5.0)

yes (4.0.5.0)

-

Windows Live OneCare

1.x

yes (4.1.0.0)

yes (4.1.0.0)

-

Windows Live OneCare

2.x

yes (4.1.3.2)

yes (4.1.3.2)

-

Windows OneCare Live

0.8.x

yes (3.5.11.1)

-

-

MicroWorld

eScan Anti-Virus (AV) for Windows

8.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

eScan Corporate for Windows

8.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

eScan Internet Security for Windows

8.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

eScan Professional for Windows

8.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

eScan Virus Control (VC) for Windows

8.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Norman ASA

Norman Virus Control

5.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Panda Software

Panda Antivirus 2007

2.x

yes (4.0.4.0)

yes (4.0.4.0)

-

Panda Antivirus 2008

3.x

yes (4.0.6.1)

yes (4.0.6.1)

-

Panda Antivirus 6.0 Platinum

6

yes (3.5.0)

yes (3.5.0)

yes

Panda Antivirus + Firewall 2007

6.x

yes (4.0.4.0)

yes (4.0.4.0)

yes

Panda Antivirus + Firewall 2008

7.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

Panda Antivirus Lite

1.x

yes (3.5.0)

yes (3.5.0)

-

Panda Antivirus Lite

3.x

yes (3.5.9)

yes (3.5.9)

-

Panda Antivirus Platinum

7.04.x

yes (3.5.0)

yes (3.5.0)

yes

Panda Antivirus Platinum

7.05.x

yes (3.5.0)

yes (3.5.0)

yes

Panda Antivirus Platinum

7.06.x

yes (3.5.0)

yes (3.5.0)

yes

Panda Client Shield

4.x

yes (4.0.4.0)

yes (4.0.4.0)

-

Panda Internet Security 2007

11.x

yes (4.0.4.0)

yes (4.0.4.0)

yes

Panda Internet Security 2008

12.x

yes (4.0.6.1)

yes (4.0.6.1)

yes

Panda Platinum 2005 Internet Security

9.x

yes (3.5.3)

yes (3.5.3)

yes

Panda Platinum 2006 Internet Security

10.x

yes (4.0.4.0)

yes (4.0.4.0)

yes

Panda Platinum Internet Security

8.03.x

yes (3.5.0)

yes (3.5.0)

yes

Panda Titanium 2006 Antivirus + Antispyware

5.x

yes (3.5.10.1)

yes (3.5.10.1)

yes

Panda Titanium Antivirus 2004

3.00.00

yes (3.5.0)

yes (3.5.0)

yes

Panda Titanium Antivirus 2004

3.01.x

yes (3.5.0)

yes (3.5.0)

yes

Panda Titanium Antivirus 2004

3.02.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Panda Titanium Antivirus 2005

4.x

yes (3.5.1)

yes (3.5.1)

yes

Panda TruPrevent Personal 2005

2.x

yes (3.5.3)

yes (3.5.3)

yes

Panda TruPrevent Personal 2006

3.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

WebAdmin Client Antivirus

3.x

yes (3.5.11)

yes (3.5.11)

-

PC Tools Software

PC Tools AntiVirus 2.0

2.x

yes (4.1.3.0)

yes (4.1.3.0)

-

PC Tools AntiVirus 2007

3.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

PC Tools AntiVirus 2008

4.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

PC Tools Internet Security [Antivirus]

5.x

yes (4.1.3.0)

yes (4.1.3.0)

-

PC Tools Spyware Doctor [Antivirus]

5.x

yes (4.1.3.2)

-

-

Spyware Doctor [Antivirus]

5.x

yes (4.1.3.2)

yes (4.1.3.2)

-

ThreatFire 3.0

3.x

yes (4.1.3.0)

-

-

Radialpoint Inc.

Radialpoint Security Services Virus Protection

6.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

Radialpoint Virus Protection

5.x

yes (4.0.5.1)

yes (4.0.5.1)

-

Zero-Knowledge Systems Radialpoint Security Services Virus Protection

6.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

SalD Ltd.

Dr.Web

4.32.x

yes (3.5.0)

yes (3.5.0)

yes

Dr.Web

4.33.x

yes (3.5.11.1)

yes (3.5.11.1)

yes

Dr.Web

4.44.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

Sereniti, Inc.

Sereniti Antivirus

1.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

The River Home Network Security Suite

1.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

SOFTWIN

BitDefender 8 Free Edition

8.x

yes (3.5.8)

yes (3.5.8)

-

BitDefender 8 Professional Plus

8.x

yes (3.5.0)

yes (3.5.0)

-

BitDefender 8 Standard

8.x

yes (3.5.0)

yes (3.5.0)

-

BitDefender 9 Internet Security AntiVirus

9.x

yes (3.5.11.1)

yes (3.5.11.1)

-

BitDefender 9 Professional Plus

9.x

yes (3.5.8)

yes (3.5.8)

yes

BitDefender 9 Standard

9.x

yes (3.5.8)

yes (3.5.8)

yes

BitDefender Antivirus 2008

11.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

BitDefender Antivirus Plus v10

10.x

yes (4.0.4.0)

yes (4.0.4.0)

yes

BitDefender Antivirus v10

10.x

yes (4.0.4.0)

yes (4.0.4.0)

yes

BitDefender Client Professional Plus

8.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

BitDefender Free Edition

7.x

yes (3.5.0)

yes (3.5.0)

-

BitDefender Free Edition v10

10.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

BitDefender Internet Security 2008

11.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

BitDefender Internet Security v10

10.x

yes (4.0.4.0)

yes (4.0.4.0)

yes

BitDefender Professional Edition

7.x

yes (3.5.0)

yes (3.5.0)

-

BitDefender Standard Edition

7.x

yes (3.5.0)

yes (3.5.0)

-

BitDefender Total Security 2008

11.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

Sophos Plc.

Sophos Anti-Virus

3.x

yes (3.5.3)

yes (3.5.3)

-

Sophos Anti-Virus

4.x

yes (3.6.3.0)

yes (3.6.3.0)

-

Sophos Anti-Virus

5.x

yes (3.5.3)

yes (3.5.3)

yes

Sophos Anti-Virus

6.x

yes (4.0.1.0)

yes (4.0.1.0)

yes

Sophos Anti-Virus

7.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

Sophos Anti-Virus version 3.80

3.8

yes (3.5.0)

yes (3.5.0)

-

Symantec Corp.

Norton 360 (Symantec Corporation)

1.x

yes (4.1.1.0)

yes (4.1.1.0)

yes

Norton 360 (Symantec Corporation)

2.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

Norton AntiVirus

10.x

yes (3.5.0)

yes (3.5.0)

yes

Norton AntiVirus

14.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Norton AntiVirus

15.x

yes (4.0.6.1)

yes (4.0.6.1)

yes

Norton AntiVirus 2002

8.00.x

yes (3.5.0)

yes (3.5.0)

yes

Norton AntiVirus 2002

8.x

yes (3.5.1)

yes (3.5.1)

yes

Norton AntiVirus 2002 Professional

8.x

yes (3.5.0)

yes (3.5.0)

yes

Norton AntiVirus 2002 Professional Edition

8.x

yes (3.5.0)

yes (3.5.0)

yes

Norton AntiVirus 2003

9.x

yes (3.5.0)

yes (3.5.0)

yes

Norton AntiVirus 2003 Professional

9.x

yes (3.5.0)

yes (3.5.0)

yes

Norton AntiVirus 2003 Professional Edition

9.x

yes (3.5.0)

yes (3.5.0)

yes

Norton AntiVirus 2004

10.x

yes (3.5.0)

yes (3.5.0)

yes

Norton AntiVirus 2004 Professional

10.x

yes (3.5.0)

yes (3.5.0)

yes

Norton AntiVirus 2004 Professional Edition

10.x

yes (3.5.0)

yes (3.5.0)

yes

Norton AntiVirus 2004 (Symantec Corporation)

10.x

yes (3.5.0)

yes (3.5.0)

yes

Norton AntiVirus 2005

11.0.x

yes (3.5.0)

yes (3.5.0)

yes

Norton AntiVirus 2006

12.0.x

yes (3.5.5)

yes (3.5.5)

yes

Norton AntiVirus 2006

12.x

yes (3.5.5)

yes (3.5.5)

yes

Norton AntiVirus Corporate Edition

7.x

yes (3.5.1)

yes (3.5.1)

yes

Norton Internet Security

7.x

yes (3.5.0)

yes (3.5.0)

yes

Norton Internet Security

8.0.x

yes (3.5.0)

yes (3.5.0)

yes

Norton Internet Security

8.2.x

yes (3.5.1)

yes (3.5.1)

yes

Norton Internet Security

8.x

yes (3.5.1)

yes (3.5.1)

yes

Norton Internet Security

9.x

yes (3.5.10.1)

yes (3.5.10.1)

yes

Norton Internet Security (Symantec Corporation)

10.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Norton Security Scan

1.x

yes (4.1.3.0)

yes (4.1.3.0)

-

Norton SystemWorks 2003

6.x

yes (3.5.3)

yes (3.5.3)

yes

Norton SystemWorks 2004 Professional

7.x

yes (3.5.4)

yes (3.5.4)

yes

Norton SystemWorks 2005

8.x

yes (3.5.3)

yes (3.5.3)

yes

Norton SystemWorks 2005 Premier

8.x

yes (3.5.3)

yes (3.5.3)

yes

Norton SystemWorks 2006 Premier

12.0.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Symantec AntiVirus

10.x

yes (3.5.3)

yes (3.5.3)

yes

Symantec AntiVirus

9.x

yes (3.5.0)

yes (3.5.0)

yes

Symantec AntiVirus Client

8.x

yes (3.5.0)

yes (3.5.0)

yes

Symantec AntiVirus Server

8.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Symantec AntiVirus Win64

10.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

Symantec Client Security

10.x

yes (3.5.3)

yes (3.5.3)

yes

Symantec Client Security

9.x

yes (3.5.0)

yes (3.5.0)

yes

Symantec Endpoint Protection

11.x

yes (4.0.6.1)

yes (4.0.6.1)

yes

Symantec Scan Engine

5.x

yes (4.0.5.1)

yes (4.0.5.1)

-

Trend Micro, Inc.

PC-cillin 2002

9.x

yes (3.5.1)

yes (3.5.1)

-

PC-cillin 2003

10.x

yes (3.5.0)

yes (3.5.0)

-

ServerProtect

5.x

yes (4.1.0.0)

yes (3.6.5.0)

-

Trend Micro Antivirus

11.x

yes (3.5.0)

yes (3.5.0)

yes

Trend Micro AntiVirus

15.x

yes (3.6.5.0)

yes (3.6.5.0)

-

Trend Micro AntiVirus

16.x

yes (4.1.3.0)

yes (4.1.3.0)

-

Trend Micro Client/Server Security

6.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Trend Micro Client/Server Security Agent

7.x

yes (3.5.12)

yes (3.5.12)

yes

Trend Micro HouseCall

1.x

yes (4.0.1.0)

yes (4.0.1.0)

-

Trend Micro Internet Security

11.x

yes (3.5.0)

yes (3.5.0)

yes

Trend Micro Internet Security

12.x

yes (3.5.0)

yes (3.5.0)

-

Trend Micro Internet Security

16.x

yes (4.1.3.0)

yes (4.1.3.0)

-

Trend Micro OfficeScan Client

5.x

yes (3.5.1)

yes (3.5.1)

yes

Trend Micro OfficeScan Client

6.x

yes (3.5.1)

yes (3.5.1)

yes

Trend Micro OfficeScan Client

7.x

yes (3.5.3)

yes (3.5.3)

yes

Trend Micro OfficeScan Client

8.x

yes (4.0.5.0)

yes (4.0.5.0)

yes

Trend Micro PC-cillin 2004

11.x

yes (3.5.0)

yes (3.5.0)

yes

Trend Micro PC-cillin Internet Security 12

12.x

yes (4.0.1.0)

yes (4.0.1.0)

-

Trend Micro PC-cillin Internet Security 14

14.x

yes (4.0.1.0)

yes (4.0.1.0)

yes

Trend Micro PC-cillin Internet Security 2005

12.x

yes (3.5.3)

yes (3.5.3)

yes

Trend Micro PC-cillin Internet Security 2006

14.x

yes (3.5.8)

yes (3.5.8)

yes

Trend Micro PC-cillin Internet Security 2007

15.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

VCOM

Fix-It Utilities 7 Professional [AntiVirus]

7.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

Fix-It Utilities 8 Professional [AntiVirus]

8.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

SystemSuite 7 Professional [AntiVirus]

7.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

SystemSuite 8 Professional [AntiVirus]

8.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

VCOM Fix-It Utilities Professional 6 [AntiVirus]

6.x

yes (4.0.6.1)

yes (4.0.6.1)

yes

VCOM SystemSuite Professional 6 [AntiVirus]

6.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

Verizon

Verizon Internet Security Suite Anti-Virus

5.x

yes (4.0.5.1)

yes (4.0.5.1)

-

VirusBuster Ltd.

VirusBuster for Windows Servers

5.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

VirusBuster Professional

5.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

Webroot Software, Inc.

Webroot Spy Sweeper Enterprise Client with AntiVirus

4.x

yes (4.1.3.2)

-

-

Webroot Spy Sweeper with AntiVirus

5.x

yes (4.1.3.0)

yes (4.1.3.0)

-

Yahoo!, Inc.

AT&T Yahoo! Online Protection [AntiVirus]

7.x

yes (4.0.6.1)

yes (4.0.6.1)

yes

SBC Yahoo! Anti-Virus

7.x

yes (3.5.10.1)

yes (3.5.10.1)

yes

Verizon Yahoo! Online Protection [AntiVirus]

7.x

yes (4.0.6.1)

yes (4.0.6.1)

yes

Zone Labs LLC

ZoneAlarm Anti-virus

6.x

yes (3.5.5)

yes (3.5.5)

-

ZoneAlarm Security Suite

5.x

yes (3.5.0)

yes (3.5.0)

-

ZoneAlarm Security Suite

6.x

yes (3.5.5)

yes (3.5.5)

-

ZoneAlarm with Antivirus

5.x

yes (3.5.0)

yes (3.5.0)

-

1 "Yes" in the AV Checks Supported columns indicates the Agent supports the AV Rule check for the product starting from the version of the Agent listed in parentheses (CAM automatically determines whether to use Def Version or Def Date for the check).

2 The Live Update column indicates whether the Agent supports live update for the product via the Agent Update button (configured by AV Definition Update requirement type). For products that support "Live Update," the Agent launches the update mechanism of the AV product when the Update button is clicked. For products that do not support this feature, the Agent displays a message popup. In this case, administrators can configure a different requirement type (such as "Local Check") to present alternate update instructions to the user.

3 For Symantec Enterprise products, the Clean Access Agent can initiate AV Update when Symantec Antivirus is in unmanaged mode. If using Symantec AV in managed mode, the administrator must allow/deny managed clients to run LiveUpdate via the Symantec management console (right-click the primary server, go to All Tasks -> Symantec Antivirus, select Definition Manager, and configure the policy to allow clients to launch LiveUpdate for agents managed by that management server.) If managed clients are not allowed to run LiveUpdate, the update button will be disabled on the Symantec GUI on the client, and updates can only be pushed from the server.


Clean Access AV Support Chart (Windows ME/98)

Table 7 lists Windows ME/98 Supported AV Products as of the latest release of the Cisco NAC Appliance software. (See Table 6 for Windows Vista/XP/2000.)

Table 7 Clean Access Antivirus Product Support Chart (Windows ME/98)
Version 68, 4.1.3.2 Agent, CAM/CAS Release 4.1.3.1 (Sheet 1 of 2)

Product Name
Product Version
AV Checks Supported
(Minimum Agent Version Needed)1
Live Update 2 , 3
Installation
Virus Definition
Beijing Rising Technology Corp. Ltd.

Rising Antivirus Software AV

18.x

yes (4.0.5.0)

yes (4.0.5.0)

yes

Computer Associates International, Inc.

CA eTrust Antivirus

7.x

yes (3.5.3)

yes (3.5.3)

yes

eTrust EZ Antivirus

6.1.x

yes (3.5.0)

yes (3.5.8)

yes

eTrust EZ Antivirus

6.2.x

yes (3.5.0)

yes (3.5.0)

yes

eTrust EZ Antivirus

6.4.x

yes (3.5.0)

yes (3.5.0)

yes

eTrust EZ Antivirus

7.x

yes (3.5.3)

yes (3.5.3)

yes

eTrust EZ Armor

6.1.x

yes (3.5.3)

yes (3.5.8)

yes

McAfee, Inc.

McAfee Managed VirusScan

3.x

yes (3.5.8)

yes (3.5.8)

yes

McAfee VirusScan

10.x

yes (3.5.4)

yes (3.5.4)

yes

McAfee VirusScan

4.5.x

yes (3.5.0)

yes (3.5.0)

yes

McAfee VirusScan

8.x

yes (3.5.3)

yes (3.5.3)

yes

McAfee VirusScan

9.x

yes (3.5.3)

yes (3.5.3)

yes

McAfee VirusScan Professional

8.x

yes (3.5.3)

yes (3.5.3)

yes

McAfee VirusScan Professional

8xxx

yes (3.5.0)

yes (3.5.0)

yes

McAfee VirusScan Professional

9.x

yes (3.5.3)

yes (3.5.3)

yes

McAfee VirusScan Professional Edition

7.x

yes (3.5.0)

yes (3.5.0)

yes

SOFTWIN

BitDefender 8 Free Edition

8.x

yes (3.5.8)

yes (3.5.8)

-

BitDefender 8 Professional Plus

8.x

yes (3.5.0)

yes (3.5.0)

-

BitDefender 8 Standard

8.x

yes (3.5.0)

yes (3.5.0)

-

BitDefender 9 Professional Plus

9.x

yes (3.5.8)

yes (3.5.8)

-

BitDefender 9 Standard

9.x

yes (3.5.8)

yes (3.5.8)

-

BitDefender Free Edition

7.x

yes (3.5.0)

yes (3.5.0)

-

BitDefender Professional Edition

7.x

yes (3.5.0)

yes (3.5.0)

-

BitDefender Standard Edition

7.x

yes (3.5.0)

yes (3.5.0)

-

Symantec Corp.

Norton AntiVirus

10.x

yes (3.5.0)

yes (3.5.0)

yes

Norton AntiVirus 2002

8.00.x

yes (3.5.0)

yes (3.5.0)

yes

Norton AntiVirus 2002

8.x

yes (3.5.1)

yes (3.5.1)

yes

Norton AntiVirus 2003

9.x

yes (3.5.0)

yes (3.5.0)

yes

Norton AntiVirus 2003 Professional Edition

9.x

yes (3.5.3)

yes (3.5.3)

yes

Norton AntiVirus 2004

10.x

yes (3.5.0)

yes (3.5.0)

yes

Norton AntiVirus 2004 (Symantec Corporation)

10.x

yes (3.5.0)

yes (3.5.0)

yes

Norton AntiVirus 2005

11.0.x

yes (3.5.0)

yes (3.5.0)

yes

Norton Internet Security

8.0.x

yes (3.5.0)

yes (3.5.0)

yes

Norton Internet Security

8.x

yes (3.5.1)

yes (3.5.1)

yes

Symantec AntiVirus

10.x

yes (4.0.5.0)

yes (4.0.5.0)

yes

Symantec AntiVirus

9.x

yes (3.5.8)

yes (3.5.3)

yes

Symantec AntiVirus Client

8.x

yes (3.5.9)

yes (3.5.9)

yes

Trend Micro, Inc.

PC-cillin 2003

10.x

yes (3.5.0)

yes (3.5.0)

-

Trend Micro Internet Security

11.x

yes (3.5.0)

yes (3.5.0)

-

Trend Micro Internet Security

12.x

yes (3.5.0)

yes (3.5.0)

-

Trend Micro OfficeScan Client

7.x

yes (4.0.5.0)

yes (4.0.5.0)

-

Trend Micro PC-cillin 2004

11.x

yes (3.5.0)

yes (3.5.0)

-

Trend Micro PC-cillin Internet Security 2005

12.x

yes (3.5.3)

yes (3.5.3)

-

1 "Yes" in the AV Checks Supported columns indicates the Agent supports the AV Rule check for the product starting from the version of the Agent listed in parentheses (CAM automatically determines whether to use Def Version or Def Date for the check).

2 The Live Update column indicates whether the Agent supports live update for the product via the Agent Update button (configured by AV Definition Update requirement type). For products that support "Live Update," the Agent launches the update mechanism of the AV product when the Update button is clicked. For products that do not support this feature, the Agent displays a message popup. In this case, administrators can configure a different requirement type (such as "Local Check") to present alternate update instructions to the user.

3 For Symantec Enterprise products, the Clean Access Agent can initiate AV Update when Symantec Antivirus is in unmanaged mode. If using Symantec AV in managed mode, the administrator must allow/deny managed clients to run LiveUpdate via the Symantec management console (right-click the primary server, go to All Tasks -> Symantec Antivirus, select Definition Manager, and configure the policy to allow clients to launch LiveUpdate for agents managed by that management server.) If managed clients are not allowed to run LiveUpdate, the update button will be disabled on the Symantec GUI on the client, and updates can only be pushed from the server.


Clean Access AS Support Chart (Windows Vista/XP/2000)

Table 8 lists Windows Vista/XP/2000 Supported Antispyware Products as of the latest release of the Cisco Clean Access software.

Table 8 Clean Access Antispyware Product Support Chart (Windows Vista/XP/2000)
Version 68, 4.1.3.2 Agent, CAM/CAS Release 4.1.3.1 (Sheet 1 of 6)

Product Name
Product Version
AS Checks Supported
(Minimum Agent Version Needed)1
Live Update2
Installation
Spyware Definition
Agnitum Ltd.

Outpost Firewall Pro 2008 [AntiSpyware]

6.x

yes (4.1.3.2)

yes (4.1.3.2)

-

AhnLab, Inc.

AhnLab SpyZero 2.0

2.x

yes (3.6.0.0)

yes (3.6.0.0)

yes

AhnLab SpyZero 2007

3.x

yes (3.6.5.0)

yes (3.6.5.0)

yes

AhnLab V3 Internet Security 2007 Platinum AntiSpyware

7.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

AhnLab V3 Internet Security 2008 Platinum AntiSpyware

7.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

AhnLab V3 Internet Security 7.0 Platinum Enterprise AntiSpyware

7.x

yes (4.1.2.0)

yes (4.1.2.0)

yes

America Online, Inc.

AOL Safety and Security Center Spyware Protection

2.0.x

yes (4.1.0.0)

-

-

AOL Safety and Security Center Spyware Protection

2.1.x

yes (4.1.0.0)

yes (4.1.0.0)

-

AOL Safety and Security Center Spyware Protection

2.2.x

yes (4.1.0.0)

yes (4.1.0.0)

-

AOL Safety and Security Center Spyware Protection

2.3.x

yes (4.1.0.0)

yes (4.1.0.0)

-

AOL Safety and Security Center Spyware Protection

2.x

yes (3.6.1.0)

yes (3.6.1.0)

-

AOL Spyware Protection

1.x

yes (3.6.0.0)

yes (3.6.0.0)

-

AOL Spyware Protection

2.x

yes (3.6.0.0)

yes (4.1.3.0)

-

Anonymizer, Inc.

Anonymizer Anti-Spyware

1.x

yes (4.1.0.0)

yes (4.1.0.0)

-

Anonymizer Anti-Spyware

3.x

yes (4.1.0.0)

yes (4.1.0.0)

-

Authentium, Inc.

Cox High Speed Internet Security Suite

3.x

yes (4.0.4.0)

-

yes

AVG Technologies

AVG 8.0 [AntiSpyware]

8.x

yes (4.1.3.2)

-

yes

BellSouth

BellSouth Internet Security Anti-Spyware

5.x

yes (4.0.5.1)

yes (4.0.5.1)

-

Check Point, Inc

ZoneAlarm (AntiSpyware)

7.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

ZoneAlarm Anti-Spyware

7.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

ZoneAlarm Pro Antispyware

7.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

ZoneAlarm Security Suite Antispyware

7.x

yes (4.0.5.0)

yes (4.0.5.0)

yes

Computer Associates International, Inc.

CA eTrust Internet Security Suite AntiSpyware

10.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

CA eTrust Internet Security Suite AntiSpyware

5.x

yes (3.6.1.0)

yes (3.6.1.0)

yes

CA eTrust Internet Security Suite AntiSpyware

8.x

yes (4.1.2.0)

yes (4.1.2.0)

yes

CA eTrust Internet Security Suite AntiSpyware

9.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

CA eTrust PestPatrol

5.x

yes (3.6.1.0)

yes (4.0.6.0)

yes

CA eTrust PestPatrol Anti-Spyware

8.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

CA eTrust PestPatrol Anti-Spyware Corporate Edition

5.x

yes (3.6.0.0)

yes (3.6.0.0)

yes

PestPatrol Corporate Edition

4.x

yes (3.6.0.0)

yes (3.6.0.0)

yes

PestPatrol Standard Edition (Evaluation)

4.x

yes (3.6.0.0)

yes (3.6.0.0)

yes

EarthLink, Inc.

Aluria Security Center AntiSpyware

1.x

yes (4.1.0.0)

yes (4.1.0.0)

-

EarthLink Protection Control Center AntiSpyware

1.x

yes (3.6.0.0)

yes (3.6.0.0)

-

EarthLink Protection Control Center AntiSpyware

2.x

yes (4.0.6.0)

-

-

EarthLink Protection Control Center AntiSpyware

3.x

yes (4.1.3.0)

-

-

Primary Response SafeConnect

2.x

yes (3.6.5.0)

-

-

FaceTime Communications, Inc.

X-Cleaner Deluxe

4.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

F-Secure Corp.

F-Secure (AntiSpyware)

7.x

yes (4.1.3.0)

yes (4.1.3.0)

-

F-Secure Internet Security (AntiSpyware)

7.x

yes (4.1.3.0)

yes (4.1.3.0)

-

Grisoft, Inc.

AVG Anti-Malware [AntiSpyware]

7.x

yes (4.1.2.0)

-

-

AVG Anti-Spyware 7.5

7.x

yes (4.0.5.1)

yes (4.0.5.1)

-

iS3 Inc.

STOPzilla

5.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

Javacool Software LLC

SpywareBlaster v3.1

3.1.x

yes (3.6.0.0)

yes (3.6.0.0)

yes

SpywareBlaster v3.2

3.2.x

yes (3.6.0.0)

yes (3.6.0.0)

yes

SpywareBlaster v3.3

3.3.x

yes (3.6.0.0)

yes (3.6.0.0)

yes

SpywareBlaster v3.4

3.4.x

yes (3.6.0.0)

yes (3.6.0.0)

yes

SpywareBlaster v3.5.1

3.5.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Kingsoft Corp.

Kingsoft AntiSpyware 2007 Free

2007.x

yes (4.1.3.2)

yes (4.1.3.2)

-

Kingsoft Internet Security [AntiSpyware]

7.x

yes (4.0.6.1)

yes (4.0.6.1)

yes

Lavasoft, Inc.

Ad-Aware 2007

7.x

yes (4.1.3.0)

-

-

Ad-Aware 2007 Professional

7.x

yes (4.0.6.1)

-

yes

Ad-aware 6 Professional

6.x

yes (3.6.0.0)

yes (3.6.0.0)

-

Ad-Aware SE Personal

1.x

yes (3.6.0.0)

yes (3.6.0.0)

-

Ad-Aware SE Professional

1.x

yes (3.6.1.0)

yes (3.6.1.0)

yes

McAfee, Inc.

McAfee AntiSpyware

1.5.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

McAfee AntiSpyware

1.x

yes (3.6.0.0)

yes (4.1.0.0)

yes

McAfee AntiSpyware

2.0.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

McAfee AntiSpyware

2.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

McAfee AntiSpyware Enterprise

8.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

McAfee Anti-Spyware Enterprise Module

8.0.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

McAfee AntiSpyware Enterprise Module

8.5.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

McAfee VirusScan AS

11.x

yes (4.0.6.1)

yes (4.0.6.1)

yes

McAfee VirusScan AS

12.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

MicroSmarts LLC

Spyware Begone

4.x

yes (3.6.0.0)

-

-

Spyware Begone

6.x

yes (4.1.0.0)

-

-

Spyware Begone

8.x

yes (4.1.0.0)

-

-

Spyware Begone Free Scan

7.x

yes (3.6.0.0)

-

-

Spyware Begone V7.30

7.30.x

yes (3.6.1.0)

-

-

Spyware Begone V7.40

7.40.x

yes (3.6.1.0)

-

-

Spyware Begone V7.95

7.95.x

yes (4.1.0.0)

-

-

Spyware Begone V8.20

8.20.x

yes (4.1.0.0)

-

-

Spyware Begone V8.25

8.25.x

yes (4.1.0.0)

-

-

Spyware Begone! Version 9

9.x

yes (4.1.3.2)

-

-

Microsoft Corp.

Microsoft AntiSpyware

1.x

yes (4.0.6.0)

-

yes

Windows Defender

1.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Windows Defender Vista

1.x

yes (4.0.5.0)

yes (4.0.5.0)

yes

Omniquad

Omniquad Total Security

2.0.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

Panda Software

Panda Titanium 2006 Antivirus + Antispyware [AntiSpyware]

5.x

yes (4.1.3.2)

yes (4.1.3.2)

-

PC Tools Software

PC Tools Internet Security [Antispyware]

5.x

yes (4.1.3.0)

-

-

PC Tools Spyware Doctor

5.x

yes (4.1.3.2)

-

yes

Spyware Doctor

4.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Spyware Doctor

5.x

yes (4.0.6.0)

-

yes

Spyware Doctor 3.0

3.x

yes (3.6.0.0)

yes (3.6.0.0)

yes

Spyware Doctor 3.1

3.x

yes (3.6.0.0)

yes (3.6.0.0)

yes

Spyware Doctor 3.2

3.x

yes (3.6.0.0)

yes (3.6.0.0)

yes

Spyware Doctor 3.5

3.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Spyware Doctor 3.8

3.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Spyware Doctor [AntiSpyware]

5.x

yes (4.1.3.2)

-

yes

Prevx Ltd.

Prevx1

1.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Prevx1

2.x

yes (4.1.0.0)

yes (4.1.0.0)

yes

Prevx Home

2.x

yes (3.6.0.0)

yes (3.6.0.0)

-

Radialpoint Inc.

Radialpoint Security Services Spyware Protection

6.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

Radialpoint Spyware Protection

5.x

yes (4.0.5.1)

yes (4.0.5.1)

-

Zero-Knowledge Systems Radialpoint Security Services Spyware Protection

6.x

yes (4.0.6.0)

yes (4.0.6.0)

yes

Safer Networking Ltd.

Spybot - Search & Destroy 1.3

1.3

yes (3.6.0.0)

yes (3.6.0.0)

yes

Spybot - Search & Destroy 1.4

1.4

yes (3.6.0.0)

yes (3.6.0.0)

yes

Spybot - Search & Destroy 1.5

1.x

yes (4.0.6.1)

yes (4.0.6.1)

-

Sereniti, Inc.

Sereniti Antispyware

1.x

yes (4.0.6.0)

-

yes

The River Home Network Security Suite Antispyware

1.x

yes (4.0.6.0)

-

yes

SOFTWIN

BitDefender 9 Antispyware

9.x

yes (4.1.0.0)

yes (4.1.0.0)

-

BitDefender 9 Internet Security AS

9.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

BitDefender Antivirus Plus v10 AS

10.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

BitDefender Antivirus v10 AS

10.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

BitDefender Internet Security v10 AS

10.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

Sunbelt Software

CounterSpy Enterprise Agent

1.8.x

yes (4.0.6.0)

-

-

CounterSpy Enterprise Agent

2.0.x

yes (4.1.3.0)

-

-

Sunbelt CounterSpy

1.x

yes (3.6.0.0)

-

yes

Sunbelt CounterSpy

2.x

yes (4.0.6.0)

-

yes

Symantec Corp.

Norton Internet Security AntiSpyware

15.x

yes (4.1.3.0)

-

-

Norton Spyware Scan

2.x

yes (4.1.0.0)

yes (4.1.0.0)

-

Trend Micro, Inc.

Trend Micro Anti-Spyware

3.5.x

yes (4.0.5.1)

yes (4.0.5.1)

-

Trend Micro Anti-Spyware

3.x

yes (3.6.0.0)

-

-

Trend Micro PC-cillin Internet Security 2007 AntiSpyware

15.x

yes (4.1.0.0)

yes (4.1.3.2)

yes

VCOM

Fix-It Utilities 7 Professional [AntiSpyware]

7.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

Fix-It Utilities 8 Professional [AntiSpyware]

8.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

SystemSuite 7 Professional [AntiSpyware]

7.x

yes (4.0.5.1)

yes (4.0.5.1)

yes

SystemSuite 8 Professional [AntiSpyware]

8.x

yes (4.1.3.2)

yes (4.1.3.2)

yes

VCOM Fix-It Utilities Professional 6 [AntiSpyware]

6.x

yes (4.0.6.1)

yes (4.0.6.1)

yes

VCOM SystemSuite Professional 6 [AntiSpyware]

6.x

yes (4.1.3.0)

yes (4.1.3.0)

yes

Verizon

Verizon Internet Security Suite Anti-Spyware

5.x

yes (4.0.5.1)

yes (4.0.5.1)

-

Webroot Software, Inc.

Spy Sweeper

3.x

yes (3.6.0.0)

-

-

Spy Sweeper

4.x

yes (3.6.0.0)

-

-

Spy Sweeper

5.0.x

yes (4.1.3.0)

-

-

Spy Sweeper

5.x

yes (4.1.0.0)

-

-

Webroot Spy Sweeper Enterprise Client

1.x

yes (3.6.0.0)

-

-

Webroot Spy Sweeper Enterprise Client

2.x

yes (3.6.1.0)

-

-

Webroot Spy Sweeper Enterprise Client

3.5.x

yes (4.1.3.2)

-

-

Webroot Spy Sweeper Enterprise Client

3.x

yes (4.0.5.1)

-

-

Yahoo!, Inc.

AT&T Yahoo! Online Protection

2006.x

yes (4.0.6.1)

yes (4.0.6.1)

yes

CA Yahoo! Anti-Spy

2.x

yes (4.1.3.2)

-

-

SBC Yahoo! Applications

2005.x

yes (3.6.0.0)

yes (3.6.0.0)

yes

Verizon Yahoo! Online Protection

2005.x

yes (4.0.6.1)

yes (4.0.6.1)

yes

Yahoo! Anti-Spy

1.x

yes (3.6.0.0)

yes (3.6.0.0)

-

Zone Labs LLC

Integrity Agent

6.x

yes (4.1.2.0)

yes (4.1.2.0)

-

1 "Yes" in the AS Checks Supported columns indicates the Agent supports the AS Rule check for the product starting from the version of the Agent listed in parentheses (CAM automatically determines whether to use Def Version or Def Date for the check).

2 The Live Update column indicates whether the Agent supports live update for the product via the Agent Update button (configured by AS Definition Update requirement type). For products that support "Live Update," the Agent launches the update mechanism of the AS product when the Update button is clicked. For products that do not support this feature, the Agent displays a message popup. In this case, administrators can configure a different requirement type (such as "Local Check") to present alternate update instructions to the user.


Supported AV/AS Product List Version Summary

Table 9 details enhancements made per version of the Supported Antivirus/Antispyware Product List. See Clean Access Supported AV/AS Product List for the latest Supported AV list as of the latest release. See New and Changed Information for the release feature list.

Table 9 Supported AV/AS Product List Versions 

Version
Enhancements

Release 4.1.3.1—4.1.3.2/4.1.3.1/4.1.3.0 Agents

Version 68

Added New AV Products (Windows Vista/XP/2000):

AVG 8.0 [AntiVirus], 8.x

BullGuard 8.0, 8.x

Quick Heal AntiVirus Lite, 9.5.x

Quick Heal AntiVirus Plus, 9.5.x

ZoneAlarm Anti-virus, 7.0.x

ZoneAlarm (AntiVirus), 7.0.x

ZoneAlarm Security Suite Antivirus, 7.0.x

NOD32 antivirus system, x

NOD32 Antivirus System, x

NOD32 antivirus System, x

ESET NOD32 Antivirus, 3.x

F-Secure Anti-Virus for Windows Servers, 5.x

Kaspersky Anti-Virus for Windows File Servers, 6.x

Kaspersky Anti-Virus for Windows Servers, 6.x

Kaspersky Internet Security 8.0, 8.x

Kingsoft AntiVirus 2007 Free, 2007.x

Windows Live OneCare, 2.x

PC Tools AntiVirus 2008, 4.x

PC Tools Spyware Doctor [Antivirus], 5.x

Spyware Doctor [Antivirus], 5.x

BitDefender Free Edition v10, 10.x

Norton 360 (Symantec Corporation), 2.x

Fix-It Utilities 8 Professional [AntiVirus], 8.x

SystemSuite 8 Professional [AntiVirus], 8.x

VirusBuster for Windows Servers, 5.x

VirusBuster Professional, 5.x

Webroot Spy Sweeper Enterprise Client with AntiVirus, 4.x

Version 68 (continued)

Added New AS Products (Windows Vista/XP/2000):

Outpost Firewall Pro 2008 [AntiSpyware], 6.x

AVG 8.0 [AntiSpyware], 8.x

STOPzilla, 5.x

Kingsoft AntiSpyware 2007 Free, 2007.x

Spyware Begone! Version 9, 9.x

Panda Titanium 2006 Antivirus + Antispyware [AntiSpyware], 5.x

PC Tools Spyware Doctor, 5.x

Spyware Doctor [AntiSpyware], 5.x

BitDefender 9 Internet Security AS, 9.x

BitDefender Antivirus Plus v10 AS, 10.x

BitDefender Antivirus v10 AS, 10.x

BitDefender Internet Security v10 AS, 10.x

Fix-It Utilities 8 Professional [AntiSpyware], 8.x

SystemSuite 8 Professional [AntiSpyware], 8.x

Webroot Spy Sweeper Enterprise Client, 3.5.x

CA Yahoo! Anti-Spy, 2.x

Added Spyware definition check support:

Trend Micro PC-cillin Internet Security 2007 AntiSpyware, 15.x

Release 4.1(3)—4.1.3.1/4.1.3.0 Windows Clean Access Agents

Version 67

Added New AV Products (Windows Vista/XP/2000):

AhnLab V3 Internet Security 2007, 7.x

AhnLab V3 Internet Security 2008 Platinum, 7.x

Avira AntiVir PersonalEdition Classic, 7.x

Rising Antivirus Software AV, 20.x

CA Anti-Virus, 9.x

eTrust Antivirus, 6.0.x

EarthLink Protection Control Center AntiVirus, 3.x

F-Secure Internet Security 2005, 5.x

G DATA AntiVirus 2008, 18.x

G DATA AntiVirusKit, 17.x

G DATA InternetSecurity [Antivirus], 17.x

G DATA InternetSecurity [Antivirus], 18.x

G DATA TotalCare [Antivirus], 18.x

Version 67 (continued)

New AV Products (continued):

ViRobot Desktop, 5.x

Jiangmin AntiVirus KV2007, 10.x

Kaspersky Anti-Virus 7.0, 7.x

Kaspersky Internet Security 7.0, 7.x

McAfee VirusScan, 12.x

Panda Antivirus + Firewall 2008, 7.x

PC Tools AntiVirus 2.0, 2.x

PC Tools AntiVirus 2007, 3.x

PC Tools Internet Security [Antivirus], 5.x

ThreatFire 3.0, 3.x

Radialpoint Security Services Virus Protection, 6.x

Dr.Web, 4.44.x

BitDefender Antivirus 2008, 11.x

BitDefender Client Professional Plus, 8.x

BitDefender Internet Security 2008, 11.x

BitDefender Total Security 2008, 11.x

Norton Security Scan, 1.x

Trend Micro AntiVirus, 16.x

Trend Micro Internet Security, 16.x

VCOM SystemSuite Professional 6 [AntiVirus], 6.x

Webroot Spy Sweeper with AntiVirus, 5.x

Version 67 (continued)

Added New AS Products (Windows Vista/XP/2000):

AhnLab V3 Internet Security 2008 Platinum AntiSpyware, 7.x

CA eTrust Internet Security Suite AntiSpyware, 10.x

EarthLink Protection Control Center AntiSpyware, 3.x

F-Secure (AntiSpyware), 7.x

F-Secure Internet Security (AntiSpyware), 7.x

Ad-Aware 2007, 7.x

McAfee AntiSpyware, 2.0.x

McAfee AntiSpyware Enterprise Module, 8.5.x

McAfee VirusScan AS, 12.x

Omniquad Total Security, 2.0.x

PC Tools Internet Security [Antispyware], 5.x

Radialpoint Security Services Spyware Protection, 6.x

CounterSpy Enterprise Agent, 2.0.x

Norton Internet Security AntiSpyware, 15.x

VCOM SystemSuite Professional 6 [AntiSpyware], 6.x

Spy Sweeper


Caveats

This section describes the following caveats:

Open Caveats - Release 4.1(3)

Resolved Caveats - Windows Clean Access Agent 4.1.3.2

Resolved Caveats - Mac OS X Agent 4.1.3.1

Resolved Caveats - Release 4.1.3.1

Resolved Caveats - Cisco NAC Web Agent 4.1.3.10

Resolved Caveats - Windows Clean Access Agent 4.1.3.1

Resolved Caveats - Release 4.1(3)


Note If you are a registered cisco.com user, you can view Bug Toolkit on cisco.com at the following website:

http://www.cisco.com/pcgi-bin/Support/Bugtool/home.pl

To become a registered cisco.com user, go to the following website:

http://tools.cisco.com/RPF/register/register.do


Open Caveats - Release 4.1(3)


Note Refer to the applicable version of the Release Notes for Cisco NAC Profiler for caveats related to Cisco NAC Profiler.


Table 10 List of Open Caveats (Sheet 1 of 8)

DDTS Number
Software Release 4.1(3)
Corrected
Caveat

CSCsd03509

No

The Time Servers setting is not updated in HA-Standby CAM web console

After updating the "Time Servers" setting in HA-Primary CAM, the counterpart "Time Servers" setting for the HA-Standby CAM does not get updated in the web console even though the "Time Servers" setting is updated in the HA-Standby CAM database.

CSCsd90433

No

Apache does not start on HA-Standby CAM after heartbeat link is restored.

Output from the fostate.sh command shows "My node is standby without web console, peer node is active."

CSCse86581

No

Agent does not correctly recognize def versions on the following Trend AV products:

PC-cillin Internet Security 2005

PC-cillin Internet Security 2006

OfficeScan Client

Tested Clients:

PC-cillin Internet Security 2006 (English) on US-English Windows 2000 SP4

OfficeScan Client (English) on US-English Windows 2000 SP4

VirusBaster 2006 Internet Security (Japanese) on Japanese Windows XP SP2

VirusBaster Corporate Edition (Japanese) on Japanese Windows XP SP2

CSCsg07369

No

Incorrect "IP lease total" displayed on editing manually created subnets

Steps to reproduce:

1. Add a Managed Subnet having at least 2500+ IP addresses (for example 10.101.0.1/255.255.240.0) using CAM web page Device Management > Clean Access Servers > Manage [IP Address] > Advanced > Managed Subnet.

2. Create a DHCP subnet with 2500+ hosts using CAM web page Device Management > Clean Access Servers > Manage [IP Address] > Network > DHCP > Subnet List > New.

3. Edit the newly created subnet using CAM web page Device Management > Clean Access Servers > Manage [IP Address] > Network > DHCP > Subnet List > Edit.

4. Click Update. The CAM displays a warning informing the administrator that the current IP Range brings IP lease total up to a number that is incorrect. The CAM counts the IP address in the subnet twice, creating the incorrect count.

The issue is judged to be cosmetic and does not affect DHCP functionality.

CSCsg66511

No

Configuring HA-failover synchronization settings on Secondary CAS takes an extremely long time

Once you have configured the Secondary CAS HA attributes and click Update, it can take around 3 minutes for the browser to get the response from the server. (Configuring HA-failover synchronization on the Primary CAS is nearly instantaneous.)

CSCsh77730

No

Clean Access Agent locks up when greyed out OK button is pressed

The Clean Access Agent locks up when the client machine refreshes its IP address. This only occurs when doing an IP release/renew, so the CAS must be in an OOB setup.

If the Automatically close login success screen after <x> secs option is enabled and the duration set to 0 (instantaneous) in the Clean Access > General Setup > Agent Login page and the user clicks on the greyed out OK button while the IP address is refreshing, the Clean Access Agent locks up after refreshing the IP address. The IP address is refreshed and everything else on the client machine works, but the user cannot close the Clean Access Agent without exiting via the system tray icon, thus "killing" the Agent process.

Workaround: Either uncheck the box or set that timer to a non-zero value. If it is set to anything else, and the user hits the greyed out OK button while the IP is refreshing, then the Agent window closes successfully.

CSCsi07595

No

DST fix will not take effect if generic MST, EST, HST, etc. options are specified

Due to a Java runtime implementation, the DST 2007 fix does not take effect for Cisco NAC Appliances that are using generic time zone options such as "EST," "HST," or "MST" on the CAM/CAS UI time settings.

Workaround

If your CAM/CAS machine time zone setting is currently specified via the UI using a generic option such as "EST," "HST," or "MST." change this to a location/city combination, such as "America/Denver."

Note CAM/CAS machines using time zone settings specified by the "service perfigo config" script or specified as location/city combinations in the UI, such as "America/Denver" are not affected by this issue.

CSCsk55292

No

Agent not added to system tray during boot up

When the Agent is installed on a Windows client, the Start menu is updated and Windows tries to contact AD (in some cases where the AD credentials are expired) to refresh the Start menu.

Due to the fact that the client machine is still in the Unauthenticated role, AD cannot be contacted and an approximately 60 second timeout ensues, during which the Windows taskbar elements (Start menu, System Tray, and Task Bar) are locked. As a result, the Agent displays a "Failed to add Clean Access Agent icon to taskbar status area" error message.

Workaround

Allow AD traffic through the CAS for clients in the Unauthenticated role.

Try to start the Agent manually after the install and auto load process fails.

CSCsk58244

No

Clean Access Report for WSUS shows failed

This situation applies to Windows XP and Windows Vista client machines. The Agent report on the CAM does not show any on the updates required for the client.

CSCsl00736

No

Download of the Cisco NAC Web Agent fails if the link speed is below 50Kbits/s

Note Cisco does not recommend using the Cisco NAC Web Agent on client machines connecting with link speeds slower than 56Kbits/s.

CSCsl13782

No

Microsoft Internet Explorer 7.0 browser pop-ups on Windows Vista launched from the Summary Report appear behind the Summary Report window

This is also seen when you click on the Policy link in the Policy window. This issue appears on Vista Ultimate and Vista Home, but is not seen with Firefox or on Internet Explorer versions running in Windows 2000 or Windows XP.

Note This problem only happens when a Google tool bar is installed and enabled in Internet Explorer.

CSCsl71585

No

DHCP status does not display non-restricted scope with Relay IP restriction

When a DHCP range with no restrictions and a DHCP range with a Relay-IP restriction are created using the Clean Access Manager (CAM) GUI, the DHCP range with no restrictions does not display.

Steps to reproduce:

1. Create a DHCP scope with no restriction, either VLAN ID or Relay-IP on the CAS using the CAM GUI.
2. Add a static route on the CAS using the CAM GUI.
3. Create another DHCP scope with a relay-IP restriction.
4. Go to the DHCP Status web page. The web page only displays the IPs for the relay-IP restriction and does not display the non-restricted IP scope.

Workaround: Avoid creating DHCP scopes having both no restrictions and Relay-IP restrictions.

Note The issue is known to be cosmetic and does not affect functionality.

CSCsl17379

No

Multiple Clean Access Agent pop-ups with Multi NIC in L2 VGW OOB role-based VLAN

The user sees multiple Clean Access Agent login dialogs with two or more active NICs on the same client machine pointing to the Unauthenticated network access point (eth1 IP address).

After the first Clean Access Agent pops up and the user logs in, a second Agent login dialog pops up. If the user logs in to this additional Agent instantiation there are now two entries for the same system with both MAC addresses in the CAM's Certified Device List and Online Users List.

Workaround

The user can manually Disable Agent login pop-up after authentication.

CSCsl22653

No

Mac OS X Agent running on 10.2 does not display green colored icons in places like the "About Us" dialog in the Finder.

CSCsl22774

No

Incorrect download filename perfigo_dm_enforce.jsp for the 10.2 version of the Mac OS X Agent

The filename for the agent download file should be "CCAAgent_MacOSX.tar," similar to that in versions 10.3, 10.4, and 10.5.

CSCsl40626

No

Cisco NAC Web Agent should handle certificate revocation dialogs similar to Clean Access Agent

Upon logging in via the Cisco NAC Web Agent (with certificate revocation turned on or with Norton 360 installed), the user is presented with a "Revocation information for the security certificate for this site is not available. Do you want to proceed?" dialog box several times (approximately 40 to 50 times). If the user clicks Yes to proceed enough times, the Web Agent fails to login and reports "You will not be allowed to access the network due to internal error. Please contact your administrator." back to the user.

CSCsl40812

No

The Refresh Windows domain group policy after login option is not functioning for Cisco NAC Web Agent

(It is working fine with the Clean Access Agent.)

This scenario was tested configuring a GPO policy for a Microsoft Internet Explorer browser title. The browser was not refreshed as expected after login in using the Web Agent.

CSCsl75403

No

MAC filter does not work for Macintosh client machines connected to the network in VPN environment

Steps to reproduce:

1. Setup a VPN environment.
2. Get the MAC address of the en0 interface of Macintosh client machine.
3. Put the MAC address in the CAM device filter list with "Deny" access type.
4. Connect the Macintosh client machine to the VPN concentrator.
5. Agent will be allowed to perform VPN SSO [or present login page if no VPN SSO is configured].
6. Traffic originating from the client machine on the untrusted network is allowed to go to the trusted network even though the MAC address of the client machine is denied in the device filter list.

CSCsl77701

No

Network Error dialog appears during CAS HA failover

When a user is logged in as ADSSO user on CAS HA system and the CAS experiences a failover event, the user sees is a pop-up message reading, "Network Error! Detail: The network cannot be accessed because your machine cannot connect to the default gateway. Please release/renew IP address manually."

This is not an error message and the user is still logged in to the system. The user simply needs to click on the Close button to continue normal operation.

CSCsl88429

No

User sees Invalid session after pressing [F5] following Temporary role time-out

When a user presses [F5] or [Refresh] to refresh the web page after the Agent Temporary role access timer has expired, the user sees an "Invalid" session message. If the user then attempts to navigate to the originally requested web address, they are prompted with the web login page again and are able to log in.

CSCsl88627

No

Description of removesubnet has "updatesubnet" in op field

The removesubnet API function description has "updatesubnet" listed in its operations field. The description should read "removesubnet."

CSCsm20254

No

CAS duplicates HSRP packets with Cisco NAC Profiler Collector Modules enabled.

Symptom

HSRP duplicate frames are sent by CAS in Real-IP Gateway with Collector modules enabled. This causes HSRP issues and the default gateway to go down.

Conditions

Real-IP Gateway and Collector modules enabled on a CAS with ETH0 and or ETH1 configured for NetWatch.

Workaround

Do not configure the CAS' ETH0 trusted interface or ETH1 untrusted interface in the NetWatch configuration settings for the CAS Collector. It is not a supported configuration.

CSCsm20655

No

Can not do a minor upgrade for Clean Access Agent from MSI package.

When CCAAgent.msi is used and the Clean Access Agent is upgraded to a minor version (e.g. 4.1.2.1 to 4.1.2.2) the following error message will be displayed:

"Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel."

Reason: Windows Installer uses only the first three fields of the product version. When a fourth field is included in the product version, the installer ignores the fourth field. For details refer to http://msdn2.microsoft.com/en-us/library/aa370859(VS.85).aspx

Workaround

Uninstall the program from Add/Remove Programs before installing it.

CSCsm25788

No

Avast 4.7 showing as not up to date with Cisco NAC Appliance Release 4.1(3)

User is told that Avast needs to be updated, but shows as up to date. This occurs when user is running Avast 4.7 and the Agent version is 4.1.3.0 or 4.1.3.1

Workaround

Create a custom check for Avast that allows the users on without verifying the definition version.

CSCsm53743

No

File ownership of Mac OS X Agent directory and related files should be corrected

File ownership of Mac OS X Agent and related files should be "root:admin."

Currently, the file ownership is with UID 505 and GID 505. Anyone able to assume this UID could potentially modify the Agent application files and introduce a security threat.

CSCsm76779

No

CSRF tag is added to CAS specific MAC Device Filter description field upon edit

Steps to reproduce:

1. Go to CAS-specific device filters in the CAM web console (Device Management > Clean Access Servers > Manage [IP_Address] > Filter > Devices).

2. Edit a device filter with the description field like
"<a href='http://www.cisco.com'>Cisco</a>"

3. Click Save. A CSRF tag is appended to (and is visible in) the hypertext entry in the device filter description field.

Subsequent entry updates also append the same CSRF tag each time the administrator edits the description. After editing the description 3 times, however, the entry can no longer be edited and the CAS returns an "Updating device MAC failed" error message.

Note This issue only addresses CAS-specific device filters and not global device filters addressed with caveat CSCsm55679.

CSCsm79088

No

Mac OS X Agent reports "Unknown user" when sending the second logout request

The Mac OS X Agent specifies an "Unknown user" when it sends a second logout request before receiving a response from the first logout request.

Steps to reproduce:

1. Log into the network using the Mac OS X Agent.

2. Right-click on Agent icon and choose Logout.

3. Repeat step 2 before receiving a response for the first logout request.

The Mac Agent displays a "Cisco Clean Access Agent is having a difficulty with the server. Unknown user." error message, resulting in a situation where the client machine no longer appears in the CAM's Online Users list even though the Agent indicates that the user is logged in. In this situation, the Mac Agent essentially "freezes" as the user is no longer able to log out, ether.


Resolved Caveats - Windows Clean Access Agent 4.1.3.2

Refer to Windows Clean Access Agent Version 4.1.3.2 for additional information.

Table 11 List of Closed Caveats (Sheet 1 of 3)

DDTS Number
Windows Clean Access Agent 4.1.3.2
Corrected
Caveat

CSCsl77778

Yes

Russian Language is not translated accurately in 4.1.3.0 Agent

Clean Access Agent version 4.1.3.0 displays English language in native Russian Windows operating systems and displays garbled Russian characters. For best results, Cisco recommends using the Russian version of the Clean Access Agent on a native Russian version of the Windows operating system.

Note This also pertains to the 4.1.1.0 Clean Access Agent.

CSCsl77801

Yes

Turkish language partially translated in 4.1.3.0 Clean Access Agent

Not all of the 4.1.3.0 Clean Access Agent dialogs related to new release 4.1(3) features (Auto-Remediation, new WSUS messages) are properly translated. Some read "Unknown String."

CSCsm04923

Yes

Windows 2000 clients are asked to log in when using a MAC address filter

This issue arises when the client machine is running the Nortel VPN software and Windows Clean Access Agent version 4.1.2.1.

CSCsm38529

Yes

A client with two active NICs faces repeated IP refresh events

Practical Scenario

1. Connect cable for the first NIC. The client is authenticated by the CAS.

2. Enable 2nd NIC. Authentication for the second NIC does not start, because the default gateway is still valid on the first active NIC.

3. The multiple NIC support feature blocks unneeded authentication.

4. Disconnect cable for the first NIC. The default gateway changes to the second NIC. However, the Agent does not send an ARP packet to the default gateway, and the client machine starts to repeatedly refresh the IP address.

The problem is not solved until the user exits and restarts the Agent or reboots the PC.

Workaround

1. Reload the Agent or PC.

2. Disable the Access to Authentication VLAN Change Detection feature.

CSCsm39238

Yes

In 4.1.3.0 and 4.1.3.1 Windows Agents, clients that fail requirements may get hung at the Login Screen with "Validating Requirements...Please Wait" showing on the Agent

This occurs when the session timer for the Agent Temporary Role is set to "Disabled," and when the user fails a requirement.

Navigate to User Management > User Roles > Schedule > Session Timer in the CAM web console and set the Session Timeout value for the Temporary Role equal to a positive integer value. The Agent allows that amount of time for the user to remediate.

In prior Agent versions, the Agent interpreted "Disabled" to mean unlimited time. However in 4.1.3.x, the Agent seems to interpret this as "0" and when the user fails a requirement, the user gets stuck because they have 0 seconds to remediate. (The remediation screen never appears and the user is stuck on the login screen.)

Note Users that pass all requirements are fine.

CSCsm54763

Yes

Symantec endpoint protection definition updates require administrator permissions.

This issue is resolved in Windows Clean Access Agent version 4.1.3.2.

Workaround

Users can manually update their endpoint protection from the Symantec software user interface.

CSCsm42572

Yes

NOD 32 antivirus fails an AV definition check even though it is up to date

This occurs when running version 4.1.3.0 of the Windows Clean Access Agent. Currently, the only workaround is to create a custom check to "allow" NOD 32 users without checking for the definition version.

CSCsm62326

Yes

The 4.1.3.0 Windows Clean Access Agent installation process returns message: "Error 1324. The path My Pictures contains an invalid character"

This occurs if the My Documents folder is mapped to a remote server to which the user does not have access in the unauthenticated role, for example: \\servername\userid\My Documents.

Workarounds

Enable off-line file access.

Allow access to the server in the unauthenticated role.

CSCsm67052

Yes

When using Clean Access Agent posture assessment with Webroot AntiSpyware Corporate Edition, the Agent incorrectly detects the AS product as an unknown AV product and does not display the correct definition information. The administrator sees the following in the user Agent report:

Client AV Info
Product ID: WmiAV
Product Name: Webroot Software Inc. unknown product
Product Version: 3.5
Virus Definition File Version:
Virus Definition File Date:

This occurs with Windows Agent versions 4.1.2.x and 4.1.3.x when used in conjunction with Webroot AntiSpyware Corporate Edition 3.5.

Workaround

Create a custom check using the following value: HKLM\\Software\\Webroot\\Enterprise\\CommAgent\\sdfv.

CSCso22399

Yes

On Windows 2000 SP4, the Clean Access Agent takes about 15 minutes to perform an IP refresh

After switching back to the Authentication VLAN when the Access to Authentication VLAN change detection feature is enabled, and the VlanDetectInterval value is set to 5 per the appropriate registry key setting, the Windows Agent can take up to 15 minutes before the client machine recognizes the VLAN change from Access back to Auth and completes the client IP refresh.

Note This issue only occurs on Windows 2000 SP4 client machines where the user does not have administrator privileges.

Workarounds

Grant users administrator access to their client machines.

Do not enable the Access to Authentication VLAN change detection feature. Instead, use port bouncing to refresh client IP addresses.

Decrease the interval or the number of times the Agent attempts to retry connection. (Cisco does not recommend this option if there are other operating systems on the network, as this may result in unwarranted IP refreshes on other client machines.)


Resolved Caveats - Mac OS X Agent 4.1.3.1

Refer to Mac OS X Clean Access Agent Version 4.1.3.1 for additional information.

Table 12 List of Closed Caveats (Sheet 1 of 3)

DDTS Number
Mac OS X Agent 4.1.3.1
Corrected
Caveat

CSCsl83353

Yes

Mac OS X Agent does not refresh icon status after disconnecting interface

The Mac OS X Agent does not refresh the tray icon status when you physically disconnect the network interface cable.

Steps to reproduce:

1. Log in to Cisco NAC Appliance using the Mac OS X Agent.

2. Disconnect the network cable from the active network interface. The Mac Agent status does not change from "Logged-in."

Note The issue is cosmetic and does not affect Agent functionality.

CSCsl88985

Yes

Mac Agent logs out user after every login once operating system mismatch is detected

The Mac OS X Clean Access Agent logs the user out after every login once the Agent detects an operating system mismatch and prompts the user with a new login dialog requesting credentials. When the user logs in again, the Agent again detects the operating system mismatch and repeats the process.

Workaround

Exit and re-launch the Clean Access Agent on Macintosh client machine.

CSCsl98060

Yes

Mac OS X Agent CPU usage spikes every few seconds

The CPU usage rises to 85-99% every few seconds, recedes, and then spikes again.

CSCsm10311

Yes

Mac OS X Agent changes Applications folder permissions to "unknown"

Installing the 4.1.3.0 Agent on a Mac client machine changes the Applications folder permissions to "Owner:unknown" with read/write access and the Application Group to "Unknown" with read only and Others to read permissions.

This issue impacts other applications already installed and can keep them from updating themselves and could even affect the stability of the Finder system application.

Note Any new additions to the Applications folder require non-root users to login as root in order to make changes.

CSCsm20813

Yes

Mac OS X Agent difficult to exit when discovery host FQDN cannot be resolved

For users attempting to log in via the Mac Agent 4.1.3.0 where the discovery host cannot be resolved, it is difficult to close/exit the Agent (or use any other menu items). In addition, a "System failed to resolve the host name!" message appears repeatedly.

Workaround

You must add an entry to /etc/hosts to resolve the host name of the CAS server correctly:

When the user first clicks on the menu, the error message appears.

If the user clicks the OK button or anywhere else on the screen (after getting the error message), the user sees the error message again.

If the user clicks on the menu without clicking anywhere else on the screen, the menu comes up (instead of the error) and the user can then quit/exit the Mac Agent.

Therefore, if you only use the mouse (and do not clear the error message by pressing enter to trigger the OK button), quitting or accessing anything else in the Mac Agent is difficult.

Note This error message makes it difficult to clear the Mac Agent from the screen and the verbiage may baffle many Mac users who do not know what "*nix" is.

CSCsm26806

Yes

The Mac OS X Agent fails to work with device filters in L3 deployment

In some deployment scenarios, the Mac Agent does not work correctly with device filters based on the ROLE or CHECK settings. Layer 3 (L3) Real-IP-mode topologies do not appear to properly obtain the MAC address of the Mac Agent and apply filter policies. A discrepancy exists in an environment with the following topology:

Client---AP---Routing Devices---CAS (Real IP)---Inside Network

where the client machine entry appears as a device filter (specifying both MAC and IP address) set to "Check" the user role, resulting in the following behavior:

Windows Agent

After connecting via wireless, the Windows Agent pops up stating that authentication is being performed via a device filter and the login session completes successfully. Once this is done, the user has full access granted by the assigned role and is not redirected (desired behavior).

Mac OS X Agent

After connecting via wireless, the Mac Agent icon turns orange, stating that the session is "Not Supported," and the user continues to receive redirects to the authentication page (user does not have the full access specified in the assigned user role).

Note If the filter is changed from "Check" to "Assign a role," the Mac Agent turns green rather than orange, but the end-user still receives redirects to the CAS authentication page for all web requests.

This issue does not occur if the Mac Agent is used in an L2 setup.

CSCsm47276

Yes

Mac OS X Agent memory usage goes up with time

To reproduce the issue, let the Mac Agent run for several hours or a day and watch the memory usage going up using the "top" system command.


Resolved Caveats - Release 4.1.3.1

Refer to Enhancements in Release 4.1.3.1 for additional information.

Table 13 List of Closed Caveats  

DDTS Number
Software Release 4.1.3.1
Corrected
Caveat

CSCsm13673

Yes

CAM 4.1(3) upgrade from release 4.0(x) and 3.6(x) takes too long with too many Agent reports

Clean Access Manager (CAM) 4.1(3) upgrade from Cisco NAC Appliance release 4.0(x) and 3.6(x) should not take too long with too many Clean Access Agent reports. The upgrade can take over 90 minutes on a Cisco NAC-3310 appliance with 30,000 Agent reports in the CAM database before the upgrade.

CSCsm27731

Yes

CAM should not send Auth VLAN set request when receiving MAC move notification

Normally, when the CAM receives a MAC move notification, the CAM consults the client database to deduce the original managed port from which the MAC address first became known on the system, and set the port VLAN to Authentication VLAN.

This operation can cause problems in certain situations. If, for example, the port over which the client first authenticated and the port to which the client is moving (per the MAC move notification SNMP trap) are same, the CAM assigns the Authentication VLAN to the port even though the client MAC address has already been certified.

Although the period of time that the port remains assigned to the Authentication VLAN is very short:

If a SWISS discovery packet is sent from the client during this period, an erroneous user login popup can appear, prompting the user to enter their login credentials.

If a DHCP packet is sent from the client during this period, the client's IP may be reassigned to the Authentication VLAN.

CSCsm55679

Yes

CSRF tag is added to a global MAC device filter's description when edited

If the description of a global MAC filter contains a single quote (`) and you edit the description entry in the CAM web console, a CSRF tag is appended to the description when you save the changes. (The same CSRF tag is appended every time you edit and save the filter from the CAM web console.)

Note This issue directly impacts Cisco NAC Profiler users as Profiler also includes a link in Filter List descriptions and, whenever you edit them, the same additional CSRF "token" is appended to the URL.


Resolved Caveats - Cisco NAC Web Agent 4.1.3.10

Refer to Cisco NAC Web Agent Version 4.1.3.10 for additional information.

Table 14 List of Closed Caveats  

DDTS Number
Cisco NAC Web Agent 4.1.3.10
Corrected
Caveat

CSCsm03961

Yes

A certificate warning dialog appears even when the root certificate is trusted

A warning message stating there is a mismatch between the website name and the certificate presented is displayed to end users when they launch the Web Agent in an environment which uses FQDN within certificates.

This condition arises because the Web Agent tries to access the CAS via IP address and the certificate CN value has a Hostname/FQDN instead of an IP address. This causes the mismatch between the URL requested and the actual Certificate presented.

Note If the URL called by the Web Agent is the CAS FQDN, the message does not appear.

Workaround

1. The warning message can be ignored and the Web Agent will still function.

2. Generate certificates with an IP address for the CN instead of FQDN/Hostname.

CSCsm17435

Yes

Audit requirements should not be visible in Web Agent reports

When an audit requirement is included in the requirement list, the result of the audit requirement should still be sent to the CAM/CAS, but should not be displayed on the Web Agent report. In addition, the audit check status should not affect the overall posture status.


Resolved Caveats - Windows Clean Access Agent 4.1.3.1

Refer to Windows Clean Access Agent Version 4.1.3.1 for additional information.

Table 15 List of Closed Caveats  

DDTS Number
Clean Access Agent 4.1.3.1
Corrected
Caveat

CSCsm05207

Yes

Windows Clean Access Agent drops network connection after delayed or no ARP reply

The Clean Access Agent transmits ARP requests for the default gateway, and if it does not receive a reply, the client automatically performs an IP address release/renew. In customer environments where the default gateway does not return an ARP reply, the 4.1.3.0 Agent can cause link-flapping.

With version 4.1.3.1 of the Windows Clean Access Agent, the new Access to Authentication VLAN switching feature is disabled by default from regkey settings from the installer (4.1.3.1).

Workaround

For Windows, there is a registry key that can be set to "not check" for the ARP replies. The same is true for Mac OS X clients.

Create one of the following registry keys:

1. Global registry key:

HKEY_LOCAL_MACHINE/SOFTWARE/Cisco/Clean Access Agent/
DWORD Value Name: VlanDetectInterval
DWORD Value Data: 0