<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ACS4 posture validation problems in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585245#M426981</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have exactly the same issue with CTA version 2.0.1.14 and VirusScan 8.0i.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 27 Sep 2006 12:01:42 GMT</pubDate>
    <dc:creator>m.vuckovic</dc:creator>
    <dc:date>2006-09-27T12:01:42Z</dc:date>
    <item>
      <title>ACS4 posture validation problems</title>
      <link>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585243#M426977</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We're implementing NAC and are experiencing some problems with NAI's posture valiation attributes.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Frequently the attributes for NAI's virusscan (8.0i enterprise) are not received by ACS and clients get quarantined. &lt;/P&gt;&lt;P&gt;When authentication and authorization succeeds, the NAI's attributes are displayed in the ACS's passed authentication report. But when the user gets quarantined the report doesn't show NAI's attribute values.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This gets me thinking NAI didn't supply the attribute values to CTA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone else have ACS4, CTA(latest) and NAI's AntiVirus (8i) working together as expected? If so, what was the solution to the problems you experienced (I'm guessing you've at least had some ...)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 21:38:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585243#M426977</guid>
      <dc:creator>etamminga</dc:creator>
      <dc:date>2019-03-10T21:38:31Z</dc:date>
    </item>
    <item>
      <title>Re: ACS4 posture validation problems</title>
      <link>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585244#M426979</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;CTA version 1 is not sending the Cisco:PA attribute  to ACS 4.0.But CTA version 2 is working fine.The issue is ACS 4.0 is requesting an attribute, Machine Posture State, of CTA, which CTA 1.0 does not know (Machine Posture State was added to CTA 2.0).  CTA should ignore it but it returns an error instead.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 03 Jul 2006 13:48:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585244#M426979</guid>
      <dc:creator>aghaznavi</dc:creator>
      <dc:date>2006-07-03T13:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: ACS4 posture validation problems</title>
      <link>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585245#M426981</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have exactly the same issue with CTA version 2.0.1.14 and VirusScan 8.0i.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 27 Sep 2006 12:01:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585245#M426981</guid>
      <dc:creator>m.vuckovic</dc:creator>
      <dc:date>2006-09-27T12:01:42Z</dc:date>
    </item>
    <item>
      <title>Re: ACS4 posture validation problems</title>
      <link>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585246#M426983</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Eric,&lt;/P&gt;&lt;P&gt;I'm having PV problems similuar to yours. My set-up:&lt;/P&gt;&lt;P&gt;Client pc--&amp;gt;Cisco VPN concentrator--&amp;gt;ACS4.0&lt;/P&gt;&lt;P&gt;If I enable anything but "any" in Network Access Profile/Authorization/System Posture Token, my client cannot connect. Cisco got into the boxes and then generated very detailed reports and they show that PostureValidation.dll is missing from the acs install directory. C:\Program Files\CiscoSecure ACS v4.0\Authenticators is where it should be. I re-installed but that didn't add that dll file.&lt;/P&gt;&lt;P&gt;Do you have that file in that directory? &lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Chuck&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 17 Nov 2006 21:14:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585246#M426983</guid>
      <dc:creator>cjdock123</dc:creator>
      <dc:date>2006-11-17T21:14:29Z</dc:date>
    </item>
    <item>
      <title>Re: ACS4 posture validation problems</title>
      <link>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585247#M426984</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Chuck,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm sorry. We're using the appliance version of ACS and thus do not have access to the harddrive. &lt;/P&gt;&lt;P&gt;For your information, we've stopped the NAC pilot because of too many problems with the combination ACS / Switches / Windows 2000/XP and McAfee. Both on the authentitcation as on the validation points the pilot failed dramatically. We keep hitting problems of which we amaze ourselves that they even exist. Most likely Cisco did little testing before they shipped the product (ACS).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Nov 2006 08:26:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585247#M426984</guid>
      <dc:creator>etamminga</dc:creator>
      <dc:date>2006-11-20T08:26:24Z</dc:date>
    </item>
    <item>
      <title>Re: ACS4 posture validation problems</title>
      <link>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585248#M426985</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the same problem with Panda Antivirus&lt;/P&gt;&lt;P&gt;and ACS 3.3, "same times" the Panda attributes ACS are not recived by ACS and logs a external DB account restriccion.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Nov 2006 11:50:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585248#M426985</guid>
      <dc:creator>natxoc</dc:creator>
      <dc:date>2006-11-23T11:50:47Z</dc:date>
    </item>
    <item>
      <title>Re: ACS4 posture validation problems</title>
      <link>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585249#M426986</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Natxoc,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think "External DB account restrictions" are authentication failures and not authorization failures. The attributes for anti-virus are checked in the authorization section of the whole process. So have another look at your problem to be sure it's not an authentication problem.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Erik&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Nov 2006 14:13:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585249#M426986</guid>
      <dc:creator>etamminga</dc:creator>
      <dc:date>2006-11-23T14:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: ACS4 posture validation problems</title>
      <link>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585250#M426987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Erik, Thanks&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt; yes External DB account restrictions are authentication failures. ACS fail in authentication becouse the "Mandatory credentials" are not sent by the client (Panda credentials)to ACS (Or not recived by ACS).&lt;/P&gt;&lt;P&gt;I have created another external DB with CTA the only mandatory credentials and posture token CHECKUP and now there are not clients with the DB account fail they get the Checup token.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 23 Nov 2006 16:45:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585250#M426987</guid>
      <dc:creator>natxoc</dc:creator>
      <dc:date>2006-11-23T16:45:36Z</dc:date>
    </item>
    <item>
      <title>Re: ACS4 posture validation problems</title>
      <link>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585251#M426988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think you have install the acs4 add-on (nai.adf file)for NAI AV from your description. You find example in ACS 4.0 documentation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;And on the client, verify you have this.&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://knowledge.mcafee.com/SupportSite/search.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=KB45653&amp;amp;sliceId=SAL_Public&amp;amp;dialogID=5672976&amp;amp;stateId=0%200%204773882" target="_blank"&gt;http://knowledge.mcafee.com/SupportSite/search.do?cmd=displayKC&amp;amp;docType=kc&amp;amp;externalId=KB45653&amp;amp;sliceId=SAL_Public&amp;amp;dialogID=5672976&amp;amp;stateId=0%200%204773882&lt;/A&gt;  &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Apply latest Vscan 8.0 Patch14 and latest McAfee Common Management Agent 3.6.0. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the CTA 2.0.1, in the CiscoTrustAgent dir   add "PPMsgSize=4096" in ctad.ini at the GENERAL part (top of the file).&lt;/P&gt;&lt;P&gt;This allow bigger messages from Posture Agent (NAI) to CTA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reboot and get healthy&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;//&lt;/P&gt;&lt;P&gt;Christer  &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 28 Dec 2006 14:36:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/acs4-posture-validation-problems/m-p/585251#M426988</guid>
      <dc:creator>axfood</dc:creator>
      <dc:date>2006-12-28T14:36:42Z</dc:date>
    </item>
  </channel>
</rss>

