Table Of Contents
Release Notes for Cisco NAC Appliance,
Version 4.5(1)System and Hardware Requirements
Release 4.5 and Hardware Platform Support
Release 4.5 and Cisco NAC Profiler
Supported Switches for Cisco NAC Appliance
Cisco NAC Appliance Wireless OOB Support
VPN and Wireless Components Supported for Single Sign-On (SSO)
Additional Support Information
Release 4.5 Compatibility Matrix
Release 4.5 CAM/CAS Upgrade Compatibility Matrix
Release 4.5 Clean Access Agent Upgrade Compatibility Matrix
Determining the Software Version
Enhancements in Release 4.5(1)
CAS Fallback Behavior Enhancement
CAS HA Pair Link-Detect Configuration Enhancement
DHCP Failover Behavior Enhancement
Cisco NAC Appliance API Enhancement
Supported AV/AS Product List Enhancements (Version 74)
New Features and Enhancements in Release 4.5(0)
CAM/CAS SSL Certificate Management Enhancement
CAM/CAS Software Upload Page Enhancements
Database Snapshot Upgrade Enhancement
Clean Access Manager High Availability User Interface Enhancement
CAM/CAS Support Log Level Settings Enhancement
CAM/CAS High Availability Configuration Able to Detect Hard-Drive Failure
Support for Wireless Out-of-Band Deployments
Assign Restricted VLAN for OOB Client Machines When Disconnected
Certified Device List/Online User List Enhancements
Out-of-Band Shield Enhancement
Out-of-Band Discovered Clients Cleanup
FIPS-Related Security Enhancements
Strong Password Support for Root Admin Users
External Authentication Server Support for Web Administrator Login
Support for Cisco NAC Appliance/NME-NAC Platforms Only
Default CAM Web Console Password Removed
Windows ME/98/NT OS Support Removed
Clean Access Supported AV/AS Product Lists
Supported AV/AS Product List Version Summary (Windows)
Clean Access AV Support Chart (Windows Vista/XP/2000)
Clean Access AS Support Chart (Windows Vista/XP/2000)
Supported AV/AS Product List Version Summary (Mac OS X)
Clean Access AV Support Chart (Mac OS X)
Clean Access AS Support Chart (Mac OS X)
Resolved Caveats - Release 4.5(1)
Resolved Caveats - Agent Version 4.5.2.0
Resolved Caveats - Agent Version 4.5.1.0
Resolved Caveats - Release 4.5(0)
Resolved Caveats - Agent Version 4.5.0.0
New Installation of Release 4.5
Changes for 4.5 Installation/Upgrade
Features That May Change With Upgrade
General Preparation for Upgrade
Upgrading from Customer-Supplied Hardware to Cisco NAC Appliance Hardware Platforms
Upgrade Instructions for Standalone Machines
Copy the Upgrade File to the CAS/CAM
Run Upgrade Script on the CAM/CAS
Upgrade Instructions for HA Pairs
Upgrading HA-CAM and HA-CAS Pairs
Known Issues for Cisco NAC Appliance
Known Issue with Mass DHCP Address Deletion
Known Issue for VPN SSO Following Upgrade to Release 4.5
Known Issue for DHCP Address Assignments in Layer 2 and Layer 3 Following Upgrade to Release 4.5(0)
Known Issue with DHCPD Service When Global DHCP Option is Enabled in Release 4.5(0)
Known Issues with Web Upgrade in Release 4.1(x) and Earlier
Known Issues with www.perfigo.com Root CA
Known Issue with Active HA CAM Web Console Following Failover
Known Issue with Upgrading CCA-3140 Appliance from Release 4.1(6) to 4.5
Known Issue with NAC-3310 Based Appliances
Known Issues with NAC-3300 Series Appliances and Serial HA (Failover) Connection
Known Issues with Cisco 2200/4400 Wireless LAN Controllers (Airespace WLCs)
Known Issue for Windows Vista and IP Refresh/Renew
Known Issues for Windows Vista and Agent Stub
Use "No UI" or "Reduced UI" Installation Option
"Interactive Services Dialog Detection" and Uninstall
Known Issues with MSI Agent Installer
Known Issue with Windows 2000 Clean Access Agent/Local DB Authentication
Known Issue with Windows XP/2000 and Windows Script 5.6
Vista/IE 7 Certificate Revocation List
Windows Vista Agent Stub Installer Error
Agent Stub Upgrade and Uninstall Error
Clean Access Agent AV/AS Rule Troubleshooting
Generating Windows Installer Log Files for Agent Stub
Debug Logging for Cisco NAC Appliance Agents
Generate Windows Agent Debug Log
Generate Mac OS X Agent Debug Log
Recovering Root Password for CAM/CAS
Troubleshooting CAM/CAS Certificate Issues
Troubleshooting Switch Support Issues
Other Troubleshooting Information
Obtaining Documentation and Submitting a Service Request
Release Notes for Cisco NAC Appliance,
Version 4.5(1)
Revised: July 10, 2009, OL-16409-01Contents
These release notes provide late-breaking and cumulative release information for Cisco® NAC Appliance, Release 4.5. This document describes new features, changes to existing features, limitations and restrictions ("caveats"), upgrade instructions, and related information. These release notes supplement the Cisco NAC Appliance documentation included with the distribution. Read these release notes carefully and refer to the upgrade instructions prior to installing the software.
•
System and Hardware Requirements
•
Clean Access Supported AV/AS Product Lists
•
New Installation of Release 4.5
•
Known Issues for Cisco NAC Appliance
•
Obtaining Documentation and Submitting a Service Request
Cisco NAC Appliance Releases
Cisco NAC Appliance Version Availability4.5.2.0 Cisco Clean Access Agent
July 9, 2009
4.5(1) ED
February 25, 2009
4.5 ED
October 21, 2008
Note
Any ED release of software should be utilized first in a test network before being deployed in a production network.
System and Hardware Requirements
This section describes the following:
•
Supported Switches for Cisco NAC Appliance
•
VPN and Wireless Components Supported for Single Sign-On (SSO)
•
Additional Support Information
Licensing
You must obtain and install Cisco NAC Appliance product licenses for the Clean Access Manager (CAM) and Clean Access Server (CAS) in order for your deployment to function. Install the CAM product license in the CAM License Form to initially access the CAM web admin console. Once you can access the CAM web console, upload the additional CAM HA license or CAS license(s) into the CAM (under Administration > CCA Manager > Licensing) in order to add CASs to the CAM, including the Cisco NAC network module. An OOB CAS license must be present to access the "OOB Management" module of the CAM. The Licensing page displays the types of licenses present after they are added.
Note that both CAM and CAS product licenses are generated based on the eth0 MAC address of the CAM. For High Availability (HA) pairs, you must generate an additional CAM HA license based on the eth0 MAC addresses of both Primary and Secondary CAMs and install it on the CAM whether you are adding a CAM HA-pair or CAS HA-pair.
For complete details on service contract support, obtaining new and evaluation licenses, legacy licenses and RMA, refer to Cisco NAC Appliance Service Contract / Licensing Support.
Hardware Support
This section contains the following topics:
•
Release 4.5 and Hardware Platform Support
•
Release 4.5 and Cisco NAC Profiler
•
Supported Switches for Cisco NAC Appliance
Release 4.5 and Hardware Platform Support
Starting from Cisco NAC Appliance Release 4.5, Cisco NAC Appliance software only supports and can only be installed on the following Cisco NAC Appliance platforms:
•
Cisco CCA-3140
•
Cisco NAC-3310
•
Cisco NAC-3350
•
Cisco NAC-3390
•
Cisco NAC Network Module (NME-NAC-K9)
Note
If upgrading a CCA-3140 appliance from 4.1(6) to 4.5 and later, refer to Known Issue with Upgrading CCA-3140 Appliance from Release 4.1(6) to 4.5 prior to upgrade.
Additionally, Cisco NAC Appliance Release 4.5 provides substantial changes and enhancements for product hardware support, installation and upgrade:
•
A single product installation CD (ISO) provides the option to perform CD installation on CCA-3140 and NAC-3300 series appliance platforms. The installation package detects whether a CAS, CAM or SuperCAM was previously installed along with the software version.
•
For NAC-3310 appliances, the DL140 and serial_DL140 boot installation directives are no longer required when installing the software starting from Release 4.5.
•
Web upgrade is no longer supported for upgrade to release 4.5. To upgrade your CAM and CAS from 4.1(x) or 4.0(x) releases, you must copy the cca_upgrade-4.5.1-NO-WEB.tar.gz file to each CAM and CAS appliance and run the upgrade script via the command line. Refer to Upgrading to Release 4.5 and Known Issues with Web Upgrade in Release 4.1(x) and Earlier for details.
•
Neither the installation CD nor the upgrade file will execute if attempting to run them on a non-supported platform. Refer to Changes for 4.5 Installation/Upgrade for additional details.
•
Legacy customers on non-appliance platforms who wish to upgrade to release 4.5 will need to purchase a supported platform to install the release 4.5 software. Refer to Upgrading from Customer-Supplied Hardware to Cisco NAC Appliance Hardware Platforms for additional details.
See also Features Optimized/Removed for additional information.
Cisco NAC Network Module
The Cisco NAC Network Module for Integrated Services Routers (NME-NAC-K9) is a next generation service module for the Cisco 2811, 2821, 2851, 3825, and 3845 Integrated Services Routers (ISRs) that is supported starting from Cisco NAC Appliance, Release 4.1(2) and later. The Cisco NAC network module has the same software features as the Clean Access Server on a NAC-3300 series appliance, with the exception of high availability. NME-NAC-K9 does not support failover from one module to another.
Note
Cisco NAC Network Module does not support Wireless Out-of-Band (OOB). The Wireless OOB feature introduced in Release 4.5 only supports Layer 2 OOB Virtual Gateway deployments that require no IP change. The NAC Network Module does not support this topology.
For further details, including software installation instructions, refer to Getting Started with Cisco NAC Network Modules in Cisco Access Routers.
Note
You must run the same software version (e.g. 4.5) on all CAM/CAS appliances and CAS network modules in your network.
Release 4.5 and Cisco NAC Profiler
Release 4.5 includes version 2.1.8-37 of the Cisco NAC Profiler Collector component that resides on Clean Access Server installations. When upgrading Clean Access Server appliances (standalone or HA) to release 4.5, the upgrade script will check the version of the Collector and only upgrade it if version 2.1.8-37 is not already installed.
Refer to the Release Notes for Cisco NAC Profiler for software compatibility matrixes and additional upgrade and product information.
Supported Switches for Cisco NAC Appliance
Cisco NAC Appliance Wireless OOB Support
Table 1 lists the Wireless LAN Controller platforms that Cisco NAC Appliance supports for the Wireless Out-of-Band feature. Table 2 lists the recommended IOS versions for the switches used with Cisco NAC Appliance, Release 4.5. See Support for Wireless Out-of-Band Deployments for further details.
Note
Starting from Release 4.5, administrators are able to update the object IDs (OIDs) of supported WLC platforms by performing a CAM update (under Device Management > Clean Access > Updates).
Table 2 lists the IOS versions and switch platforms that are tested and known to work with the Wireless OOB feature in Release 4.5. If you encounter issues with WOOB support and are running a minimum IOS version listed as supported for your existing hardware platform in Switch Support for Cisco NAC Appliance, you may need to upgrade the IOS on your switch to the version listed in Table 2.
See Switch Support for Cisco NAC Appliance for complete details on:
•
All switch models and NME service modules that support Out-of-Band (OOB) deployment
•
Switches/NMEs that support VGW VLAN mapping
•
Known issues with switches/WLCs
•
Troubleshooting information
VPN and Wireless Components Supported for Single Sign-On (SSO)
Table 3 lists VPN and wireless components supported for Single Sign-On (SSO) with Cisco NAC Appliance. Elements in the same row are compatible with each other.
Table 3 VPN and Wireless Components Supported By Cisco NAC Appliance For SSO
Cisco NAC Appliance Version VPN Concentrator/Wireless Controller VPN Clients4.5 and later
Cisco WiSM Wireless Service Module for the Cisco Catalyst 6500 Series Switches
N/A
Cisco 2200/4400 Wireless LAN Controllers (Airespace WLCs)1
N/A
Cisco ASA 5500 Series Adaptive Security Appliances, Version 8.0(3)7 or later2
AnyConnect
Cisco ASA 5500 Series Adaptive Security Appliances, Version 7.2(0)81 or later
•
Cisco SSL VPN Client (Full Tunnel)
•
Cisco VPN Client (IPSec)
Cisco WebVPN Service Modules for Cisco Catalyst 6500 Series Switches and Cisco 7600 Series Routers
Cisco VPN 3000 Series Concentrators, Release 4.7
Cisco PIX Firewall
1 For additional details, see also Known Issues with Cisco 2200/4400 Wireless LAN Controllers (Airespace WLCs).
2 Release 4.5 supports existing AnyConnect clients accessing the network via Cisco ASA 5500 Series devices running release 8.0(3)7 or later. For more information, see the Release Notes for Cisco NAC Appliance, Version 4.1(3), and CSCsi75507.
Note
Only the SSL Tunnel Client mode of the Cisco WebVPN Services Module is currently supported.
For further details, see the Cisco NAC Appliance - Clean Access Manager Installation and Configuration Guide, Release 4.5 and the Cisco NAC Appliance - Clean Access Server Installation and Configuration Guide, Release 4.5.
Additional Support Information
Refer to Support Information for Cisco NAC Appliance Agents for additional details related to Windows/Mac OS X/Web Agent support.
Refer to Supported Hardware and System Requirements for Cisco NAC Appliance (Cisco Clean Access) for additional information on Cisco NAC Appliance hardware platforms and support information for Cisco NAC Appliance 4.1(x) and earlier releases.
Software Compatibility
This section describes software compatibility for releases of Cisco NAC Appliance:
•
Release 4.5 Compatibility Matrix
•
Release 4.5 CAM/CAS Upgrade Compatibility Matrix
•
Release 4.5 Clean Access Agent Upgrade Compatibility Matrix
Release 4.5 Compatibility Matrix
Table 4 shows Clean Access Manager and Clean Access Server compatibility and the Clean Access Agent version supported with each release (if applicable). CAM/CAS/Agent versions displayed in the same row are compatible with one another. Cisco recommends that you synchronize your software images to match those shown as compatible in the table.
Table 4 Release 4.5 CAM/CAS/Agent Compatibility Matrix
Clean Access Manager 1 Clean Access Server 1 Cisco NAC Appliance Agents 2 Windows Mac OS X Web Agent4.5(1) 3
4.54.5(1)
4.54.5.2.0 4
4.5.1.0
4.5.0.04.5.0.0 4
4.5.1.2
4.1.7.0 5
4.1.3.0 5
-
4.1.6.0 5
4.1.3.0 5
4.1.2.2 5
1 Cisco NAC Appliance Release 4.5 only supports and can only be installed on the following Cisco NAC Appliance platforms: Cisco CCA-3140, Cisco NAC-3310, Cisco NAC-3350, Cisco NAC-3390, Cisco NAC Network Module (NME-NAC-K9). You cannot upgrade to or install release 4.5 on any other platform. See Hardware Support and Changes for 4.5 Installation/Upgrade for additional details.
2 See Cisco NAC Appliance Agents for details on each version of the Windows/Mac OS X/Web Agents.
3 When upgrading the CAM from version 4.1(1) and earlier, Agent files are automatically upgraded to the latest Agent version packaged with the CAM software image (e.g. 4.5.2.0). When upgrading the CAM from release 4.1(2) and later, the script will prompt you whether or not to upgrade the Agent files to the latest version. This allows administrators to schedule the Agent upgrade separately from the CAM/CAS server upgrade. Cisco recommends upgrading to the latest 4.5.2.0 Agent version as soon as possible.
4 4.5.x.x Windows/Mac OS X Clean Access Agents are supported on 4.1(3) and later CAM/CAS releases for basic compatibility (login/logout) and AV/AS product support. The maximum available AV/AS support is based on the maximum version of the Clean Access Agent Setup or Patch (upgrade) file uploaded to the CAM as well as the maximum version of the Agent on the client. See Support Information for Cisco NAC Appliance Agents, Release 4.5 for details. For full 4.5 features (including Mac OS posture), the 4.5.0.0 or later Agent must be run with the 4.5 CAM/CAS.
5 CAM/CAS release 4.5 supports 4.1.2.2 and later Agents for basic compatibility (login/logout) and AV/AS product support. The maximum available AV/AS support is based on the maximum version of the Clean Access Agent Setup or Patch (upgrade) file uploaded to the CAM as well as the maximum version of the Agent on the client. See Support Information for Cisco NAC Appliance Agents, Release 4.5 for details. For full 4.5 features (including Mac OS posture) and 4.5 AV/AS product support, the 4.5.x.x Agent must be run with the 4.5 CAM/CAS.
Release 4.5 CAM/CAS Upgrade Compatibility Matrix
Table 5 shows CAM/CAS upgrade compatibility. You can upgrade/migrate your CAM/CAS from the previous release(s) specified to the latest release shown in the same row. When you upgrade your system software, Cisco recommends you upgrade to the most current release available whenever possible.
Table 5 Release 4.5 CAM/CAS Upgrade Compatibility Matrix
Clean Access Manager 1 Clean Access Server 1 Upgrade From: To: Upgrade From: To:4.1(x)2
4.0(x)4.5(1)
4.54.1(x) 2
4.0(x)4.5(1) 3
4.5
1 Cisco NAC Appliance Release 4.5 only supports and can only be installed on the following Cisco NAC Appliance platforms: Cisco CCA-3140, Cisco NAC-3310, Cisco NAC-3350, Cisco NAC-3390, Cisco NAC Network Module (NME-NAC-K9). You cannot upgrade to or install release 4.5 on any other platform. See Hardware Support and Changes for 4.5 Installation/Upgrade for additional details.
2 When upgrading the CAM from version 4.1(1) and earlier, Agent files are automatically upgraded to the latest Agent version packaged with the CAM software image (e.g. 4.5.2.0). When upgrading the CAM from release 4.1(2) and later, the script will prompt you whether or not to upgrade the Agent files to the latest version. This allows administrators to schedule the Agent upgrade separately from the CAM/CAS server upgrade. Cisco recommends upgrading to the latest 4.5.2.0 Agent version as soon as possible.
3 The Clean Access Server is shipped with a default version of the Cisco NAC Profiler Collector. See Release 4.5 and Cisco NAC Profiler for details.
.
Release 4.5 Clean Access Agent Upgrade Compatibility Matrix
Table 6 shows Clean Access Agent upgrade compatibility when upgrading existing versions of the persistent Agents on clients after CAM/CAS upgrade.
Note
Auto-upgrade does not apply to the temporal Cisco NAC Web Agent, since it is updated on the CAM under Device Management > Clean Access > Updates > Update.
Refer to Support Information for Cisco NAC Appliance Agents for additional details related to Windows/Mac OS X/Web Agent support.
Table 6 Release 4.5.x.x Agent Upgrade Compatibility Matrix
Clean Access Manager 1 Clean Access Server 1 Clean Access Agent 2 Upgrade From: To Latest Compatible Windows Version: To Latest Compatible Mac OS X Version:4.5(1)
4.54.5(1)
4.54.5.0.0 6
1 Cisco NAC Appliance Release 4.5 only supports and can only be installed on the following Cisco NAC Appliance platforms: Cisco CCA-3140, Cisco NAC-3310, Cisco NAC-3350, Cisco NAC-3390, Cisco NAC Network Module (NME-NAC-K9). You cannot upgrade to or install release 4.5 on any other platform. See Hardware Support and Changes for 4.5 Installation/Upgrade for additional details.
2 See Cisco NAC Appliance Agents for details on each version of the Windows/Mac OS X/Web Agent.
3 Auto-upgrade to the latest 4.5.x.x Agent is supported from any 4.0.0.0 and later Windows Agent and any 4.1.3.0 and later Mac OS X Agent. To upgrade earlier Mac OS X Agent versions, download the Agent via web login and run the Agent installation.
4 When upgrading the CAM from version 4.1(1) and earlier, Agent files are automatically upgraded to the latest Agent version packaged with the CAM software image (e.g. 4.5.2.0). When upgrading the CAM from release 4.1(2) and later, the script will prompt you whether or not to upgrade the Agent files to the latest version. This allows administrators to schedule the Agent upgrade separately from the CAM/CAS server upgrade. Cisco recommends upgrading to the latest 4.5.2.0 Agent version as soon as possible.
5 CAM/CAS release 4.5 supports 4.1.2.2 and later Agents for basic compatibility (login/logout) and AV/AS product support. The maximum available AV/AS support is based on the maximum version of the Clean Access Agent Setup or Patch (upgrade) file uploaded to the CAM as well as the maximum version of the Agent on the client. See Support Information for Cisco NAC Appliance Agents, Release 4.5 for details. For full 4.5 features (including Mac OS posture) and 4.5 AV/AS product support, the 4.5.0.0 or later Agent must be run with the 4.5 CAM/CAS.
6 4.5.x.x Clean Access Agents are supported on 4.1(3) and later CAM/CAS releases for basic compatibility (login/logout) and AV/AS product support (Windows only). The maximum available AV/AS support is based on the maximum version of the Clean Access Agent Setup or Patch (upgrade) file uploaded to the CAM as well as the maximum version of the Agent on the client. See Support Information for Cisco NAC Appliance Agents, Release 4.5 for details. For full 4.5 features (including Mac OS posture), the 4.5.0.0 or later Agent must be run with the 4.5 CAM/CAS.
7 Cisco NAC Appliance release 4.5 no longer supports Windows ME/98/NT client operating systems and you cannot install the Windows Clean Access Agent version 4.5.0.0+ to Windows ME/98/NT client machines. For details, see Windows ME/98/NT OS Support Removed.
8 For checks/rules/requirements, version 4.1.1.0 and later Windows Agents can detect "N" (European) versions of the Windows Vista operating system, but the CAM/CAS treat "N" versions of Vista as their US counterpart.
Determining the Software Version
Clean Access Manager (CAM) Version
•
SSH or console to the machine and type: cat /perfigo/build
•
CAM web console: Administration > CCA Manager > Software Upload | Current Version
Clean Access Server (CAS) Version
•
SSH or console to the machine (or network module) and type cat /perfigo/build
•
CAS web console (https://<CAS_eth0_IP_address>/admin):
Administration > Software Upload | Current Version•
CAM web console: Device Management > CCA Servers > List of Servers > Manage [CAS_IP] > Misc > Upgrade Logs | Current Version
Cisco NAC Appliance Agent Version (Windows, Mac OS, Web Agent)
•
CAM web console: Monitoring > Summary
•
Clean Access Agent taskbar menu: right-click About for Agent version; right-click Properties for AV/AS software installed and Discovery Host (used for L3 deployments).
Cisco Clean Access Updates
•
CAM web console: Device Management > Clean Access > Updates > Summary
New and Changed Information
This section describes enhancements added to the following releases of Cisco NAC Appliance for the Clean Access Manager and Clean Access Server.
•
Enhancements in Release 4.5(1)
•
New Features and Enhancements in Release 4.5(0)
Enhancements in Release 4.5(1)
•
CAS Fallback Behavior Enhancement
•
CAS HA Pair Link-Detect Configuration Enhancement
•
DHCP Failover Behavior Enhancement
•
Cisco NAC Appliance API Enhancement
•
Supported AV/AS Product List Enhancements (Version 74)
Cisco NAC Appliance Agents Enhancements
General Enhancements
CAS Fallback Behavior Enhancement
In Cisco NAC Appliance Release 4.5(1), the CAS Fallback function has been enhanced to more appropriately handle CAS Fallback behavior when the CAM becomes unreachable on the network. In previous releases of Cisco NAC Appliance, the CAS determined that the CAM was unreachable after failing to successfully poll the CAM over a specified Detect Timeout period and would automatically initiate a Fallback event. Once the CAS was able to successfully contact the CAM one time following a Fallback event, the CAS would assume the CAM was "alive" again and resume normal operation (exit Fallback mode). Unfortunately, depending on the Fallback settings for the CAS, this behavior could lead to the CAS continually flapping between Fallback mode and normal operation when the network experienced even minor intermittent connectivity issues, and leave large segments of the user pool unable to log in.
With Cisco NAC Appliance Release 4.5(1), in addition to setting both the Detect Interval and Detect Timeout values in the CAS Fallback page, administrators can also specify the CAM detection Fail Percentage threshold value that helps better tune the CAS Fallback behavior to the network. When the administrator specifies a value for the Fail Percentage setting, the CAS also automatically sets the subsequent Resume Percentage success threshold value that determines when the CAS returns to normal operation following a CAS Fallback event.
For new installations of Cisco NAC Appliance Release 4.5(1), this enhancement also introduces a new default value of 20 seconds for the Detect Interval setting and requires the Detect Timeout value to be at least 15 times the specified Detect Interval. If you are upgrading to release 4.5(1) and already employ CAS Fallback behavior in your system, your existing values for these settings are preserved, and you may need to reconfigure your settings to maintain expected CAS Fallback behavior in your network.
Note
Although the Detect Timeout must be at least 15 times the Detect Interval, Cisco recommends making the Detect Timeout 30 times the Detect Interval value.
This enhancement affects the following page of the CAM web console:
•
Device Management > CCA Servers > Manage [CAS_IP] > Filter > Fallback—new Fail Percentage and Restore Percentage settings and new default value of 20 seconds for the Detect Interval setting (the Detect Interval default value was 60 seconds in previous releases)
Refer to "CAS Fallback Policy" in the Cisco NAC Appliance - Clean Access Server Installation and Administration Guide, Release 4.5(1) for further details. s
CAS HA Pair Link-Detect Configuration Enhancement
Cisco NAC Appliance Release 4.5(1) enables administrators to create and/or edit a configuration file residing on the CAS to specify link-detect interfaces to monitor on the CAS. This enhancement is designed to provide a solution for Cisco NAC Appliance networks where, due to network topology or configuration issues, CAS high-availability (HA) pairs may be unable to verify connectivity with the trusted (eth0) and/or untrusted (eth1) external interfaces specified in the CAS web console (Administration > Network Settings > Failover).
To enable this enhancement, the administrator must add or update the linkdetect.conf file residing in the /etc/ha.d/ directory on the CAS, specifying the interface(s) on which to enable Link-detect functionality. After adding/updating the file, you must stop and then restart services on the CAS using the service perfigo stop and service perfigo start commands.
For more information, see CSCsv74447.
DHCP Failover Behavior Enhancement
Cisco NAC Appliance Release 4.5(1) enhances the CAS failover behavior for DHCP when a standby CAS assumes the role of the active CAS. In the event an active HA CAS performing DHCP address assignment is in Fallback (Fail Open) state before the failover event, the standby CAS is now able to assume DHCP address management functions in addition to user login.
This enhancement addresses an issue where client machines are unable to get IP addresses or even renew address leases when the DHCP service is configured to run on an active HA CAS and the CAS goes into Fallback (Fail Open) mode when the CAM becomes unreachable for an extended period of time. This enhancement also improves Cisco NAC Appliance availability and operation when the active CAS reboots or the CAS fails over when the CAM is unreachable on the network.
For more information, see CSCsv71328.
Cisco NAC Appliance API Enhancement
Two new functions are added to the Cisco NAC Appliance API (cisco_api.jsp):
•
checkmac—queries the Device Filters list to check if a particular MAC address exists.
•
getmaclist —fetches the entire Device Filters list.
See CSCsw67822.
Supported AV/AS Product List Enhancements (Version 74)
•
See Clean Access Supported AV/AS Product Lists for the latest AV/AS product charts.
•
See Supported AV/AS Product List Version Summary (Windows) for details on each update to the list.
New Features and Enhancements in Release 4.5(0)
•
CAM/CAS SSL Certificate Management Enhancement
•
CAM/CAS Software Upload Page Enhancements
•
Database Snapshot Upgrade Enhancement
•
Clean Access Manager High Availability User Interface Enhancement
•
CAM/CAS Support Log Level Settings Enhancement
•
CAM/CAS High Availability Configuration Able to Detect Hard-Drive Failure
•
Support for Wireless Out-of-Band Deployments
•
Assign Restricted VLAN for OOB Client Machines When Disconnected
•
Certified Device List/Online User List Enhancements
•
Out-of-Band Shield Enhancement
•
Out-of-Band Discovered Clients Cleanup
FIPS-Related Security Enhancements
•
Strong Password Support for Root Admin Users
•
External Authentication Server Support for Web Administrator Login
•
Support for Cisco NAC Appliance/NME-NAC Platforms Only
•
Windows ME/98/NT OS Support Removed
•
Default CAM Web Console Password Removed
Cisco NAC Appliance Agents Enhancements
Clean Access Supported AV/AS Product Lists Enhancements
•
Supported AV/AS Product List Version Summary (Windows)
•
Supported AV/AS Product List Version Summary (Mac OS X)
•
Clean Access AV Support Chart (Windows Vista/XP/2000)
•
Clean Access AS Support Chart (Windows Vista/XP/2000)
•
Clean Access AV Support Chart (Mac OS X)
•
Clean Access AS Support Chart (Mac OS X)
General Enhancements
Policy Import/Export
The Policy Import/Export feature allows administrators to propagate device filters, traffic and remediation policies, and OOB port and VLAN profiles from one CAM to several CAMs. All CAMs must run release 4.5 or later to enable Policy Sync. Policies are defined on a single CAM which you configure as the Policy Sync Master, and a maximum of 10 CAMs or 10 CAM HA-pairs are supported as Policy Sync Receivers. You can export policies using Manual Sync or Auto Sync. Auto Sync allows you to schedule an automatic Policy Sync once every x number of days.
Note
On CAM HA-pairs, Policy Sync settings are disabled for the Standby CAM.
To perform Policy Sync, the Master and Receiver CAMs must be configured to authorize each other using the DN from the SSL certificate of each CAM or CAM HA pair. For production deployments, CA-signed SSL certificates should be used.
•
Policy Sync Policies lists the configurations that are subject to Policy Sync.
•
Policies Excluded from Policy Sync is a list (non-exhaustive) of policies that are not included in Policy Sync.
Policy Sync Policies
During Policy Sync, the Master configuration completely overrides (and clears) the existing Receiver configuration for the policies that are configured for Policy Sync, such as OOB profiles or user roles. Policy Sync enables the following global configurations to be propagated from a Master CAM.
•
Role-Based Policies
–
User roles with associated global traffic control policies (IP-based, Host-based, L2 Ethernet) and session timers
Note: This includes customized policies and the Default Host Policies, Default L2 Policies from Cisco Updates that are on the Master CAM.
–
Global device filters with access type: Role or Check
–
Clean Access Agent rules (Cisco and AV/AS), requirements, rule-requirement mappings, and role-requirement mappings
Note: This includes customized checks/rules and Cisco Checks & Rules and Supported AV/AS Product List (Windows & Macintosh) from Cisco Updates that are on the Master CAM and associated to rules/requirements.
•
Non Role-Based Policies
–
Global device filters with access type: Allow, Deny or Ignore
•
OOB Policies (does not include switch information (i.e. Device/SNMP))
–
Port Profiles
–
VLAN Profiles
Note
•
OOB policies should not be selected for Policy Sync if a Master is not configured for OOB, as this will clear any OOB policies on the Receiver CAM.
•
If you have an OOB CAM and any legacy CAMs with IB-Only licenses, make sure to configure the OOB CAM as the Master CAM and the legacy CAMs as Receivers.
Note
Policy Sync exports all global device filters created on the Master CAM to the Receiver CAMs. Any MAC address which is in the Master CAM's global Device Filter list will be exported, including Cisco NAC Profiler generated filters.
Policies Excluded from Policy Sync
Policies/configurations that are not listed under Policy Sync Policies are not subject to Policy Sync and are otherwise left alone on the Receiver CAM after a Policy Sync. The following non-exhaustive list describes the kinds of policies/configurations that are not included for Policy Sync:
•
Cisco NAC Appliance Agents. The Master and Receiver CAMs retain the Agent versions and Agent download and distribution policies they already have. You will still need to require use of the Agent for a role and operating system (e.g. Agent Login/Distribution pages) on each CAM.
•
Local configuration on the Receiver CAMs such as CAS-specific traffic policies or device filters. Local policies stay the same on the Receiver CAM and are not removed after a Policy Sync.
•
OOB switch configurations such as Device Profiles and SNMP Receiver settings.
•
Clean Access Agent Updates for Cisco NAC Appliance Agents (Windows/Mac OS/Web), OS Detection Fingerprinting, and Switch OIDs
•
User Login pages, Local Users, or Bandwidth policies (see also CSCsu78379) associated with a user role.
•
Subnet filters
•
Authentication server configurations
•
Certified Device List or Timers
•
Network Scanning (Nessus) configuration
Note
Cisco recommends that you configure auto update settings on the Master and Receiver CAMs (under Device Management > Clean Access > Updates > Update) and ensure that the Master CAM has the latest Cisco Updates before you perform a Policy Sync.
This enhancement affects the following pages of the CAM web console:
•
New Administration > CCA Manager > Policy Sync configuration module
•
Red-colored product banner for CAM web consoles of Policy Sync Receivers
For configuration information, refer to the "Policy Import/Export" section of the Cisco NAC Appliance - Clean Access Manager Installation and Configuration Guide.
CAM/CAS SSL Certificate Management Enhancement
Release 4.5 updates the temporary SSL certificate generation, the CA-signed certificate request mechanism, and certificate/Private Key import and export operations (included in Release 4.1(6)) to better segregate and more clearly define the SSL certificate functions on the CAM and CAS.
When you perform a fresh install of release 4.5, the default Certificate Authority trust store contains only the private CA required to generate a temporary certificate suitable for lab environments. One of the first steps administrators must take once SSL communications between the CAM and CAS have been established is to generate Certificate Signing Requests (CSRs) from a trusted third-party certificate authority for the CAM and CAS and import the resulting certificates onto the CAM and CAS once they are generated and returned from the CA.
This enhancement updates the following pages of the CAM web console:
•
Administration > CCA Manager > SSL > X509 Certificate
•
Administration > CCA Manager > SSL > Trusted Certificate Authorities
This enhancement adds the following CAM web console page:
•
Administration > CCA Manager > SSL > x509 Certification Request
This enhancement affects the following pages of the CAS web console:
•
Administration > SSL > X509 Certificate
•
Administration > SSL > Trusted Certificate Authorities
This enhancement adds the following CAS web console page:
•
Administration > SSL > x509 Certification Request
For configuration information, refer to the "Manage CAM SSL Certificates" section of the Cisco NAC Appliance - Clean Access Manager Installation and Configuration Guide and "Manage CAS SSL Certificates" section of the Cisco NAC Appliance - Clean Access Server Installation and Configuration Guide.
See also Known Issues with www.perfigo.com Root CA for additional details.
CAM/CAS Software Upload Page Enhancements
Note
Web upgrade is no longer supported for upgrade to release 4.5. To upgrade your CAM and CAS from 4.1(x) or 4.0(x) releases, you must copy the cca_upgrade-4.5.1-NO-WEB.tar.gz file to each CAM and CAS appliance and run the upgrade script via the command line. Refer to Upgrading to Release 4.5 and Known Issues with Web Upgrade in Release 4.1(x) and Earlier for details.
With removal of the web upgrade functionality, previous web console pages are modified for release 4.5. For administrator convenience and backward compatibility, release 4.5 maintains the CAM/CAS web console pages that were related to web upgrade in prior releases, but modifies them to allow file upload and viewing of upgrade log information only. The "Apply" and "Upgrade Agent?" columns and functionality are removed. Note that upgrade log files are preserved on these pages for upgraded systems only.
This affects the following CAM/CAS web console pages:
•
CAM: Administration > CCA Manager > Software Upload ("System Upgrade" has become Software Upload" and "Upgrade Agent" and "Apply" options are removed)
•
CAM: Device Management > CCA Servers > Manage [CAS_IP] > Misc > Upgrade Logs (upload function removed completely; "Update" is now "Upgrade Logs", "Apply" and "Notes" options are removed)
•
CAS: Administration > Software Upload ("Software Update" link changed to "Software Upload", "Apply" and "Notes" options are removed)
Note
Starting from 4.5, successfully web-uploaded upgrade files are automatically placed in the /store directory of the CAM of the CAS, and the release 4.5 upgrade script will not run in any directory not under /store.
Note
The format of the Upgrade Details log is: state before upgrade, upgrade process details, state after upgrade. It is normal for the "state before upgrade" to contain several warning/error messages (e.g. "INCORRECT"). The "state after upgrade" should be free of any warning or error messages.
See Known Issues with Web Upgrade in Release 4.1(x) and Earlier for further details.
Database Snapshot Upgrade Enhancement
Release 4.5 enhances the database snapshot re-importing process for users who back up their CAM system snapshot before upgrading and are forced to re-import the database following an upgrade failure (as might be the case if a planned HA upgrade does not succeed). Although re-importing a snapshot from a previous Cisco NAC Appliance release is not allowed in release 4.0(x) or 4.1(x), this function is possible in Cisco NAC Appliance Release 4.5 because, as long as the CAM database schema does not change at the time of upgrade, you can now re-import an existing snapshot from a prior release and attempt the upgrade again.
The process and method of backing up the database and re-importing the snapshot does not change from previous releases, but the time it takes to re-import and the reliability of the process has also improved dramatically over prior releases.
Clean Access Manager High Availability User Interface Enhancement
In Cisco NAC Appliance release 4.5, the HA-Standby CAM web console now matches the HA-Active web console, but disables (greys out) or hides non-applicable menu options. Some additional HA-Active web console menu and submenu items are also enabled to the HA-Standby web console:
•
The HA-Standby web console allows you to view the Clean Access Server list via the new CCA Servers sub-menu option under Device Management.
•
The HA-Standby web console allows you to view the default system Monitoring > Summary page displayed when logging into the HA-Active web console.
•
The HA-Standby web console displays CCA Manager management options similar to those found on the HA-Active web console. HA-Active web console options that are not available on the HA-Standby console are hidden or disabled (greyed out).
CAM/CAS Support Log Level Settings Enhancement
In Cisco NAC Appliance release 4.5, the CAM/CAS event log settings options have been expanded, offering greater granularity in available log levels and improved control over the type and detail of support log entries recorded for the various event log categories on the CAM/CAS. One key improvement is the ability to turn logging off altogether for one or more particular event log categories, thus reserving available logging disk space for more critical event log types.
This enhancement affects the following pages of the CAM web console:
•
Administration > CCA MAnager > Support Logs—page now features six log levels for each of the five log categories: OFF, ERROR, WARN, INFO, DEBUG, and TRACE
This enhancement affects the following pages of the CAS web console:
•
Monitoring > Support Logs—page now features six log levels for each of the five log categories: OFF, ERROR, WARN, INFO, DEBUG, and TRACE
CAM/CAS High Availability Configuration Able to Detect Hard-Drive Failure
In Cisco NAC Appliance release 4.5 deployments configured for High Availability, nodes that undergo hard disk failure now automatically reboot, thus triggering the High Availability failover mechanism. With previous releases of Cisco NAC Appliance, it was possible for an active CAM/CAS to experience a hard-drive failure yet still respond to heartbeat packets from the standby CAM/CAS, thus never failing over to the standby even though no user authentication/access could take place in the system and the administrator was no longer able to manage the "active" CAM/CAS. The only way to handle this issue was to manually shut the active CAM/CAS down so that automatic HA failover would kick in.
For more information, see CSCso51899.
Out-of-Band Enhancements
Support for Wireless Out-of-Band Deployments
Note
Cisco NAC Appliance Release 4.5 introduces Wireless OOB support which only supports Layer 2 OOB Virtual Gateway deployments that require no IP change. Because the Cisco NAC Network Module does not support this topology, the NAC Network Module is not supported for Wireless OOB.
Release 4.5 introduces Out-of-Band support for wireless clients logging into the Cisco NAC Appliance system. Previous releases of Cisco NAC Appliance support wireless client machines, but only in In-Band mode, with all traffic between the client machine and the internal network always passing through the Clean Access Server. To address increasing demand for bandwidth from more and more client machines authenticating via Cisco NAC Appliance, administrators can now configure the CAM to manage client authentication information from one or more Wireless LAN Controllers (WLCs), similar to the way the CAM manages other switch devices in the network, prompting switches to change the Authentication (or Quarantine) VLAN to the Access VLAN for client ports and vice-versa. To support wireless Out-of-Band communication, the CAS remains inline only until the wireless user is authenticated and the WLC is able to switch the client machine VLAN assignment from the Authentication VLAN to the Access VLAN. After that, all traffic from the wireless client can bypass the CAS to access the network directly.
Note
You can only deploy CASs supporting wireless client machine authentication in Virtual Gateway mode.
Some strict guidelines dictate how WLCs and Cisco NAC Appliance interact when authenticating wireless client machines and how they keep one another informed of client status:
•
WLCs must be configured to interact with the CAM using SNMP read, write, and trap functions.
•
Each SSID/dynamic interface on the WLC must have both an Authentication (Quarantine) VLAN and Access VLAN configured.
•
If the Access VLAN is the same for two or more SSIDs, those SSIDs should also have the same Authentication (Quarantine) VLANs.
•
Authentication and Access VLANs are defined on the WLC and changes between the two are transmitted to the CAM using SNMP traps—administrators do not assign VLANs from the CAM via user role assignments or otherwise.
•
When a wireless user logs off, the WLC also sends SNMP information to the CAM to ensure the user ID is removed from the Online Users List. Likewise, if the administrator must kick any users out of the Online Users List, the CAM informs the WLC via SNMP and the WLC automatically assigns the wireless client to the Authentication (Quarantine) VLAN once more.
•
If Single Sign-On (SSO) is required for wireless users, the WLC must also be configured to transmit RADIUS accounting packets to the CAS.
•
Administrators need to configure a device profile for the WLC on the CAM (under OOB Management > Profiles > Device > New) and add the new device to the OOB devices list (under OOB Management > Devices > Devices > New) in order to manage the WLC like a switch.
Note
Administrators do not need to configure any Port Profiles on the CAM to manage WLCs.
Cisco NAC Appliance only interoperates with Cisco Wireless LAN Controllers. Refer to Table 1, "Recommended WLC Platforms to Support Wireless OOB in Release 4.5" for a list of supported Cisco Wireless LAN Controller platforms.
This enhancement affects the following pages of the CAM web console:
•
"Switch Management" left navigation module becomes "OOB Management"
•
OOB Management > Profiles > Group > List/Edit—"Switch" column becomes "Device"
•
OOB Management > Profiles > Device > List/New/Edit—"Switch" column becomes "Device"
•
OOB Management > Devices > Devices > List/New/Search—"Switch" column becomes "Device"
•
OOB Management > Devices > Discovered Clients — Two new tabs: Wired Clients, Wireless Clients
•
OOB Management > Devices | new WLC[x.x.x.x] Wireless LAN Controller category "Config" icon only displays "Basic" and "Group" subtabs (no "Advanced" subtab like the Switch category) and the "Ports" icon available for switch device entries is grayed out/disabled for all WLC table entries.
•
Device Management > Filters > Devices > New/Edit—Descriptions now include additional information on WLC behavior for Wireless Out-of-Band
For additional pages affected, see also Certified Device List/Online User List Enhancements.
For configuration information, refer to the "Configuring Wireless Out-of-Band Deployments" section of the Cisco NAC Appliance - Clean Access Manager Installation and Configuration Guide.
Assign Restricted VLAN for OOB Client Machines When Disconnected
In Cisco NAC Appliance Release 4.5, administrators can now configure which VLANs should be assigned to switch ports after an OOB client goes offline and the CAM receives a linkdown SNMP trap from the switch. In Cisco NAC Appliance Releases 4.1(3) and 4.1(6), anytime an OOB client machine disconnected from the network, the CAM would automatically change the VLAN on the switch port to the Authentication VLAN. (In prior releases of Cisco NAC Appliance—release 4.1.2.1 and earlier—the CAM would simply allow the switch port to remain unchanged, thus the port would very often remain in the Access VLAN until the next client machine attempted to access the Cisco NAC Appliance network via that same port.) Release 4.5 allows you to configure which VLAN assignment to make using the enhanced dropdown menu options available with the existing Remove out-of-band online user when SNMP linkdown trap is received option. There are three settings you can use:
•
do nothing—The CAM does not perform any unilateral VLAN reassignment for switch ports where OOB clients have disconnected from the network. Other options in your Port Profile configuration (for example, having enabled and configured the Change to [Auth VLAN | Access VLAN] if the device is certified but not in the out-of-band user list option) still affect the VLAN assignment. Essentially, unless otherwise configured, the switch port remains on the Access VLAN when you choose the do nothing setting.
•
change to Auth VLAN—The CAM automatically assigns switch ports to the Authentication VLAN for OOB clients that have disconnected and for which a linkdown SNMP trap has been received.
•
change to Restricted VLAN—You can configure the CAM to assign a specific VLAN profile or VLAN ID (that can be separate from both the Authentication and Access VLANs) to switch ports where OOB clients have disconnected from the network. The administrator can configure one or more custom VLANs (perhaps featuring varying levels of network access) for client machines that fall into this category and assign one of them to switch ports where OOB clients have disconnected. This "restricted" VLAN assignment can also be useful to provide basic level access for OOB users when the CAM has gone offline, for example.
If the administrator disconnects the client machine (the administrator kicks the user out of the OOB Online Users list), the CAM bounces the switch port and the port is automatically assigned to the Authentication VLAN by default. If the administrator disconnects the client and the Remove out-of-band online user without bouncing the port option is enabled, the client machine experiences the same net effect because when the CAM removes the OOB user from the OOB Online Users list, it also assigns the client machine to the Authentication VLAN.
This enhancement affects the following page of the CAM web console:
•
OOB Management > Profiles > Port > New | Edit—the existing Remove out-of-band online user when SNMP linkdown trap is received option now features a dropdown menu allowing you to configure the VLAN assignment for OOB client machines when they have disconnected and are reconnecting to the network.
For more information, see also CSCso76150.
Certified Device List/Online User List Enhancements
The Certified Devices List (CDL) allows administrators to track users and devices that have met posture assessment. The Online Users Lists (OULs) track In-Band and Out-of-Band authenticated users logged into the network. Unlike the In-Band and Out-of-Band Online User Lists (OUL), which allow you to specify which fields are displayed on the OUL, you cannot choose the fields displayed in the Certified Devices List (CDL).
•
For prior 4.1(x) releases, the CDL specifies: Clean Access Server, MAC Address, User, Provider, Role, VLAN, Time, and Switch. In release 4.5, the CDL specifies: CCA Server, MAC Address, User, Provider, Role, VLAN, Time, and Location.
For 4.5 OOB users, the new Location column on the CDL and OUL displays the location of the user (switch/port or WLC/SSID) in OOB mode. This location should match the one listed on the OOB Online User Page when the client passes posture assessment for the first time.
•
In release 4.1(x), the Switch field was an inactive string/link for IB users. In release 4.5, Location fields associated with switch entries are simply left blank. for IB users.
•
In release 4.1(x), the Switch and Port fields in the In-Band and Out-of-Band Online Users lists would inform the administrator where the client machine was connected to the access network. In release 4.5, to accommodate Wireless Out-of-Band user entries, the lists of online users now show identify client machine access points in the more generic Location column.
These enhancement affects the following CAM web console pages:
•
Device Management > Clean Access > Certified Devices > Certified Devices List | Location field
•
Device Management > Clean Access > Certified Devices > Certified Devices List—"Switch" column becomes "Location"
•
Monitoring > Online Users > View Online Users > Out-of-Band—"Switch" and "Port" columns combine to become "Location"
•
Monitoring > Online Users > Display Settings > Out-of-Band—"Switch" and "Port" checkboxes become single "Location" checkbox
See also Support for Wireless Out-of-Band Deployments.
Out-of-Band Shield Enhancement
Cisco NAC Appliance release 4.5 features enhanced SNMP polling behavior for Out-of-Band managed switches to ensure that the CAM is able to communicate with switches experiencing network issues when they return to normal operation. Previous releases of Cisco NAC Appliance would occasionally lose communication with managed switches altogether before the administrator was forced to step in and clear up the switch behavior and re-establish CAM-to-switch communication.
You can configure this feature using the following settings in the smartmanager_conf table of the CAM CLI:
•
OobSnmpErrorLimit—This is maximum number of consecutive SNMP timeout failures. If the number of consecutive failures reaches this value, the switch is disabled. If the administrator specifies the limit so that it is equal to or is less than 0, this feature is disabled. The default value is 10.
•
OobSnmpRecoverInterval—This is the internal time period (in minutes) that the recovery process waits to check disabled switches to see if they have come back online. The default value is 10.
For more information, see CSCsq75149.
Out-of-Band Discovered Clients Cleanup
Cisco NAC Appliance release 4.5 enhances existing Out-of-Band client and OOB Online Users list maintenance. Some system configurations can result in OOB clients and OOB online users remaining in the CAM Discovered Clients and OOB Online Users lists even when the switch through which they originally accessed the network is no longer a managed resource, and when clients log in only once and never sign into the Cisco NAC Appliance network again. This solution introduces two new verification features on the CAM:
•
When a managed switch is deleted from the Devices list, the CAM now also deletes associated OOB online users and discovered clients.
•
The CAM now features configurable timers for discovered client sessions to check if they have expired. If the session has expired and the client is not active, the CAM deletes those entries and removes the associated OOB online user entry from the Online Users List.
Two optional processes can be activated every day to clean up the wired and wireless discovered clients respectively. (These two processes are disabled by default.) To enable these processes, set OobDiscoveredClientCleanup to yes in the CAM CLI's smartmanager_conf table. If enabled, the processes will run at 1:30AM for wired clients and 2:30AM for wireless clients.
For wired discovered clients, the process removes the entry if any of the following conditions is met:
–
The switch is not managed.
–
The port is not managed.
–
The port is down and there is no OOB online user on that port.
–
The port is down and the Remove out-of-band online user when SNMP linkdown trap is received option is checked in the port profile (the OOB user is also removed in this case).
For wireless discovered clients, the process removes the entry when any of the following conditions is met:
–
The WLC is not managed/associated with the CAM.
–
The MAC address is not known to the WLC.
For more information, see CSCsl77438.
FIPS-Related Security Enhancements
Although Cisco NAC Appliance is not certified for FIPS, release 4.5 includes the following FIPS-related security enhancements.
Pre-Login Banner
Cisco NAC Appliance release 4.5 introduces a new optional, customizable administrator welcome screen (called a "Pre-login Banner") that you can use to present a broad range of messages, including warnings, system/network status, access requirements, and so on to administrator users before they enter authentication credentials in the CAM/CAS. Administrators can specify the text of the Pre-login Banner by enabling this feature on the appliance during initial configuration, logging into the command-line console, and editing the /root/banner.pre file. The text of the Pre-login Banner appears in both the web console interface and the command-line interface when admin users log into the CAM/CAS.
This feature is disabled by default. You can enable or disable this feature during the initial CAM/CAS configuration CLI session or using the service perfigo config CLI command.
Strong Password Support for Root Admin Users
To offer increased security against potential unauthorized access to Cisco NAC Appliance, the CAM and CAS root admin password you specify during initial system configuration must now meet strong password standards requiring that the password be at least 8 characters long and contain at least two characters from each of the following classes:
•
Lower-case letters
•
Upper-case letters
•
Numbers (digits)
•
Special characters (like !@#$%^&*~)
For example, 1o-9=OnE is a valid password, but the password 10-9=One does not satisfy the requirements because it does not contain two characters from each category.
Note
If the first character of a password is an upper-case letter, that character is not counted toward the minimum number of required upper-case letters (two) when determining whether or not the correct number of characters exists in the password.
If the last character of a password is a digit, that character is not counted toward the minimum number of required digits (two) when determining whether or not the correct number of characters exists in the password.See Changes for 4.5 Installation/Upgrade for additional information on admin passwords.
External Authentication Server Support for Web Administrator Login
In Cisco NAC Appliance Release 4.5, you can authenticate administrator user credentials through an external Kerberos, LDAP, or RADIUS authentication server just like regular users when they log in to the Cisco NAC Appliance network. When an administrator user who has been configured to authenticate via an external server logs in, the CAM directs the user credentials to the external authentication server for validation. This login behavior also applies to administrator users logging into an associated CAS. If the CAS has been added to the CAM and the administrator user profile is configured to validate credentials via an external authentication server, the users credentials are also directed to the external authentication server when the administrator user logs into the CAS.
This enhancement affects the following page of the CAM web console:
•
Administration > Admin Users > New | Edit—this configuration window now includes an Authentication Server dropdown list where you can authenticate administrator user credentials via Built-in Admin Authentication (local CAM) or using an external Kerberos, LDAP, or RADIUS authentication server configured under User Management > Auth Servers > New | Edit.
Note
When specifying an external authentication server for admin login, the Password and Confirm Password fields that support Built-in Admin Authentication disappear from the configuration window.
Features Optimized/Removed
The following functions have been optimized or removed in Cisco NAC Appliance Release 4.5:
•
Support for Cisco NAC Appliance/NME-NAC Platforms Only
•
Default CAM Web Console Password Removed
•
Windows ME/98/NT OS Support Removed
Support for Cisco NAC Appliance/NME-NAC Platforms Only
Cisco NAC Appliance Release 4.5 only supports and can only be installed on the following Cisco NAC Appliance platforms: Cisco CCA-3140, Cisco NAC-3310, Cisco NAC-3350, Cisco NAC-3390, Cisco NAC Network Module (NME-NAC-K9). You cannot upgrade to or install release 4.5 on any other platform. See Hardware Support and Changes for 4.5 Installation/Upgrade for additional details.
Web Upgrade Support Removed
Web upgrade is no longer supported to upgrade from release 4.0(x)/4.1(x) to release 4.5, or from release 4.5 to a later release. For details, refer to CAM/CAS Software Upload Page Enhancements and Known Issues with Web Upgrade in Release 4.1(x) and Earlier.
Default CAM Web Console Password Removed
For new installations of Cisco NAC Appliance, there is no longer a default cisco123 CAM web console password. Administrators must specify a unique password for the CAM web console (does not have to be a strong password). However, any existing CAM web console passwords (including the old default cisco123) are preserved during upgrade.
See Strong Password Support for Root Admin Users for additional details on the enhancements to the root password.
Windows ME/98/NT OS Support Removed
Cisco NAC Appliance release 4.5 no longer supports Windows 98/Millennium Edition/NT client operating systems, and Clean Access Agent Version 4.5.0.0 and later cannot be installed on these operating systems. Windows 98/ME/NT Operating System dropdown menu options are retained on User Login and Clean Access Agent Requirement/Rule configuration pages on the CAM. However, Release 4.5 removes support for Windows 98/ME/NT for the Clean Access Agent and Clean Access Agent Supported AV/AS Product List.
Cisco NAC Appliance Agents
This section describes new features or enhancements for the Cisco NAC Appliance Agents:
Windows Clean Access Agent
Version 4.5.2.0
•
Version 4.5.2.0 of the Windows Clean Access Agent in Cisco NAC Appliance release 4.5(1) adds new AV/AS support as listed in Clean Access Supported AV/AS Product Lists.
•
Applicable bugs are resolved as listed in Resolved Caveats - Agent Version 4.5.2.0.
Version 4.5.1.0
•
Version 4.5.1.0 of the Windows Clean Access Agent in Cisco NAC Appliance release 4.5(1) adds new AV/AS support as listed in Clean Access Supported AV/AS Product Lists.
•
The Exit button in the Windows Clean Access Agent system tray can now be disabled by setting a registry value: HKLM\SOFTWARE\Cisco\Clean Access Agent, "DisableExit" (Dword, value=1). See CSCsw52528.
•
Applicable bugs are resolved as listed in Resolved Caveats - Agent Version 4.5.1.0.
Version 4.5.0 0
•
Version 4.5.0.0 of the Windows Clean Access Agent in t in Cisco NAC Appliance release 4.5(0) adds new AV/AS support as listed in Clean Access Supported AV/AS Product Lists.
•
Additionally release 4.5 no longer supports Windows 98/ME/NT operating systems for the Clean Access Agent. See also Windows ME/98/NT OS Support Removed.
Mac OS X Clean Access Agent
There are no changes to the Mac OS X Clean Access Agent in Cisco NAC Appliance release 4.5(1), and he version remains at 4.5.0.0.
Version 4.5.0.0 with Posture Assessment
With release 4.5, version 4.5.0.0 of the Mac OS X Clean Access Agent can perform posture assessment on Macintosh client machines for the supported AV and AS products listed in Supported AV/AS Product List Version Summary (Mac OS X). Mac OS X Clean Access Agent version 4.5.0.0 also supports a subset of the requirement types available on the current version of the Windows Clean Access Agent. The supported requirement types are:
•
Link Distribution
•
Local Check
•
AV Definition Update
•
AS Definition Update
After a Macintosh OS 10.4 or 10.5 user initiates login and the Mac OS X Agent determines that the client machine requires remediation, the user sees a Mac OS X Agent Assessment Report calling out each of the "failed" mandatory or optional requirements. When presented with the Mac OS X Agent Assessment Report window, users then determine which optional requirements to address (users must address all mandatory requirements) to ensure the client machine is compliant with configured Cisco NAC Appliance security guidelines. Once the user starts client remediation, the Mac OS X Agent addresses each requirement one-by-one as they appear in the Assessment Report until all mandatory requirements "pass" assessment and the user chooses to complete the remediation process and successfully log into the Cisco NAC Appliance system. If any mandatory requirements are not resolved, the user cannot complete the login process.
Additional Features
•
When launching a browser, the Link Distribution requirement type will launch the default browser, which can be configured in the Safari browser preference settings. Users can use any browser to perform remediation, including Safari, Firefox, or Opera.
•
The Mac OS X Agent fully supports UTF-8 for localization. For configuration details, refer to the "Mac OS X Agent Prerequisites" section of the Cisco NAC Appliance - Clean Access Manager Installation and Configuration Guide, Release 4.5.
•
The Mac OS X Agent installer (built by Apple's "Package Maker" system application) installs two application files on the client: CCAAgent.app to launch the Mac OS X Clean Access Agent, and dhcp_refresh to facilitate IP address refresh procedures. See CSCso50613 for additional details on dhcp_refresh.
•
The Mac OS X Agent supports Auto-Upgrade. Users can upgrade client machines to the latest Mac OS X Agent by downloading the Agent via web login and running the Agent installation.
Mac OS X Posture Assessment Restrictions
•
The client machine must be running Mac OS 10.4 or 10.5. The Mac OS X posture assessment Agent (version 4.5.0.0) does not support Mac OS 10.2 and 10.3.
•
The Mac OS X Agent does not support IP-based certificates for authentication.
•
The Mac OS X Agent does not support auto-remediation. The user must manually click the Remediate button on the Mac OS Agent (equivalent to the Update button on the Windows Agent) and manually remediate to make the client machine compliant with network security guidelines.
•
The Mac OS X Agent does not support custom checks ("New Check") or custom rules ("New Rule"). You can only assign AV and AS rules to the Link Distribution, Local Check, AV Definition Update, and AS Definition Update requirement types for Mac OS X posture assessment/remediation.
•
The Log file (~/Library/Application Support/Cisco Systems/CCAAgent/event.log) is encrypted. The user must use the decryption tool on Windows to see the log in clear text.
See also CSCsl75403, CSCso15754, CSCso50613 under Open Caveats - Release 4.5(1) for additional details.
For configuration information, refer to the "Mac OS X Clean Access Agent" section of the Cisco NAC Appliance - Clean Access Manager Installation and Configuration Guide.
Cisco NAC Web Agent
Version 4.5.1.2
•
Version 4.5.1.2 of the Cisco NAC Web Agent in Cisco NAC Appliance release 4.5(1) adds new AV/AS support as listed in Clean Access Supported AV/AS Product Lists.
•
Applicable bugs are resolved as listed in Resolved Caveats - Agent Version 4.5.1.0.
Version 4.5.0
There are no changes to the Cisco NAC Web Agent in Cisco NAC Appliance release 4.5 except that the Cisco NAC Web Agent version is updated to version 4.5.0.
Clean Access Supported AV/AS Product Lists
The Cisco NAC Appliance Supported AV/AS Product List is a versioned XML file distributed from a centralized update server and downloaded to the Clean Access Manager via Device Management > Clean Access > Updates > Update. It provides the most current matrix of supported antivirus (AV) and anti-spyware (AS) vendors and products per version of the Clean Access Agent, and is used to populate AV/AS Rules and AV/AS Definition Update requirements for Clean Access Agents that support posture assessment/remediation.
You can access AV and AS product support information from the CAM web console under Device Management > Clean Access > Clean Access Agent > Rules > AV/AS Support Info. For convenience, this section also provides the following summary and product charts. The charts list which product versions support virus or spyware definition checks and automatic update of client virus/spyware definition files via the user clicking the Update button on the Agent.
•
Supported AV/AS Product List Version Summary (Windows)
•
Clean Access AV Support Chart (Windows Vista/XP/2000)
•
Clean Access AS Support Chart (Windows Vista/XP/2000)
•
Supported AV/AS Product List Version Summary (Mac OS X)
•
Clean Access AV Support Chart (Mac OS X)
•
Clean Access AS Support Chart (Mac OS X)
Note
Release 4.5 removes support for Windows 98/ME/NT for the Clean Access Agent and Clean Access Agent Supported AV/AS Product List. See Windows ME/98/NT OS Support Removed.
Note
Cisco recommends keeping your Supported AV/AS Product List up-to-date on your CAM (particularly if you have updated the Windows Agent Setup/Patch version or Mac OS Agent) by configuring the Update Settings under Device Management > Clean Access > Updates > Update to Automatically check for updates starting from <x> every <y> hours.
Note
Where possible, Cisco recommends using AV Rules mapped to AV Definition Update Requirements when checking antivirus software on clients, and AS Rules mapped to AS Definition Update Requirements when checking anti-spyware software on clients. In the case of non-supported AV or AS products, or if an AV/AS product/version is not available through AV Rules/AS Rules, administrators always have the option of creating their own custom checks, rules, and requirements for the AV/AS vendor (and/or using Cisco provided pc_ checks and pr_rules) through Device Management > Clean Access > Clean Access Agent (use New Check, New Rule, and New File/Link/Local Check Requirement). See the Cisco NAC Appliance - Clean Access Manager Installation and Configuration Guide, Release 4.5 for configuration details.
Note that Clean Access works in tandem with the installation schemes and mechanisms provided by supported AV/AS vendors. In the case of unforeseen changes to underlying mechanisms for AV/AS products by vendors, the Cisco NAC Appliance team will update the Supported AV/AS Product List and/or Clean Access Agent in the timeliest manner possible in order to support the new AV/AS product changes. In the meantime, administrators can always use the "custom" rule workaround for the AV/AS product (such as pc_checks/pr_ rules) and configure the requirement for "Any selected rule succeeds."Refer to Cisco NAC Appliance Agents for additional details on Agent versions in this release.
Supported AV/AS Product List Version Summary (Windows)
Table 7 summarizes enhancements for each version update of the Supported Antivirus/Antispyware Product List for the Windows Clean Access Agent and Cisco NAC Web Agent. See Clean Access AV Support Chart (Windows Vista/XP/2000) and Clean Access AS Support Chart (Windows Vista/XP/2000) for details.
Clean Access AV Support Chart (Windows Vista/XP/2000)
Table 8 details Windows Vista/XP/2000 Supported AV Products as of the latest release of the Cisco NAC Appliance software.
Table 8 Clean Access Antivirus Product Support Chart (Windows Vista/XP/2000)
Version 78, 4.5.2.0 Agent, CAM/CAS Release 4.5(1) (Sheet 1 of 15) Product Name Product Version AV Checks Supported
(Minimum Agent Version Needed)1 Installation Virus Definition AEC, spol. s r.o.TrustPort Antivirus
2.x
yes (4.0.6.0)
-
yes
ALWIL Softwareavast! Antivirus
4.x
yes (3.5.10.1)
yes (3.5.10.1)
yes
avast! Antivirus (managed)
4.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
avast! Antivirus Professional
4.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
avast! Server Edition
4.x
yes (4.1.8.0)
yes (4.1.8.0)
yes
AT&TAT&T Internet Security Suite AT&T Anti-Virus
6.x
yes (4.1.10.0)
-
yes
AVG TechnologiesAVG 8.0 [AntiVirus]
8.x
yes (4.1.3.2)
yes (4.1.7.0)
yes
AVG Anti-Virus Free
8.x
yes (4.1.6.0)
yes (4.1.7.0)
yes
AhnLab, Inc.AhnLab Security Pack
2.x
yes (3.5.10.1)
yes (3.5.10.1)
yes
AhnLab V3 Internet Security 2007
7.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
AhnLab V3 Internet Security 2007 Platinum
7.x
yes (3.6.5.0)
yes (3.6.5.0)
yes
AhnLab V3 Internet Security 2008 Platinum
7.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
AhnLab V3 Internet Security 7.0 Platinum Enterprise
7.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
AhnLab V3 VirusBlock Internet Security 2007
7.x
yes (4.1.8.0)
yes (4.1.8.0)
yes
V3 VirusBlock 2005
6.x
yes (4.1.2.0)
yes (4.1.2.0)
-
V3Pro 2004
6.x
yes (3.5.10.1)
yes (3.5.12)
yes
AliantAliant Business Security Suite Anti-Virus
6.x
yes (4.5.1.0)
-
yes
Aliant Business Security Suite Anti-Virus
7.x
yes (4.1.10.0)
-
-
Aliant Security Services Anti-Virus
7.x
yes (4.1.10.0)
-
-
America Online, Inc.AOL Safety and Security Center Virus Protection
1.x
yes (3.5.11.1)
yes (3.5.11.1)
-
AOL Safety and Security Center Virus Protection
102.x
yes (4.0.4.0)
yes (4.0.4.0)
-
AOL Safety and Security Center Virus Protection
2.x
yes (4.1.0.0)
yes (4.1.0.0)
-
AOL Safety and Security Center Virus Protection
210.x
yes (4.0.4.0)
yes (4.0.4.0)
-
Active Virus Shield
6.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Authentium, Inc.Command Anti-Malware
5.x
yes (4.1.10.0)
yes (4.1.10.0)
yes
Command Anti-Virus Enterprise
4.x
yes (3.5.0)
yes (3.5.0)
yes
Command AntiVirus for Windows
4.x
yes (3.5.0)
yes (3.5.0)
yes
Command AntiVirus for Windows Enterprise
4.x
yes (3.5.2)
yes (3.5.2)
yes
Cox High Speed Internet Security Suite
3.x
yes (4.0.4.0)
yes (4.0.4.0)
yes
Avira GmbHAvira AntiVir Personal - Free Antivirus
9.x
yes (4.1.10.0)
yes (4.1.10.0)
yes
Avira AntiVir PersonalEdition Classic
7.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
Avira AntiVir PersonalEdition Premium
7.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Avira AntiVir Premium
8.x
yes (4.1.6.0)
yes (4.1.6.0)
yes
Avira AntiVir Premium
9.x
yes (4.1.10.0)
yes (4.1.10.0)
yes
Avira AntiVir Professional
8.x
yes (4.1.6.0)
yes (4.1.6.0)
yes
Avira AntiVir Professional
9.x
yes (4.1.10.0)
yes (4.1.10.0)
yes
Avira AntiVir Windows Workstation
7.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Avira Premium Security Suite
7.x
yes (3.6.5.0)
yes (3.6.5.0)
yes
Avira Premium Security Suite
8.x
yes (4.1.6.0)
yes (4.1.6.0)
yes
Avira Premium Security Suite
9.x
yes (4.1.10.0)
yes (4.1.10.0)
yes
Beijing Rising Technology Corp. Ltd.Rising Antivirus Network Edition
20.x
yes (4.1.7.0)
yes (4.1.7.0)
-
Rising Antivirus Software AV
17.x
yes (3.5.11.1)
yes (3.5.11.1)
yes
Rising Antivirus Software AV
18.x
yes (3.5.11.1)
yes (3.5.11.1)
yes
Rising Antivirus Software AV
19.x
yes (4.0.5.0)
yes (4.0.5.0)
yes
Rising Antivirus Software AV
20.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
Rising Antivirus Software AV
21.x
yes (4.1.10.0)
yes (4.1.10.0)
-
Bell BellSouthBellSouth Internet Security Anti-Virus
5.x
yes (4.0.5.1)
yes (4.0.5.1)
-
BullGuard Ltd.BullGuard 7.0
7.x
yes (4.1.2.0)
yes (4.1.2.0)
-
BullGuard 8.0
8.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
BullGuard Gamers Edition
8.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
Bullguard Internet Security Suite
8.x
yes (4.1.8.0)
yes (4.1.8.0)
yes
Cat Computer Services Pvt. Ltd.Quick Heal AntiVirus Lite
9.5.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
Quick Heal AntiVirus Plus
10.x
yes (4.5.1.0)
yes (4.5.1.0)
yes
Quick Heal AntiVirus Plus
9.5.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
Quick Heal Total Security
10.x
yes (4.5.1.0)
yes (4.5.1.0)
yes
Quick Heal Total Security
9.5.x
yes (4.1.8.0)
yes (4.1.8.0)
yes
Check Point, IncZoneAlarm (AntiVirus)
7.0.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
ZoneAlarm (AntiVirus)
7.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
ZoneAlarm Anti-virus
7.0.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
ZoneAlarm Anti-virus
7.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
ZoneAlarm Anti-virus
8.x
yes (4.5.1.0)
yes (4.5.1.0)
yes
ZoneAlarm Security Suite Antivirus
7.0.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
ZoneAlarm Security Suite Antivirus
7.x
yes (4.0.5.0)
yes (4.0.5.0)
yes
ZoneAlarm Security Suite Antivirus
8.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
Cisco Systems, Inc.Cisco Security Agent
6.x
yes (4.5.1.0)
yes (4.1.10.0)
-
ClamAVClamAV
0.x
yes (4.1.8.0)
yes (4.1.8.0)
yes
ClamAV
devel-x
yes (4.0.6.0)
yes (4.0.6.0)
yes
ClamWinClamWin Antivirus
0.x
yes (3.5.2)
yes (3.5.2)
yes
ClamWin Free Antivirus
0.x
yes (3.5.4)
yes (3.5.4)
yes
Comodo GroupCOMODO Internet Security
3.5.x
yes (4.1.8.0)
-
-
Comodo BOClean Anti-Malware
4.25.x
yes (4.1.6.0)
-
yes
Computer Associates International, Inc.CA Anti-Virus
10.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
CA Anti-Virus
8.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
CA Anti-Virus
9.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
CA eTrust Antivirus
7.x
yes (3.5.0)
yes (3.5.0)
yes
CA eTrust Internet Security Suite AntiVirus
7.x
yes (3.5.11)
yes (3.5.11)
yes
CA eTrustITM Agent
8.x
yes (3.5.12)
yes (3.5.12)
yes
eTrust Antivirus
6.0.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
eTrust EZ Antivirus
6.1.x
yes (3.5.3)
yes (3.5.8)
yes
eTrust EZ Antivirus
6.2.x
yes (3.5.0)
yes (3.5.0)
yes
eTrust EZ Antivirus
6.4.x
yes (3.5.0)
yes (3.5.0)
yes
eTrust EZ Antivirus
7.x
yes (3.5.0)
yes (3.5.0)
yes
eTrust EZ Armor
6.1.x
yes (3.5.0)
yes (3.5.8)
yes
eTrust EZ Armor
6.2.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
eTrust EZ Armor
7.x
yes (3.5.0)
yes (3.5.0)
yes
Defender Pro LLCDefender Pro Anti-Virus
5.x
yes (4.0.4.0)
yes (4.0.4.0)
yes
ESTsoft Corp. EarthLink, Inc.Aluria Security Center AntiVirus
1.x
yes (4.1.0.0)
yes (4.1.0.0)
-
EarthLink Protection Control Center AntiVirus
1.x
yes (3.5.10.1)
yes (3.5.10.1)
-
EarthLink Protection Control Center AntiVirus
2.x
yes (4.0.5.1)
yes (4.0.5.1)
-
EarthLink Protection Control Center AntiVirus
3.x
yes (4.1.3.0)
yes (4.1.3.0)
-
Eset SoftwareESET NOD32 Antivirus
3.x
yes (4.1.3.2)
yes (4.1.3.2)
-
ESET NOD32 Antivirus
4.x
yes (4.1.10.0)
yes (4.1.10.0)
-
ESET Smart Security
3.x
yes (4.1.6.0)
yes (4.1.6.0)
-
ESET Smart Security
4.x
yes (4.1.10.0)
yes (4.1.10.0)
-
NOD32 Antivirus System
x
yes (4.1.3.2)
yes (4.1.3.2)
yes
NOD32 antivirus System
x
yes (4.1.3.2)
yes (4.1.3.2)
yes
NOD32 antivirus system
2.x
yes (3.5.5)
yes (3.5.5)
yes
NOD32 antivirus system
x
yes (4.1.3.2)
yes (4.1.3.2)
yes
F-Secure Corp.F-Secure Anti-Virus
5.x
yes (3.5.0)
yes (3.5.0)
yes
F-Secure Anti-Virus
6.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
F-Secure Anti-Virus
7.x
yes (4.0.4.0)
yes (4.0.4.0)
-
F-Secure Anti-Virus
8.x
yes (4.1.8.0)
yes (4.1.8.0)
-
F-Secure Anti-Virus 2005
5.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
F-Secure Anti-Virus Client Security
6.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
F-Secure Anti-Virus for Windows Servers
5.x
yes (4.1.3.2)
yes (4.1.3.2)
-
F-Secure Internet Security
6.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
F-Secure Internet Security
7.x
yes (4.0.4.0)
yes (4.0.4.0)
-
F-Secure Internet Security
8.x
yes (4.1.6.0)
yes (4.1.6.0)
-
F-Secure Internet Security 2005
5.x
yes (4.1.3.0)
yes (4.1.3.0)
-
F-Secure Internet Security 2006 Beta
6.x
yes (3.5.8)
yes (3.5.8)
yes
FairPointFairPoint Security Suite Virus Protection
7.x
yes (4.1.10.0)
yes (4.1.10.0)
-
Fortinet Inc.FortiClient Consumer Edition
3.x
yes (4.0.6.0)
yes (4.0.6.0)
yes
Frisk Software InternationalF-PROT Antivirus for Windows
6.0.x
yes (4.0.5.1)
yes (4.0.5.1)
-
F-Prot for Windows
3.14e
yes (3.5.0)
yes (3.5.0)
-
F-Prot for Windows
3.15
yes (3.5.0)
yes (3.5.0)
-
F-Prot for Windows
3.16c
yes (3.5.11)
yes (3.5.11)
-
F-Prot for Windows
3.16d
yes (3.5.11)
yes (3.5.11)
-
F-Prot for Windows
3.16x
yes (3.5.11.1)
yes (3.5.11.1)
-
GData Software AGAntiVirusKit 2006
2006.x
yes (4.1.0.0)
yes (4.1.0.0)
-
G DATA AntiVirenKit Client
8.x
yes (4.1.10.0)
yes (4.1.10.0)
-
G DATA AntiVirus 2008
18.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
G DATA AntiVirus 2009
19.x
yes (4.5.1.0)
yes (4.5.1.0)
yes
G DATA AntiVirusKit
17.x
yes (4.1.3.0)
yes (4.1.3.0)
-
G DATA InternetSecurity [Antivirus]
17.x
yes (4.1.3.0)
yes (4.1.3.0)
-
G DATA InternetSecurity [Antivirus]
18.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
G DATA InternetSecurity [Antivirus]
19.x
yes (4.5.1.0)
yes (4.5.1.0)
yes
G DATA TotalCare [Antivirus]
18.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
G DATA TotalCare [Antivirus]
19.x
yes (4.5.1.0)
yes (4.5.1.0)
yes
Grisoft, Inc.AVG 6.0 Anti-Virus - FREE Edition
6.x
yes (3.5.0)
yes (3.5.0)
-
AVG 6.0 Anti-Virus System
6.x
yes (3.5.0)
yes (3.5.0)
-
AVG 7.5
7.x
yes (4.0.4.0)
yes (4.0.4.0)
yes
AVG Anti-Virus 7.0
7.x
yes (3.5.0)
yes (3.5.0)
yes
AVG Anti-Virus 7.1
7.x
yes (3.6.3.0)
yes (3.6.3.0)
yes
AVG Antivirensystem 7.0
7.x
yes (3.5.0)
yes (3.5.0)
yes
AVG Free Edition
7.x
yes (3.5.0)
yes (3.5.0)
yes
Antivirussystem AVG 6.0
6.x
yes (3.5.0)
yes (3.5.0)
-
H+BEDV Datentechnik GmbHAntiVir PersonalEdition Classic Windows
7.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
AntiVir/XP
6.x
yes (3.5.0)
yes (3.5.0)
yes
HAURI, Inc.ViRobot Desktop
5.0.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
ViRobot Desktop
5.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
ViRobot Expert Ver 4.0
2006.x
yes (4.1.10.0)
yes (4.1.10.0)
yes
IKARUS Software GmbHIKARUS Guard NT
2.x
yes (4.0.6.0)
yes (4.0.6.0)
-
IKARUS virus utilities
5.x
yes (4.0.6.0)
yes (4.0.6.0)
-
Internet Security Systems, Inc.Proventia Desktop
10.x
yes (4.1.6.0)
yes (4.1.6.0)
-
Proventia Desktop
8.x
yes (4.0.6.0)
-
-
Proventia Desktop
9.x
yes (4.0.6.0)
yes (4.0.6.0)
-
Jiangmin, Inc.Jiangmin AntiVirus KV2007
10.x
yes (4.1.3.0)
-
yes
Jiangmin AntiVirus KV2008
11.x
yes (4.1.7.0)
-
yes
K7 Computing Pvt. Ltd.K7 Total Security
9.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
K7AntiVirus 7.0
7.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
Kaspersky LabsKaspersky Anti-Virus 2006 Beta
6.0.x
yes (3.5.8)
yes (3.5.8)
-
Kaspersky Anti-Virus 2009
8.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
Kaspersky Anti-Virus 6.0
6.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Kaspersky Anti-Virus 6.0 Beta
6.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Kaspersky Anti-Virus 7.0
7.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
Kaspersky Anti-Virus Personal
4.5.x
yes (3.5.0)
yes (3.5.0)
yes
Kaspersky Anti-Virus Personal
5.0.x
yes (3.5.0)
yes (3.5.0)
yes
Kaspersky Anti-Virus Personal Pro
5.0.x
yes (3.5.11)
yes (3.5.11)
yes
Kaspersky Anti-Virus for Windows File Servers
5.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
Kaspersky Anti-Virus for Windows File Servers
6.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
Kaspersky Anti-Virus for Windows Servers
6.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
Kaspersky Anti-Virus for Windows Workstations
5.0.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
Kaspersky Anti-Virus for Windows Workstations
6.x
yes (4.0.6.0)
yes (4.0.6.0)
yes
Kaspersky Anti-Virus for Workstation
5.0.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
Kaspersky Internet Security
6.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Kaspersky Internet Security 7.0
7.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
Kaspersky Internet Security 8.0
8.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
Kaspersky(TM) Anti-Virus Personal 4.5
4.5.x
yes (3.5.0)
yes (3.5.0)
yes
Kaspersky(TM) Anti-Virus Personal Pro 4.5
4.5.x
yes (3.5.0)
yes (3.5.0)
yes
Kingsoft Corp.Kingsoft AntiVirus 2004
2004.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Kingsoft AntiVirus 2007 Free
2007.x
yes (4.1.3.2)
yes (4.1.3.2)
-
Kingsoft Internet Security
7.x
yes (3.6.5.0)
yes (3.6.5.0)
yes
Kingsoft Internet Security 2006 +
2006.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Kingsoft Internet Security 9
2008.x
yes (4.1.7.0)
yes (4.1.7.0)
-
Lavasoft, Inc.Lavasoft Ad-Aware 2008 Professional [Antivirus]
7.x
yes (4.1.6.0)
yes (4.1.6.0)
yes
McAfee, Inc.McAfee Internet Security 6.0
8.x
yes (3.5.4)
yes (3.5.4)
yes
McAfee Managed VirusScan
3.x
yes (3.5.8)
yes (3.5.8)
yes
McAfee Managed VirusScan
4.x
yes (4.0.4.0)
yes (4.0.4.0)
yes
McAfee VirusScan
10.x
yes (3.5.4)
yes (3.5.4)
yes
McAfee VirusScan
11.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
McAfee VirusScan
12.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
McAfee VirusScan
13.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
McAfee VirusScan
4.5.x
yes (3.5.0)
yes (3.5.0)
yes
McAfee VirusScan
8.x
yes (3.5.1)
yes (3.5.1)
yes
McAfee VirusScan
8xxx
yes (3.5.0)
yes (3.5.0)
yes
McAfee VirusScan
9.x
yes (3.5.1)
yes (3.5.1)
yes
McAfee VirusScan
9xxx
yes (3.5.0)
yes (3.5.0)
yes
McAfee VirusScan Enterprise
7.0.x
yes (3.5.0)
yes (3.5.0)
yes
McAfee VirusScan Enterprise
7.1.x
yes (3.5.0)
yes (3.5.0)
yes
McAfee VirusScan Enterprise
7.5.x
yes (3.5.0)
yes (3.5.0)
yes
McAfee VirusScan Enterprise
8.0.x
yes (3.5.0)
yes (3.5.0)
yes
McAfee VirusScan Enterprise
8.7.x
yes (4.1.6.0)
yes (4.1.6.0)
yes
McAfee VirusScan Enterprise
8.x
yes (3.6.5.0)
yes (3.6.5.0)
yes
McAfee VirusScan Home Edition
7.x
yes (4.0.6.1)
yes (4.0.6.1)
yes
McAfee VirusScan Professional
8.x
yes (3.5.1)
yes (3.5.1)
yes
McAfee VirusScan Professional
8xxx
yes (3.5.0)
yes (3.5.0)
yes
McAfee VirusScan Professional
9.x
yes (3.5.1)
yes (3.5.1)
yes
McAfee VirusScan Professional Edition
7.x
yes (3.5.0)
yes (3.5.0)
yes
Total Protection for Small Business
4.7.x
yes (4.1.8.0)
yes (4.1.8.0)
yes
Total Protection for Small Business
4.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
MicroWorldeScan Anti-Virus (AV) for Windows
8.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
eScan Corporate for Windows
8.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
eScan Internet Security for Windows
8.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
eScan Professional for Windows
8.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
eScan Virus Control (VC) for Windows
8.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
eScan Virus Control (VC) for Windows
9.x
yes (4.1.8.0)
yes (4.1.8.0)
yes
Microsoft Corp.Microsoft Forefront Client Security
1.5.x
yes (4.0.5.0)
yes (4.0.5.0)
-
Windows Live OneCare
1.x
yes (4.1.0.0)
yes (4.1.0.0)
-
Windows Live OneCare
2.x
yes (4.1.3.2)
yes (4.1.3.2)
-
Windows OneCare Live
0.8.x
yes (3.5.11.1)
-
-
New Technology Wave Inc.Client Internet Security
5.x
yes (4.1.8.0)
yes (4.1.8.0)
-
Virus Chaser
5.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
Norman ASANorman Virus Control
5.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Norman Virus Control
6.x
yes (4.1.10.0)
yes (4.1.10.0)
yes
Norman Virus Control
7.x
yes (4.1.6.0)
yes (4.1.6.0)
yes
OmniquadOmniquad Total Security AV
9.x
yes (4.1.7.0)
yes (4.1.7.0)
-
PC Tools SoftwarePC Tools AntiVirus 2.0
2.x
yes (4.1.3.0)
yes (4.1.3.0)
-
PC Tools AntiVirus 2007
3.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
PC Tools AntiVirus 2008
4.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
PC Tools AntiVirus 2008
5.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
PC Tools Internet Security [Antivirus]
5.x
yes (4.1.3.0)
yes (4.1.3.0)
-
PC Tools Internet Security [Antivirus]
6.x
yes (4.1.7.0)
yes (4.1.7.0)
-
PC Tools Spyware Doctor [Antivirus]
5.x
yes (4.1.3.2)
-
-
PC Tools Spyware Doctor [Antivirus]
6.x
yes (4.1.7.0)
-
-
Spyware Doctor [Antivirus]
5.x
yes (4.1.3.2)
yes (4.1.3.2)
-
ThreatFire 3.0
3.x
yes (4.1.3.0)
-
-
ThreatFire 3.5
3.5.x
yes (4.1.6.0)
yes (4.1.6.0)
yes
ThreatFire 4.0
4.x
yes (4.1.8.0)
yes (4.1.8.0)
-
ThreatFire 4.1
4.x
yes (4.1.10.0)
-
-
Panda SoftwarePanda Antivirus + Firewall 2007
6.x
yes (4.0.4.0)
yes (4.0.4.0)
yes
Panda Antivirus + Firewall 2008
7.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
Panda Antivirus 2007
2.x
yes (4.0.4.0)
yes (4.0.4.0)
-
Panda Antivirus 2008
3.x
yes (4.0.6.1)
yes (4.0.6.1)
-
Panda Antivirus 6.0 Platinum
6
yes (3.5.0)
yes (3.5.0)
yes
Panda Antivirus Lite
1.x
yes (3.5.0)
yes (3.5.0)
-
Panda Antivirus Lite
3.x
yes (3.5.9)
yes (3.5.9)
-
Panda Antivirus Platinum
7.04.x
yes (3.5.0)
yes (3.5.0)
yes
Panda Antivirus Platinum
7.05.x
yes (3.5.0)
yes (3.5.0)
yes
Panda Antivirus Platinum
7.06.x
yes (3.5.0)
yes (3.5.0)
yes
Panda Antivirus Pro 2009
8.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
Panda Client Shield
4.x
yes (4.0.4.0)
yes (4.0.4.0)
-
Panda Endpoint Protection
5.x
yes (4.1.10.0)
yes (4.1.10.0)
-
Panda Global Protection 2009
2.x
yes (4.1.8.0)
yes (4.1.8.0)
yes
Panda Internet Security 2007
11.x
yes (4.0.4.0)
yes (4.0.4.0)
yes
Panda Internet Security 2008
12.x
yes (4.0.6.1)
yes (4.0.6.1)
yes
Panda Internet Security 2009
14.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
Panda Platinum 2005 Internet Security
9.x
yes (3.5.3)
yes (3.5.3)
yes
Panda Platinum 2006 Internet Security
10.x
yes (4.0.4.0)
yes (4.0.4.0)
yes
Panda Platinum Internet Security
8.03.x
yes (3.5.0)
yes (3.5.0)
yes
Panda Security for Desktops
4.x
yes (4.1.8.0)
yes (4.5.1.0)
-
Panda Titanium 2006 Antivirus + Antispyware
5.x
yes (3.5.10.1)
yes (3.5.10.1)
yes
Panda Titanium Antivirus 2004
3.00.00
yes (3.5.0)
yes (3.5.0)
yes
Panda Titanium Antivirus 2004
3.01.x
yes (3.5.0)
yes (3.5.0)
yes
Panda Titanium Antivirus 2004
3.02.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Panda Titanium Antivirus 2005
4.x
yes (3.5.1)
yes (3.5.1)
yes
Panda TruPrevent Personal 2005
2.x
yes (3.5.3)
yes (3.5.3)
yes
Panda TruPrevent Personal 2006
3.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
WebAdmin Client Antivirus
3.x
yes (3.5.11)
yes (3.5.11)
-
Parallels, Inc.Parallels Internet Security
7.x
yes (4.5.1.0)
yes (4.1.10.0)
yes
Radialpoint Inc.Radialpoint Security Services Virus Protection
6.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
Radialpoint Security Services Virus Protection
7.x
yes (4.1.7.0)
yes (4.1.7.0)
-
Radialpoint Security Services Virus Protection
8.x
yes (4.1.8.0)
yes (4.1.8.0)
-
Radialpoint Virus Protection
5.x
yes (4.0.5.1)
yes (4.0.5.1)
-
Zero-Knowledge Systems Radialpoint Security Services Virus Protection
6.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
SOFTWINBitDefender 8 Free Edition
8.x
yes (3.5.8)
yes (3.5.8)
-
BitDefender 8 Professional Plus
8.x
yes (3.5.0)
yes (3.5.0)
-
BitDefender 8 Standard
8.x
yes (3.5.0)
yes (3.5.0)
-
BitDefender 9 Internet Security AntiVirus
9.x
yes (3.5.11.1)
yes (3.5.11.1)
-
BitDefender 9 Professional Plus
9.x
yes (3.5.8)
yes (3.5.8)
yes
BitDefender 9 Standard
9.x
yes (3.5.8)
yes (3.5.8)
yes
BitDefender Antivirus 2008
11.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
BitDefender Antivirus 2009
12.x
yes (4.1.8.0)
yes (4.1.8.0)
yes
BitDefender Antivirus Plus v10
10.x
yes (4.0.4.0)
yes (4.0.4.0)
yes
BitDefender Antivirus v10
10.x
yes (4.0.4.0)
yes (4.0.4.0)
yes
BitDefender Business Client
11.x
yes (4.1.10.0)
yes (4.1.10.0)
-
BitDefender Client Professional Plus
8.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
BitDefender Free Edition
7.x
yes (3.5.0)
yes (3.5.0)
-
BitDefender Free Edition v10
10.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
BitDefender Internet Security 2008
11.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
BitDefender Internet Security 2009
12.x
yes (4.1.8.0)
yes (4.1.8.0)
yes
BitDefender Internet Security v10
10.x
yes (4.0.4.0)
yes (4.0.4.0)
yes
BitDefender Professional Edition
7.x
yes (3.5.0)
yes (3.5.0)
-
BitDefender Standard Edition
7.x
yes (3.5.0)
yes (3.5.0)
-
BitDefender Total Security 2008
11.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
BitDefender Total Security 2009
12.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
SalD Ltd.Dr.Web
4.32.x
yes (3.5.0)
yes (3.5.0)
yes
Dr.Web
4.33.x
yes (3.5.11.1)
yes (3.5.11.1)
yes
Dr.Web
4.44.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
Dr.Web
5.x
yes (4.1.10.0)
yes (4.1.10.0)
yes
SecurityCoverage, Inc.SecureIT [Antivirus]
1.x
yes (4.1.7.0)
yes (4.1.7.0)
-
Sereniti, Inc.Sereniti Antivirus
1.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
The River Home Network Security Suite
1.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
Sophos Plc.Sophos Anti-Virus
3.x
yes (3.5.3)
yes (3.5.3)
-
Sophos Anti-Virus
4.x
yes (3.6.3.0)
yes (3.6.3.0)
-
Sophos Anti-Virus
5.x
yes (3.5.3)
yes (3.5.3)
yes
Sophos Anti-Virus
6.x
yes (4.0.1.0)
yes (4.0.1.0)
yes
Sophos Anti-Virus
7.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
Sophos Anti-Virus version 3.80
3.8
yes (3.5.0)
yes (3.5.0)
-
Sunbelt SoftwareSunbelt VIPRE Enterprise Agent
3.x
yes (4.1.10.0)
yes (4.1.10.0)
-
VIPRE Antivirus
3.x
yes (4.1.10.0)
yes (4.1.10.0)
yes
Symantec Corp.Norton 360 (Symantec Corporation)
1.x
yes (4.1.1.0)
yes (4.1.1.0)
yes
Norton 360 (Symantec Corporation)
2.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
Norton 360 (Symantec Corporation)
3.x
yes (4.1.8.0)
yes (4.1.8.0)
-
Norton AntiVirus
10.x
yes (3.5.0)
yes (3.5.0)
yes
Norton AntiVirus
14.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Norton AntiVirus
15.x
yes (4.0.6.1)
yes (4.0.6.1)
yes
Norton AntiVirus
16.x
yes (4.1.7.0)
yes (4.1.7.0)
-
Norton AntiVirus 2002
8.00.x
yes (3.5.0)
yes (3.5.0)
yes
Norton AntiVirus 2002
8.x
yes (3.5.1)
yes (3.5.1)
yes
Norton AntiVirus 2002 Professional
8.x
yes (3.5.0)
yes (3.5.0)
yes
Norton AntiVirus 2002 Professional Edition
8.x
yes (3.5.0)
yes (3.5.0)
yes
Norton AntiVirus 2003
9.x
yes (3.5.0)
yes (3.5.0)
yes
Norton AntiVirus 2003 Professional
9.x
yes (3.5.0)
yes (3.5.0)
yes
Norton AntiVirus 2003 Professional Edition
9.x
yes (3.5.0)
yes (3.5.0)
yes
Norton AntiVirus 2004
10.x
yes (3.5.0)
yes (3.5.0)
yes
Norton AntiVirus 2004 (Symantec Corporation)
10.x
yes (3.5.0)
yes (3.5.0)
yes
Norton AntiVirus 2004 Professional
10.x
yes (3.5.0)
yes (3.5.0)
yes
Norton AntiVirus 2004 Professional Edition
10.x
yes (3.5.0)
yes (3.5.0)
yes
Norton AntiVirus 2005
11.0.x
yes (3.5.0)
yes (3.5.0)
yes
Norton AntiVirus 2006
12.0.x
yes (3.5.5)
yes (3.5.5)
yes
Norton AntiVirus 2006
12.x
yes (3.5.5)
yes (3.5.5)
yes
Norton AntiVirus Corporate Edition
7.x
yes (3.5.1)
yes (3.5.1)
yes
Norton Internet Security
16.x
yes (4.1.7.0)
yes (4.1.7.0)
-
Norton Internet Security
7.x
yes (3.5.0)
yes (3.5.0)
yes
Norton Internet Security
8.0.x
yes (3.5.0)
yes (3.5.0)
yes
Norton Internet Security
8.2.x
yes (3.5.1)
yes (3.5.1)
yes
Norton Internet Security
8.x
yes (3.5.1)
yes (3.5.1)
yes
Norton Internet Security
9.x
yes (3.5.10.1)
yes (3.5.10.1)
yes
Norton Internet Security (Symantec Corporation)
10.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Norton Security Scan
1.x
yes (4.1.3.0)
yes (4.1.3.0)
-
Norton SystemWorks 2003
6.x
yes (3.5.3)
yes (3.5.3)
yes
Norton SystemWorks 2004 Professional
7.x
yes (3.5.4)
yes (3.5.4)
yes
Norton SystemWorks 2005
8.x
yes (3.5.3)
yes (3.5.3)
yes
Norton SystemWorks 2005 Premier
8.x
yes (3.5.3)
yes (3.5.3)
yes
Norton SystemWorks 2006 Premier
12.0.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Symantec AntiVirus
10.x
yes (3.5.3)
yes (3.5.3)
yes
Symantec AntiVirus
9.x
yes (3.5.0)
yes (3.5.0)
yes
Symantec AntiVirus Client
8.x
yes (3.5.0)
yes (3.5.0)
yes
Symantec AntiVirus Server
8.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Symantec AntiVirus Win64
10.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
Symantec Client Security
10.x
yes (3.5.3)
yes (3.5.3)
yes
Symantec Client Security
9.x
yes (3.5.0)
yes (3.5.0)
yes
Symantec Endpoint Protection
11.x
yes (4.0.6.1)
yes (4.0.6.1)
yes
Symantec Scan Engine
5.x
yes (4.0.5.1)
yes (4.0.5.1)
-
TELUSTELUS security services Anti-Virus
7.x
yes (4.1.10.0)
-
-
Trend Micro, Inc.PC-cillin 2002
9.x
yes (3.5.1)
yes (3.5.1)
-
PC-cillin 2003
10.x
yes (3.5.0)
yes (3.5.0)
-
ServerProtect
5.x
yes (4.1.0.0)
yes (3.6.5.0)
-
Trend Micro Anti-Virus
17.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
Trend Micro AntiVirus
15.x
yes (3.6.5.0)
yes (3.6.5.0)
-
Trend Micro AntiVirus
16.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
Trend Micro Antivirus
11.x
yes (3.5.0)
yes (3.5.0)
yes
Trend Micro Client/Server Security
6.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Trend Micro Client/Server Security Agent
15.x
yes (4.1.6.0)
yes (4.1.6.0)
-
Trend Micro Client/Server Security Agent
7.x
yes (3.5.12)
yes (3.5.12)
yes
Trend Micro HouseCall
1.x
yes (4.0.1.0)
yes (4.0.1.0)
-
Trend Micro Internet Security
11.x
yes (3.5.0)
yes (3.5.0)
yes
Trend Micro Internet Security
12.x
yes (3.5.0)
yes (3.5.0)
-
Trend Micro Internet Security
16.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
Trend Micro Internet Security
17.x
yes (4.1.6.0)
yes (4.1.6.0)
yes
Trend Micro OfficeScan Client
5.x
yes (3.5.1)
yes (3.5.1)
yes
Trend Micro OfficeScan Client
6.x
yes (3.5.1)
yes (3.5.1)
yes
Trend Micro OfficeScan Client
7.x
yes (3.5.3)
yes (3.5.3)
yes
Trend Micro OfficeScan Client
8.x
yes (4.0.5.0)
yes (4.0.5.0)
yes
Trend Micro PC-cillin 2004
11.x
yes (3.5.0)
yes (3.5.0)
yes
Trend Micro PC-cillin Internet Security 12
12.x
yes (4.0.1.0)
yes (4.0.1.0)
-
Trend Micro PC-cillin Internet Security 14
14.x
yes (4.0.1.0)
yes (4.0.1.0)
yes
Trend Micro PC-cillin Internet Security 2005
12.x
yes (3.5.3)
yes (3.5.3)
yes
Trend Micro PC-cillin Internet Security 2006
14.x
yes (3.5.8)
yes (3.5.8)
yes
Trend Micro PC-cillin Internet Security 2007
15.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
TrustPort, a.s.TrustPort Antivirus
2.8.x
yes (4.1.10.0)
-
yes
VCOMFix-It Utilities 7 Professional [AntiVirus]
7.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
Fix-It Utilities 8 Professional [AntiVirus]
8.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
SystemSuite 7 Professional [AntiVirus]
7.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
SystemSuite 8 Professional [AntiVirus]
8.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
SystemSuite 9 Professional
9.x
yes (4.1.8.0)
yes (4.1.8.0)
-
VCOM Fix-It Utilities Professional 6 [AntiVirus]
6.x
yes (4.0.6.1)
yes (4.0.6.1)
yes
VCOM SystemSuite Professional 6 [AntiVirus]
6.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
VerizonVerizon Internet Security Suite Anti-Virus
5.x
yes (4.0.5.1)
yes (4.0.5.1)
-
Verizon Internet Security Suite Anti-Virus
7.x
yes (4.5.1.0)
yes (4.5.1.0)
-
Verizon Internet Security Suite Anti-Virus
8.x
yes (4.1.10.0)
yes (4.1.10.0)
-
VirusBlokAda Ltd.Vba32 Personal
3.x
yes (4.1.6.0)
yes (4.1.6.0)
-
VirusBuster Ltd.VirusBuster Professional
5.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
VirusBuster for Windows Servers
5.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
Webroot Software, Inc.Webroot AntiVirus
6.x
yes (4.1.8.0)
yes (4.1.8.0)
-
Webroot Spy Sweeper Enterprise Client with AntiVirus
4.x
yes (4.1.3.2)
-
-
Webroot Spy Sweeper with AntiVirus
5.x
yes (4.1.3.0)
yes (4.1.3.0)
-
Yahoo!, Inc.AT&T Yahoo! Online Protection [AntiVirus]
7.x
yes (4.0.6.1)
yes (4.0.6.1)
yes
SBC Yahoo! Anti-Virus
7.x
yes (3.5.10.1)
yes (3.5.10.1)
yes
Verizon Yahoo! Online Protection [AntiVirus]
7.x
yes (4.0.6.1)
yes (4.0.6.1)
yes
Zone Labs LLCZoneAlarm Anti-virus
6.x
yes (3.5.5)
yes (3.5.5)
-
ZoneAlarm Security Suite
5.x
yes (3.5.0)
yes (3.5.0)
-
ZoneAlarm Security Suite
6.x
yes (3.5.5)
yes (3.5.5)
-
ZoneAlarm with Antivirus
5.x
yes (3.5.0)
yes (3.5.0)
-
eEye Digital SecurityeEye Digital Security Blink Personal
3.x
yes (4.0.6.0)
yes (4.0.6.0)
yes
eEye Digital Security Blink Personal
4.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
eEye Digital Security Blink Professional
3.x
yes (4.0.6.0)
yes (4.0.6.0)
yes
eEye Digital Security Blink Professional
4.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
iolo technologies, LLCiolo AntiVirus
1.x
yes (4.1.8.0)
yes (4.1.8.0)
-
1 "Yes" in the AV Checks Supported columns indicates the Agent supports the AV Rule check for the product starting from the version of the Agent listed in parentheses (CAM automatically determines whether to use Def Version or Def Date for the check).
2 The Live Update column indicates whether the Agent supports live update for the product via the Agent Update button (configured by AV Definition Update requirement type). For products that support "Live Update," the Agent launches the update mechanism of the AV product when the Update button is clicked. For products that do not support this feature, the Agent displays a message popup. In this case, administrators can configure a different requirement type (such as "Local Check") to present alternate update instructions to the user.
3 For Symantec Enterprise products, the Clean Access Agent can initiate AV Update when Symantec Antivirus is in unmanaged mode. If using Symantec AV in managed mode, the administrator must allow/deny managed clients to run LiveUpdate via the Symantec management console (right-click the primary server, go to All Tasks -> Symantec Antivirus, select Definition Manager, and configure the policy to allow clients to launch LiveUpdate for agents managed by that management server.) If managed clients are not allowed to run LiveUpdate, the update button will be disabled on the Symantec GUI on the client, and updates can only be pushed from the server.
Clean Access AS Support Chart (Windows Vista/XP/2000)
Table 9 details Windows Vista/XP/2000 Supported Antispyware Products as of the latest release of the Cisco NAC Appliance software.
Table 9 Clean Access Antispyware Product Support Chart (Windows Vista/XP/2000)
Version 78, 4.5.2.0 Agent, CAM/CAS Release 4.5(1) (Sheet 1 of 8) Product Name Product Version AS Checks Supported
(Minimum Agent Version Needed)1 Live Update2 Installation Spyware Definition 360Safe.com AT&TAT&T Internet Security Suite AT&T Anti-Spyware
6.x
yes (4.1.10.0)
yes (4.1.10.0)
yes
AVG TechnologiesAVG 8.0 [AntiSpyware]
8.x
yes (4.1.3.2)
yes (4.1.8.0)
yes
AVG Anti-Virus Free [AntiSpyware]
8.x
yes (4.1.8.0)
yes (4.1.8.0)
yes
Agnitum Ltd.Outpost Firewall Pro 2008 [AntiSpyware]
6.x
yes (4.1.3.2)
yes (4.1.3.2)
-
AhnLab, Inc.AhnLab SpyZero 2.0
2.x
yes (3.6.0.0)
yes (3.6.0.0)
yes
AhnLab SpyZero 2007
3.x
yes (3.6.5.0)
yes (3.6.5.0)
yes
AhnLab V3 Internet Security 2007 Platinum AntiSpyware
7.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
AhnLab V3 Internet Security 2008 Platinum AntiSpyware
7.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
AhnLab V3 Internet Security 7.0 Platinum Enterprise AntiSpyware
7.x
yes (4.1.2.0)
yes (4.1.2.0)
yes
AliantAliant Business Security Suite Anti-Spyware
6.x
yes (4.5.1.0)
yes (4.5.1.0)
yes
Aliant Business Security Suite Anti-Spyware
7.x
yes (4.1.10.0)
yes (4.1.10.0)
-
Aliant Security Services Anti-Spyware
7.x
yes (4.1.10.0)
yes (4.1.10.0)
-
America Online, Inc.AOL Safety and Security Center Spyware Protection
2.0.x
yes (4.1.0.0)
-
-
AOL Safety and Security Center Spyware Protection
2.1.x
yes (4.1.0.0)
yes (4.1.0.0)
-
AOL Safety and Security Center Spyware Protection
2.2.x
yes (4.1.0.0)
yes (4.1.0.0)
-
AOL Safety and Security Center Spyware Protection
2.3.x
yes (4.1.0.0)
yes (4.1.0.0)
-
AOL Safety and Security Center Spyware Protection
2.x
yes (3.6.1.0)
yes (3.6.1.0)
-
AOL Spyware Protection
1.x
yes (3.6.0.0)
yes (3.6.0.0)
-
AOL Spyware Protection
2.x
yes (3.6.0.0)
yes (4.1.3.0)
-
Anonymizer, Inc.Anonymizer Anti-Spyware
1.x
yes (4.1.0.0)
yes (4.1.0.0)
-
Anonymizer Anti-Spyware
3.x
yes (4.1.0.0)
yes (4.1.0.0)
-
Authentium, Inc.Cox High Speed Internet Security Suite
3.x
yes (4.0.4.0)
-
yes
Bell BellSouthBellSouth Internet Security Anti-Spyware
5.x
yes (4.0.5.1)
yes (4.0.5.1)
-
BigFix, Inc.BigFix AntiPest
2.x
yes (4.1.10.0)
-
-
Cat Computer Services Pvt. Ltd.Quick Heal AntiVirus Plus [AntiSpyware]
10.x
yes (4.1.10.0)
yes (4.1.10.0)
yes
Quick Heal Total Security [AntiSpyware]
10.x
yes (4.1.10.0)
yes (4.1.10.0)
yes
Check Point, IncZoneAlarm (AntiSpyware)
7.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
ZoneAlarm Anti-Spyware
7.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
ZoneAlarm Pro Antispyware
7.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
ZoneAlarm Pro Antispyware
8.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
ZoneAlarm Security Suite Antispyware
7.x
yes (4.0.5.0)
yes (4.0.5.0)
yes
ZoneAlarm Security Suite Antispyware
8.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
Computer Associates International, Inc.CA eTrust Internet Security Suite AntiSpyware
10.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
CA eTrust Internet Security Suite AntiSpyware
11.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
CA eTrust Internet Security Suite AntiSpyware
5.x
yes (3.6.1.0)
yes (3.6.1.0)
yes
CA eTrust Internet Security Suite AntiSpyware
8.x
yes (4.1.2.0)
yes (4.1.2.0)
yes
CA eTrust Internet Security Suite AntiSpyware
9.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
CA eTrust PestPatrol
5.x
yes (3.6.1.0)
yes (4.0.6.0)
yes
CA eTrust PestPatrol Anti-Spyware
8.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
CA eTrust PestPatrol Anti-Spyware Corporate Edition
5.x
yes (3.6.0.0)
yes (3.6.0.0)
yes
CA eTrustITM Agent (AntiSpyware)
8.x
yes (4.1.6.0)
yes (4.1.6.0)
yes
PestPatrol Corporate Edition
4.x
yes (3.6.0.0)
yes (3.6.0.0)
yes
PestPatrol Standard Edition (Evaluation)
4.x
yes (3.6.0.0)
yes (3.6.0.0)
yes
EarthLink, Inc.Aluria Security Center AntiSpyware
1.x
yes (4.1.0.0)
yes (4.1.0.0)
-
EarthLink Protection Control Center AntiSpyware
1.x
yes (3.6.0.0)
yes (3.6.0.0)
-
EarthLink Protection Control Center AntiSpyware
2.x
yes (4.0.6.0)
-
-
EarthLink Protection Control Center AntiSpyware
3.x
yes (4.1.3.0)
-
-
Primary Response SafeConnect
2.x
yes (3.6.5.0)
-
-
F-Secure Corp.F-Secure (AntiSpyware)
7.x
yes (4.1.3.0)
yes (4.1.3.0)
-
F-Secure Anti-Virus (AntiSpyware)
8.x
yes (4.1.8.0)
yes (4.1.8.0)
-
F-Secure Internet Security (AntiSpyware)
7.x
yes (4.1.3.0)
yes (4.1.3.0)
-
F-Secure Internet Security (AntiSpyware)
8.x
yes (4.1.7.0)
yes (4.1.7.0)
-
FaceTime Communications, Inc.X-Cleaner Deluxe
4.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
FairPointFairPoint Security Suite Spyware Protection
7.x
yes (4.1.10.0)
yes (4.1.10.0)
-
Grisoft, Inc.AVG Anti-Malware [AntiSpyware]
7.x
yes (4.1.2.0)
-
-
AVG Anti-Spyware 7.5
7.x
yes (4.0.5.1)
yes (4.0.5.1)
-
Javacool Software LLCJavacool SpywareBlaster
4.x
yes (4.1.6.0)
yes (4.1.6.0)
-
SpywareBlaster v3.1
3.1.x
yes (3.6.0.0)
yes (3.6.0.0)
yes
SpywareBlaster v3.2
3.2.x
yes (3.6.0.0)
yes (3.6.0.0)
yes
SpywareBlaster v3.3
3.3.x
yes (3.6.0.0)
yes (3.6.0.0)
yes
SpywareBlaster v3.4
3.4.x
yes (3.6.0.0)
yes (3.6.0.0)
yes
SpywareBlaster v3.5.1
3.5.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
KephyrBazooka Scanner
1.x
yes (4.1.8.0)
-
-
Kingsoft Corp.Kingsoft AntiSpyware 2007 Free
2007.x
yes (4.1.3.2)
yes (4.1.3.2)
-
Kingsoft Internet Security 9 [AntiSpyware]
2008.x
yes (4.1.10.0)
-
-
Kingsoft Internet Security [AntiSpyware]
7.x
yes (4.0.6.1)
yes (4.0.6.1)
yes
Lavasoft, Inc.Ad-Aware
8.x
yes (4.1.10.0)
-
yes
Ad-Aware 2007
7.x
yes (4.1.3.0)
-
-
Ad-Aware 2007 Professional
7.x
yes (4.0.6.1)
-
yes
Ad-Aware SE Personal
1.x
yes (3.6.0.0)
yes (3.6.0.0)
-
Ad-Aware SE Professional
1.x
yes (3.6.1.0)
yes (3.6.1.0)
yes
Ad-aware 6 Professional
6.x
yes (3.6.0.0)
yes (3.6.0.0)
-
Lavasoft Ad-Aware 2008
7.x
yes (4.1.6.0)
-
-
Lavasoft Ad-Aware 2008 Professional
7.x
yes (4.1.6.0)
-
yes
Malwarebytes CorporationMalwarebytes Anti-Malware
1.x
yes (4.1.8.0)
-
yes
Maxion SoftwareSpy Killer
5.x
yes (4.1.8.0)
yes (4.1.10.0)
-
McAfee, Inc.McAfee Anti-Spyware Enterprise Module
8.0.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
McAfee AntiSpyware
1.5.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
McAfee AntiSpyware
1.x
yes (3.6.0.0)
yes (4.1.0.0)
yes
McAfee AntiSpyware
2.0.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
McAfee AntiSpyware
2.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
McAfee AntiSpyware Enterprise
8.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
McAfee AntiSpyware Enterprise Module
8.5.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
McAfee AntiSpyware Enterprise Module
8.7.x
yes (4.1.6.0)
yes (4.1.6.0)
yes
McAfee VirusScan AS
11.x
yes (4.0.6.1)
yes (4.0.6.1)
yes
McAfee VirusScan AS
12.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
McAfee VirusScan AS
13.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
MicroSmarts LLCSpyware Begone
4.x
yes (3.6.0.0)
-
-
Spyware Begone
6.x
yes (4.1.0.0)
-
-
Spyware Begone
8.x
yes (4.1.0.0)
-
-
Spyware Begone Free Scan
7.x
yes (3.6.0.0)
-
-
Spyware Begone V7.30
7.30.x
yes (3.6.1.0)
-
-
Spyware Begone V7.40
7.40.x
yes (3.6.1.0)
-
-
Spyware Begone V7.95
7.95.x
yes (4.1.0.0)
-
-
Spyware Begone V8.20
8.20.x
yes (4.1.0.0)
-
-
Spyware Begone V8.25
8.25.x
yes (4.1.0.0)
-
-
Spyware Begone! Version 9
9.x
yes (4.1.3.2)
-
-
Microsoft Corp.Microsoft AntiSpyware
1.x
yes (4.0.6.0)
-
yes
Windows Defender
1.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Windows Defender Vista
1.x
yes (4.0.5.0)
yes (4.0.5.0)
yes
NETGATE Technologies s.r.oSpy Emergency 2008
5.x
yes (4.1.7.0)
-
-
OmniquadOmniquad Total Security
2.0.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
Omniquad Total Security
3.0.x
yes (4.1.7.0)
yes (4.1.7.0)
-
PC Tools SoftwarePC Tools Internet Security [Antispyware]
5.x
yes (4.1.3.0)
-
-
PC Tools Internet Security [Antispyware]
6.x
yes (4.1.7.0)
-
-
PC Tools Spyware Doctor
5.x
yes (4.1.3.2)
-
yes
PC Tools Spyware Doctor
6.x
yes (4.1.7.0)
-
yes
Spyware Doctor
4.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Spyware Doctor
5.x
yes (4.0.6.0)
-
yes
Spyware Doctor 3.0
3.x
yes (3.6.0.0)
yes (3.6.0.0)
yes
Spyware Doctor 3.1
3.x
yes (3.6.0.0)
yes (3.6.0.0)
yes
Spyware Doctor 3.2
3.x
yes (3.6.0.0)
yes (3.6.0.0)
yes
Spyware Doctor 3.5
3.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Spyware Doctor 3.8
3.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Spyware Doctor [AntiSpyware]
5.x
yes (4.1.3.2)
-
yes
Panda SoftwarePanda Titanium 2006 Antivirus + Antispyware [AntiSpyware]
5.x
yes (4.1.3.2)
yes (4.1.3.2)
-
Prevx Ltd.Prevx 2.0 Agent
1.x
yes (4.1.8.0)
yes (4.1.8.0)
yes
Prevx Home
2.x
yes (3.6.0.0)
yes (3.6.0.0)
-
Prevx1
1.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Prevx1
2.x
yes (4.1.0.0)
yes (4.1.0.0)
yes
Radialpoint Inc.Radialpoint Security Services Spyware Protection
6.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
Radialpoint Security Services Spyware Protection
7.x
yes (4.1.7.0)
yes (4.1.7.0)
-
Radialpoint Security Services Spyware Protection
8.x
yes (4.1.8.0)
yes (4.1.8.0)
-
Radialpoint Spyware Protection
5.x
yes (4.0.5.1)
yes (4.0.5.1)
-
Zero-Knowledge Systems Radialpoint Security Services Spyware Protection
6.x
yes (4.0.6.0)
yes (4.0.6.0)
yes
SOFTWINBitDefender 9 Antispyware
9.x
yes (4.1.0.0)
yes (4.1.0.0)
-
BitDefender 9 Internet Security AS
9.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
BitDefender Antivirus Plus v10 AS
10.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
BitDefender Antivirus v10 AS
10.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
BitDefender Internet Security v10 AS
10.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
SUPERAntiSpyware.comSUPERAntiSpyware Free Edition
4.x
yes (4.1.7.0)
yes (4.1.7.0)
-
SUPERAntiSpyware Professional
4.x
yes (4.1.7.0)
yes (4.1.7.0)
-
Safer Networking Ltd.Spybot - Search & Destroy 1.3
1.3
yes (3.6.0.0)
yes (3.6.0.0)
yes
Spybot - Search & Destroy 1.4
1.4
yes (3.6.0.0)
yes (3.6.0.0)
yes
Spybot - Search & Destroy 1.5
1.x
yes (4.0.6.1)
yes (4.0.6.1)
-
Spybot - Search & Destroy 1.6
1.6.x
yes (4.1.7.0)
yes (4.1.7.0)
yes
SecurityCoverage, Inc.SecureIT [AntiSpyware]
1.x
yes (4.1.8.0)
yes (4.1.8.0)
-
Sereniti, Inc.Sereniti Antispyware
1.x
yes (4.0.6.0)
-
yes
The River Home Network Security Suite Antispyware
1.x
yes (4.0.6.0)
-
yes
Sunbelt SoftwareCounterSpy Enterprise Agent
1.8.x
yes (4.0.6.0)
-
-
CounterSpy Enterprise Agent
2.0.x
yes (4.1.3.0)
-
-
Sunbelt CounterSpy
1.x
yes (3.6.0.0)
-
yes
Sunbelt CounterSpy
2.x
yes (4.0.6.0)
-
yes
Symantec Corp.Norton 360 [AntiSpyware]
3.x
yes (4.1.8.0)
yes (4.1.8.0)
-
Norton AntiVirus [AntiSpyware]
15.x
yes (4.1.10.0)
yes (4.1.10.0)
-
Norton AntiVirus [AntiSpyware]
16.x
yes (4.1.7.0)
yes (4.1.10.0)
-
Norton Internet Security AntiSpyware
15.x
yes (4.1.3.0)
yes (4.1.10.0)
-
Norton Internet Security [AntiSpyware]
16.x
yes (4.1.7.0)
yes (4.1.10.0)
-
Norton Spyware Scan
2.x
yes (4.1.0.0)
yes (4.1.0.0)
-
TELUSTELUS security services Anti-Spyware
7.x
yes (4.1.10.0)
yes (4.1.10.0)
-
Tenebril Inc.SpyCatcher Express
4.x
yes (4.1.8.0)
yes (4.1.8.0)
-
Trend Micro, Inc.Trend Micro Anti-Spyware
3.5.x
yes (4.0.5.1)
yes (4.0.5.1)
-
Trend Micro Anti-Spyware
3.x
yes (3.6.0.0)
-
-
Trend Micro OfficeScan Client (AntiSpyware)
8.x
yes (4.1.8.0)
yes (4.1.8.0)
yes
Trend Micro PC-cillin Internet Security 2007 AntiSpyware
15.x
yes (4.1.0.0)
yes (4.1.3.2)
yes
VCOMFix-It Utilities 7 Professional [AntiSpyware]
7.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
Fix-It Utilities 8 Professional [AntiSpyware]
8.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
SystemSuite 7 Professional [AntiSpyware]
7.x
yes (4.0.5.1)
yes (4.0.5.1)
yes
SystemSuite 8 Professional [AntiSpyware]
8.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
VCOM Fix-It Utilities Professional 6 [AntiSpyware]
6.x
yes (4.0.6.1)
yes (4.0.6.1)
yes
VCOM SystemSuite Professional 6 [AntiSpyware]
6.x
yes (4.1.3.0)
yes (4.1.3.0)
yes
VerizonVerizon Internet Security Suite Anti-Spyware
5.x
yes (4.0.5.1)
yes (4.0.5.1)
-
Verizon Internet Security Suite Anti-Spyware
7.x
yes (4.5.1.0)
yes (4.5.1.0)
-
Verizon Internet Security Suite Anti-Spyware
8.x
yes (4.1.10.0)
yes (4.1.10.0)
-
Webroot Software, Inc.Spy Sweeper
3.x
yes (3.6.0.0)
-
-
Spy Sweeper
4.x
yes (3.6.0.0)
-
-
Spy Sweeper
5.0.x
yes (4.1.3.0)
-
-
Spy Sweeper
5.x
yes (4.1.0.0)
-
-
Spy Sweeper
6.x
yes (4.1.8.0)
-
-
Webroot Spy Sweeper Enterprise Client
1.x
yes (3.6.0.0)
-
-
Webroot Spy Sweeper Enterprise Client
2.x
yes (3.6.1.0)
-
-
Webroot Spy Sweeper Enterprise Client
3.5.x
yes (4.1.3.2)
-
-
Webroot Spy Sweeper Enterprise Client
3.x
yes (4.0.5.1)
-
-
Yahoo!, Inc.AT&T Yahoo! Online Protection
2006.x
yes (4.0.6.1)
yes (4.0.6.1)
yes
CA Yahoo! Anti-Spy
2.x
yes (4.1.3.2)
yes (4.1.7.0)
yes
SBC Yahoo! Applications
2005.x
yes (3.6.0.0)
yes (3.6.0.0)
yes
Verizon Yahoo! Online Protection
2005.x
yes (4.0.6.1)
yes (4.0.6.1)
yes
Yahoo! Anti-Spy
1.x
yes (3.6.0.0)
yes (3.6.0.0)
-
Zone Labs LLCIntegrity Agent
6.x
yes (4.1.2.0)
yes (4.1.2.0)
-
ZoneAlarm Pro (AntiSpyware)
6.x
yes (4.1.6.0)
yes (4.1.6.0)
-
iS3 Inc.STOPzilla
5.x
yes (4.1.3.2)
yes (4.1.3.2)
yes
1 "Yes" in the AS Checks Supported columns indicates the Agent supports the AS Rule check for the product starting from the version of the Agent listed in parentheses (CAM automatically determines whether to use Def Version or Def Date for the check).
2 The Live Update column indicates whether the Agent supports live update for the product via the Agent Update button (configured by AS Definition Update requirement type). For products that support "Live Update," the Agent launches the update mechanism of the AS product when the Update button is clicked. For products that do not support this feature, the Agent displays a message popup. In this case, administrators can configure a different requirement type (such as "Local Check") to present alternate update instructions to the user.
Supported AV/AS Product List Version Summary (Mac OS X)
Table 10 summarizes enhancements made for each version update of the Supported Antivirus/Antispyware Product List for the Mac OS X Clean Access Agent. See Clean Access AV Support Chart (Mac OS X) and Clean Access AS Support Chart (Mac OS X) for details.
Clean Access AV Support Chart (Mac OS X)
Table 11 lists Mac OS X Supported AV Products for release 4.5(1) of the Cisco NAC Appliance software.
Table 11 Clean Access Antivirus Product Support Chart (Mac OS X)
Version 3, 4.5.0.0 Mac OS X Agent, CAM/CAS Release 4.5(1) Product Name Product Version AV Checks Supported
(Minimum Agent Version Needed)1 Live Update 2 , Installation Virus Definition ALWIL Softwareavast! Antivirus
2.x
yes (4.5.0.0)
yes (4.5.0.0)
-
ClamWinclamXav
0.x
yes (4.5.0.0)
yes (4.5.0.0)
yes
ClamXav
1.x
yes (4.5.0.0)
yes (4.5.0.0)
yes
Computer Associates International, Inc.eTrust Antivirus
7.x
yes (4.5.0.0)
yes (4.5.0.0)
-
eTrust ITM Agent
8.x
yes (4.5.0.0)
yes (4.5.0.0)
-
IntegoVirusBarrier X
10.x
yes (4.5.0.0)
yes (4.5.0.0)
-
VirusBarrier X4
10.4.x
yes (4.5.0.0)
yes (4.5.0.0)
-
VirusBarrier X5
10.5.x
yes (4.5.0.0)
-
-
McAfee, Inc.Virex 7.2
7.2.x
yes (4.5.0.0)
yes (4.5.0.0)
-
Virex 7.5
7.5.x
yes (4.5.0.0)
yes (4.5.0.0)
-
Virex 7.7
7.7.x
yes (4.5.0.0)
yes (4.5.0.0)
-
VirusScan
8.5.x
yes (4.5.0.0)
yes (4.5.0.0)
-
VirusScan
8.6.x
yes (4.5.0.0)
yes (4.5.0.0)
-
Sophos Plc.Sophos Anti-Virus
4.x
yes (4.5.0.0)
yes (4.5.0.0)
-
Symantec Corp.Norton AntiVirus
10.x
yes (4.5.0.0)
yes (4.5.0.0)
-
Norton AntiVirus
11.x
yes (4.5.0.0)
yes (4.5.0.0)
-
Norton AntiVirus
8.x
yes (4.5.0.0)
yes (4.5.0.0)
-
Norton AntiVirus
9.x
yes (4.5.0.0)
yes (4.5.0.0)
-
Trend Micro, Inc.Trend Micro Security for Macintosh
3.x
yes (4.5.0.0)
yes (4.5.0.0)
-
1 "Yes" in the AV Checks Supported columns indicates the Agent supports the AV Rule check for the product starting from the version of the Agent listed in parentheses (CAM automatically determines whether to use Def Version or Def Date for the check).
2 The Live Update column indicates whether the Agent supports live update for the product via the manual Agent Remediate button (configured by AV Definition Update requirement type). For products that support "Live Update," the Agent launches the update mechanism of the AV product when the Remediate button is clicked. For products that do not support this feature, administrators can configure a different requirement type (such as "Local Check") to present alternate update instructions to the user.
Clean Access AS Support Chart (Mac OS X)
Table 12 lists Mac OS X Supported Antispyware Products for release 4.5(1) of the Cisco NAC Appliance software.
Table 12 Clean Access Antispyware Product Support Chart (Mac OS X)
Version 3, 4.5.0.0 Mac OS X Agent/CAM/CAS Release 4.5(1) Product Name Product Version AS Checks Supported
(Minimum Agent Version Needed)1 Live Update2 Installation Spyware Definition SecureMac.com, Inc.MacScan
2.x
yes (4.5.0.0)
yes (4.5.0.0)
-
1 "Yes" in the AS Checks Supported columns indicates the Agent supports the AS Rule check for the product starting from the version of the Agent listed in parentheses (CAM automatically determines whether to use Def Version or Def Date for the check).
2 The Live Update column indicates whether the Agent supports live update for the product via the manual Agent Remediate button (configured by AS Definition Update requirement type). For products that support "Live Update," the Agent launches the update mechanism of the AS product when the Remediate button is clicked. For products that do not support this feature, administrators can configure a different requirement type (such as "Local Check") to present alternate update instructions to the user.
Caveats
This section describes the following caveats:
•
Open Caveats - Release 4.5(1)
•
Resolved Caveats - Release 4.5(1)
•
Resolved Caveats - Agent Version 4.5.2.0
•
Resolved Caveats - Agent Version 4.5.1.0
•
Resolved Caveats - Release 4.5(0)
•
Resolved Caveats - Agent Version 4.5.0.0
Note
If you are a registered cisco.com user, you can view Bug Toolkit on cisco.com at the following website:
http://www.cisco.com/pcgi-bin/Support/Bugtool/home.pl
To become a registered cisco.com user, go to the following website:
http://tools.cisco.com/RPF/register/register.do
Open Caveats - Release 4.5(1)
Note
For caveats related to Cisco NAC Profiler, refer to the applicable version of the Release Notes for Cisco NAC Profiler.
Table 13 List of Open Caveats (Sheet 1 of 21)
DDTS Number Software Release 4.5(1) Corrected CaveatCSCsd03509
No
The Time Servers setting is not updated in HA-Standby CAM web console
After updating the "Time Servers" setting in HA-Primary CAM, the counterpart "Time Servers" setting for the HA-Standby CAM does not get updated in the web console even though the "Time Servers" setting is updated in the HA-Standby CAM database.
CSCse86581
No
Agent does not correctly recognize def versions on the following Trend AV products:
•
PC-cillin Internet Security 2005
•
PC-cillin Internet Security 2006
•
OfficeScan Client
Tested Clients:
•
PC-cillin Internet Security 2006 (English) on US-English Windows 2000 SP4
•
OfficeScan Client (English) on US-English Windows 2000 SP4
•
VirusBaster 2006 Internet Security (Japanese) on Japanese Windows XP SP2
•
VirusBaster Corporate Edition (Japanese) on Japanese Windows XP SP2
CSCsg07369
No
Incorrect "IP lease total" displayed on editing manually created subnets
Steps to reproduce:
1.
Add a Managed Subnet having at least 2500+ IP addresses (for example 10.101.0.1/255.255.240.0) using CAM web page Device Management > Clean Access Servers > Manage [IP Address] > Advanced > Managed Subnet.
2.
Create a DHCP subnet with 2500+ hosts using CAM web page Device Management > Clean Access Servers > Manage [IP Address] > Network > DHCP > Subnet List > New.
3.
Edit the newly created subnet using CAM web page Device Management > Clean Access Servers > Manage [IP Address] > Network > DHCP > Subnet List > Edit.
4.
Click Update. The CAM displays a warning informing the administrator that the current IP Range brings IP lease total up to a number that is incorrect. The CAM counts the IP address in the subnet twice, creating the incorrect count.
The issue is judged to be cosmetic and does not affect DHCP functionality.
CSCsg66511
No
Configuring HA-failover synchronization settings on Secondary CAS takes an extremely long time
Once you have configured the Secondary CAS HA attributes and click Update, it can take around 3 minutes for the browser to get the response from the server. (Configuring HA-failover synchronization on the Primary CAS is nearly instantaneous.)
CSCsh77730
No
Clean Access Agent locks up when greyed out OK button is pressed
The Clean Access Agent locks up when the client machine refreshes its IP address. This only occurs when doing an IP release/renew, so the CAS must be in an OOB setup.
If the Automatically close login success screen after <x> secs option is enabled and the duration set to 0 (instantaneous) in the Clean Access > General Setup > Agent Login page and the user clicks on the greyed out OK button while the IP address is refreshing, the Clean Access Agent locks up after refreshing the IP address. The IP address is refreshed and everything else on the client machine works, but the user cannot close the Clean Access Agent without exiting via the system tray icon, thus "killing" the Agent process.
Workaround
Either uncheck the box or set that timer to a non-zero value. If it is set to anything else, and the user hits the greyed out OK button while the IP is refreshing, then the Agent window closes successfully.
CSCsi07595
No
DST fix will not take effect if generic MST, EST, HST, etc. options are specified
Due to a Java runtime implementation, the DST 2007 fix does not take effect for Cisco NAC Appliances that are using generic time zone options such as "EST," "HST," or "MST" on the CAM/CAS UI time settings.
Workaround
If your CAM/CAS machine time zone setting is currently specified via the UI using a generic option such as "EST," "HST," or "MST." change this to a location/city combination, such as "America/Denver."
Note
CAM/CAS machines using time zone settings specified by the "service perfigo config" script or specified as location/city combinations in the UI, such as "America/Denver" are not affected by this issue.
CSCsj16366
No
Time sync on CAS
The CAS network module (NME-NAC-K9) appears as "not connected" in CAM web console after a router/rack power outage.
This issue has been observed on a NME-NAC-K9 running Cisco NAC Appliance release 4.5(1) installed in a Cisco 2821 ISR in Out-of-Band Real-IP Gateway mode. In addition, the CAM returns the following event log message:
"AutoConnectManager failed relinking CAM with CAS-i.p.add.rs."
Note
The time on the CAS module goes back to some time in 2006.
Workaround
The administrator should manually reset the system time in the CAS web console.
CSCsk55292
No
Agent not added to system tray during boot up
When the Agent is installed on a Windows client, the Start menu is updated and Windows tries to contact AD (in some cases where the AD credentials are expired) to refresh the Start menu.
Due to the fact that the client machine is still in the Unauthenticated role, AD cannot be contacted and an approximately 60 second timeout ensues, during which the Windows taskbar elements (Start menu, System Tray, and Task Bar) are locked. As a result, the Agent displays a "Failed to add Clean Access Agent icon to taskbar status area" error message.
Workaround
There are two methods to work around this issue:
•
Allow AD traffic through the CAS for clients in the Unauthenticated role.
•
Try to start the Agent manually after the install and auto load process fails.
CSCsl13782
No
Microsoft Internet Explorer 7.0 browser pop-ups on Windows Vista launched from the Summary Report appear behind the Summary Report window
This is also seen when you click on the Policy link in the Policy window. This issue appears on Vista Ultimate and Vista Home, but is not seen with Firefox or on Internet Explorer versions running in Windows 2000 or Windows XP.
Note
This problem only happens when a Google tool bar is installed and enabled in Internet Explorer.
CSCsl17379
No
Multiple Clean Access Agent pop-ups with Multi NIC in L2 VGW OOB role-based VLAN
The user sees multiple Clean Access Agent login dialogs with two or more active NICs on the same client machine pointing to the Unauthenticated network access point (eth1 IP address).
After the first Clean Access Agent pops up and the user logs in, a second Agent login dialog pops up. If the user logs in to this additional Agent instantiation there are now two entries for the same system with both MAC addresses in the CAM's Certified Device List and Online Users List.
Workaround
The user can manually Disable Agent login pop-up after authentication.
CSCsl40626
No
Cisco NAC Web Agent should handle certificate revocation dialogs similar to Clean Access Agent
Upon logging in via the Cisco NAC Web Agent (with certificate revocation turned on or with Norton 360 installed), the user is presented with a "Revocation information for the security certificate for this site is not available. Do you want to proceed?" dialog box several times (approximately 40 to 50 times). If the user clicks Yes to proceed enough times, the Web Agent fails to login and reports "You will not be allowed to access the network due to internal error. Please contact your administrator." back to the user.
CSCsl40812
No
The Refresh Windows domain group policy after login option is not functioning for Cisco NAC Web Agent
(It is working fine with the Clean Access Agent.)
This scenario was tested configuring a GPO policy for a Microsoft Internet Explorer browser title. The browser was not refreshed as expected after login in using the Web Agent.
CSCsl75403
No
MAC filter does not work for Macintosh client machines connected to the network in VPN environment
Steps to reproduce:
1.
Setup a VPN environment.
2.
Get the MAC address of the en0 interface of Macintosh client machine.
3.
Put the MAC address in the CAM device filter list with "Deny" access type.
4.
Connect the Macintosh client machine to the VPN concentrator.
5.
Agent will be allowed to perform VPN SSO [or present login page if no VPN SSO is configured].
6.
Traffic originating from the client machine on the untrusted network is allowed to go to the trusted network even though the MAC address of the client machine is denied in the device filter list.
CSCsl77701
No
Network Error dialog appears during CAS HA failover
When a user is logged in as ADSSO user on CAS HA system and the CAS experiences a failover event, the user sees is a pop-up message reading, "Network Error! Detail: The network cannot be accessed because your machine cannot connect to the default gateway. Please release/renew IP address manually."
This is not an error message and the user is still logged in to the system. The user simply needs to click on the Close button to continue normal operation.
CSCsl88429
No
User sees Invalid session after pressing [F5] following Temporary role time-out
When a user presses [F5] or [Refresh] to refresh the web page after the Agent Temporary role access timer has expired, the user sees an "Invalid" session message. If the user then attempts to navigate to the originally requested web address, they are prompted with the web login page again and are able to log in.
CSCsl88627
No
Description of removesubnet has "updatesubnet" in op field
The removesubnet API function description has "updatesubnet" listed in its operations field. The description should read "removesubnet."
CSCsm20254
No
CAS duplicates HSRP packets with Cisco NAC Profiler Collector Modules enabled.
Symptom HSRP duplicate frames are sent by CAS in Real-IP Gateway with Collector modules enabled. This causes HSRP issues and the default gateway to go down.
Conditions
Real-IP Gateway and Collector modules enabled on a CAS with ETH0 and or ETH1 configured for NetWatch.
Workaround
Do not configure the CAS' ETH0 trusted interface or ETH1 untrusted interface in the NetWatch configuration settings for the CAS Collector. It is not a supported configuration.
CSCsm20655
No
Can not do a minor upgrade for Clean Access Agent from MSI package.
When CCAAgent.msi is used and the Clean Access Agent is upgraded to a minor version (e.g. 4.1.2.1 to 4.1.2.2) the following error message will be displayed:
"Another version of this product is already installed. Installation of this version cannot continue. To configure or remove the existing version of this product, use Add/Remove Programs on the Control Panel."
This issue occurs because the Windows Installer uses only the first three fields of the product version. When a fourth field is included in the product version, the installer ignores the fourth field. For details refer to http://msdn2.microsoft.com/en-us/library/aa370859(VS.85).aspx
Workaround
Uninstall the program from Add/Remove Programs before installing it. See also Known Issues with MSI Agent Installer.
CSCsm25788
No
Avast 4.7 showing as not up to date with Cisco NAC Appliance Release 4.1(3)
User is told that Avast needs to be updated, but shows as up to date. This occurs when user is running Avast 4.7 and the Agent version is 4.1.3.0 or 4.1.3.1
Workaround
Create a custom check for Avast that allows the users on without verifying the definition version.
CSCsm53743
No
File ownership of Mac OS X Agent directory and related files should be corrected
File ownership of Mac OS X Agent and related files should be "root:admin."
Currently, the file ownership is with UID 505 and GID 505. Anyone able to assume this UID could potentially modify the Agent application files and introduce a security threat.
CSCsm61077
No
ActiveX fails to perform IP refresh on Windows Vista with User Account Control (UAC) turned on.
When logged in as a machine admin on Vista and using web login with IP refresh configured, IP address refresh/renew via ActiveX or Java will fail due to the fact that IE does not run as an elevated application and Vista requires elevated privileges to release and renew an IP address.
Workaround
In order to use the IP refresh feature, you will need to:
1.
Log into the Windows Vista client as an administrator.
2.
Create a shortcut for IE on your desktop.
3.
Launch it by right-clicking the shortcut and running it as administrator. This will allow the application to complete the IP Refresh/Renew. Otherwise, the user will need to do it manually via Command Prompt running as administrator.
This is a limitation of the Windows Vista OS.Alternatively, the Cisco NAC Web Agent can be used with no posture requirements enabled.

