<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: NAC Agent Issue in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429678#M797194</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Faisal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my problem is when NAC try to remediate the client it is getting error message (images are attached). That means if user doesn't have a privilege to udpate the antivirus, NAC agent also can not do the remediation process am I right?&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/7/8/6874-one.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/7/8/6873-two.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 14 Sep 2010 02:59:21 GMT</pubDate>
    <dc:creator>blaxucisco</dc:creator>
    <dc:date>2010-09-14T02:59:21Z</dc:date>
    <item>
      <title>NAC Agent Issue</title>
      <link>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429671#M797187</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have implemented Cisco NAC for remote VPN users. As part of this they go through 3 checks:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. Antivirus installation check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;2. Antivirus definition check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. File check&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have configured the definition check to remediate via internal update servers if 30 days or more out of date.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The issue I'm seeing is that the end user recieves the following Cisco Agent error during the remediation process (while in the temporary role):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"The remediation you are attempting is reporting an access denied error. This is usually due to a privilege issue. Please contact your system administrator."&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The definition update happens in the background though (I have allowed the required access through the NAC server) and once complete places the user in the correct role. Therefore It's no so much an issue, just a misleading message displayed to the user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Has anyone seen this before or know where this is configure?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Terry&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 12:02:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429671#M797187</guid>
      <dc:creator>Terry</dc:creator>
      <dc:date>2020-02-21T12:02:11Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Agent Issue</title>
      <link>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429672#M797188</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Terry,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What AV and what version of that AV are you running? Your users are admins on their machines?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jul 2010 14:29:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429672#M797188</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-07-26T14:29:57Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Agent Issue</title>
      <link>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429673#M797189</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Faisal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your reply, Symantec Antivirus 10.X is being used and the users (so far test machines) have admin rights.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Terry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Jul 2010 14:56:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429673#M797189</guid>
      <dc:creator>Terry</dc:creator>
      <dc:date>2010-07-26T14:56:42Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Agent Issue</title>
      <link>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429674#M797190</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Terry,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please post an agent log file from an affected machine?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If it's 4.7, it would be just running the Cisco Log Packager utility from the Start -&amp;gt; Programs menu.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Jul 2010 11:58:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429674#M797190</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-07-27T11:58:43Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Agent Issue</title>
      <link>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429675#M797191</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Faisal&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sorry about the delay, please find the agent log file attached.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kind Regards&lt;/P&gt;&lt;P&gt;Terry&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Aug 2010 15:19:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429675#M797191</guid>
      <dc:creator>Terry</dc:creator>
      <dc:date>2010-08-02T15:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Agent Issue</title>
      <link>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429676#M797192</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Faisal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also have same problem. we are using symantec endpoint 11. though user has full administrative right on the workstation it doesn't have a privilege to update the virus definition, manual definition update option has been disabled by antivirus server configuration. for the successful remediation, does user needs to have manual update privilege?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Laxman&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Sep 2010 02:48:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429676#M797192</guid>
      <dc:creator>blaxucisco</dc:creator>
      <dc:date>2010-09-13T02:48:51Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Agent Issue</title>
      <link>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429677#M797193</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Laxman,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the AV server has the update options disabled, I don't think NAC can do anything here. You'll have to work with the AV server's admin to ensure that your users can do manual update of their AV, if need be.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Sep 2010 02:04:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429677#M797193</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-09-14T02:04:56Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Agent Issue</title>
      <link>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429678#M797194</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Faisal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;my problem is when NAC try to remediate the client it is getting error message (images are attached). That means if user doesn't have a privilege to udpate the antivirus, NAC agent also can not do the remediation process am I right?&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/4/7/8/6874-one.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/3/7/8/6873-two.jpg" class="jive-image" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Sep 2010 02:59:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429678#M797194</guid>
      <dc:creator>blaxucisco</dc:creator>
      <dc:date>2010-09-14T02:59:21Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Agent Issue</title>
      <link>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429679#M797195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Laxman,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The screenshots suggest you have a newer version of the agent running. This agent should have been installed as an administrator. If it wasn't then you would see the privilege problems.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Can you please verify whether the agent was installed as an admin? If not, can you install it as one and try your test again?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Faisal&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Sep 2010 03:58:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429679#M797195</guid>
      <dc:creator>Faisal Sehbai</dc:creator>
      <dc:date>2010-09-15T03:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: NAC Agent Issue</title>
      <link>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429680#M797196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Faisal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;this agent has been installed via centrally, pushing from the software deployement server. and we have to install to all computers (aobut 1500) by same way. int this scenario, its not easy to install the agent with administrative privilege&amp;nbsp; on the all pcs. so, which version of nac agent should I use to eliminate this problem?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thank you&lt;/P&gt;&lt;P&gt;Laxman&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 15 Sep 2010 04:08:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429680#M797196</guid>
      <dc:creator>blaxucisco</dc:creator>
      <dc:date>2010-09-15T04:08:51Z</dc:date>
    </item>
    <item>
      <title>NAC Agent Issue</title>
      <link>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429681#M797197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Faisal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have the same problem. My users get redirected to a web page with a link to install the NAC agent, this installation used to fail. So I made the user an admin on his own machine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The installation now succeeds, so the agent is being installed as a Local Admin, however I still get the exact same error above.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently my ISE is handing out agent version 4.9.0.37&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mario&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 21 May 2012 13:51:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429681#M797197</guid>
      <dc:creator>marioderosa2008</dc:creator>
      <dc:date>2012-05-21T13:51:57Z</dc:date>
    </item>
    <item>
      <title>NAC Agent Issue</title>
      <link>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429682#M797198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi Faisal,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am still having this problem.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Even though the agent displays that error message, the AV still updates in the background. The problem then is that the agent fails to realise that the definitions are then fully up to date and does not re-check posture automaticly. therefore i am having to disconnect and re-connect the network cable for the agent to realise that I am not fully compliant.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there anything that i can do to make this posture / remediation process, automatic and seemless?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Mario&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Jun 2012 12:40:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/nac-agent-issue/m-p/1429682#M797198</guid>
      <dc:creator>marioderosa2008</dc:creator>
      <dc:date>2012-06-19T12:40:11Z</dc:date>
    </item>
  </channel>
</rss>

