<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Suspend security on UI in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347039#M96737</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Last question first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your rule 25 may not correspond with another CSAMC's rule 25.  It might be better to describe the rule itself such as Agent Service Control rule with High Priority Deny.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the first question,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check and see if both rules apply to the host in question.  Look at the host details and scroll down to look at all the rules that apply to the host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there is a rule that is a high priority deny for all users to suspend the agent, it will supercede any allow rules (rule 24?) that allow a host to suspend security from the UI.  If that's the case, you could try changing the deny rule from High Priority Deny to Deny or Query User (Default Deny) and see if that fixes it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 22 Mar 2005 19:18:10 GMT</pubDate>
    <dc:creator>tsteger1</dc:creator>
    <dc:date>2005-03-22T19:18:10Z</dc:date>
    <item>
      <title>Suspend security on UI</title>
      <link>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347036#M96719</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I can't suspend security (I'm administrator) on my computer via UI, however my rules for that (24) are applied for my group!&lt;/P&gt;&lt;P&gt;It doesn't recognize me as an administrator and terminate the action immediatelly(As is in the rule 25 defined).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any idea?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 10 Mar 2019 09:20:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347036#M96719</guid>
      <dc:creator>teperjesi</dc:creator>
      <dc:date>2019-03-10T09:20:54Z</dc:date>
    </item>
    <item>
      <title>Re: Suspend security on UI</title>
      <link>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347037#M96726</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Some questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do you have another High Priority Deny rule that's preventing it?  &lt;/P&gt;&lt;P&gt;Are you in test mode?  &lt;/P&gt;&lt;P&gt;What version are you running?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember that your rule 24 and 25 may not be someone elses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom S&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Mar 2005 01:00:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347037#M96726</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2005-03-22T01:00:47Z</dc:date>
    </item>
    <item>
      <title>Re: Suspend security on UI</title>
      <link>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347038#M96733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tom&lt;/P&gt;&lt;P&gt;1. How can I chek, if there any High Priority Deny Rule overt these.&lt;/P&gt;&lt;P&gt;My CSA MC tells me the following:&lt;/P&gt;&lt;P&gt;An attempt was made to suspend agent security. This was denied.Details Rule 25 &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;2. My kit is runnig in active mode, not in test mode.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3. 4.0.3.736&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What does it mean "may not be someone elses"&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Mar 2005 13:03:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347038#M96733</guid>
      <dc:creator>teperjesi</dc:creator>
      <dc:date>2005-03-22T13:03:19Z</dc:date>
    </item>
    <item>
      <title>Re: Suspend security on UI</title>
      <link>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347039#M96737</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Last question first.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Your rule 25 may not correspond with another CSAMC's rule 25.  It might be better to describe the rule itself such as Agent Service Control rule with High Priority Deny.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now the first question,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check and see if both rules apply to the host in question.  Look at the host details and scroll down to look at all the rules that apply to the host.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If there is a rule that is a high priority deny for all users to suspend the agent, it will supercede any allow rules (rule 24?) that allow a host to suspend security from the UI.  If that's the case, you could try changing the deny rule from High Priority Deny to Deny or Query User (Default Deny) and see if that fixes it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tom&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 Mar 2005 19:18:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347039#M96737</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2005-03-22T19:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: Suspend security on UI</title>
      <link>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347040#M96741</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are you able to stop the 'Cisco Security Agent' service from Services? I had a similar problem, but it worked fine from Services.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Mar 2005 16:17:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347040#M96741</guid>
      <dc:creator>mattcooling</dc:creator>
      <dc:date>2005-03-23T16:17:34Z</dc:date>
    </item>
    <item>
      <title>Re: Suspend security on UI</title>
      <link>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347041#M96746</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;first of all, thanks the clarification.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The answers:&lt;/P&gt;&lt;P&gt;I can stop the Agent Service, but my users want to use the Suspend Security feature too. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have only one High Deny RUle for the agent, but I think, it doesnt stop these feature (I tried it)&lt;/P&gt;&lt;P&gt;I copy here the rule explanation for my computer:&lt;/P&gt;&lt;P&gt;Control agent service&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The user is explicitly forbidden to modify agent configuration, irrespective of any other rules. Applications other than Virus scanner applications will be logged when trying to modify agent configuration.&lt;/P&gt;&lt;P&gt;An event will be logged when the rule is triggered. 26&lt;/P&gt;&lt;P&gt;The user is allowed to stop the agent service, if permitted by the end user and not prohibited by a high priority deny rule. Applications will be logged when trying to modify agent configuration.&lt;/P&gt;&lt;P&gt;An event will be logged when the rule is triggered. 24&lt;/P&gt;&lt;P&gt;The user is denied to suspend security from agent UI, in the absence of an allow rule. Applications will be logged when trying to modify agent configuration.&lt;/P&gt;&lt;P&gt;An event will be logged when the rule is triggered. 25&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As I can see, it have to work!&lt;/P&gt;&lt;P&gt;??? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2005 10:20:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347041#M96746</guid>
      <dc:creator>teperjesi</dc:creator>
      <dc:date>2005-03-24T10:20:55Z</dc:date>
    </item>
    <item>
      <title>Re: Suspend security on UI</title>
      <link>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347042#M96750</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The default setting for CSA is to allow the service to be stopped, but NOT allow the security to be suspended (which appears to be the case here).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What you need to do is add an 'Agent Service Control' rule which is set to 'allow', when 'any user attempts to suspend security from agent UI'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Generate &amp;amp; poll, then it should work as required.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know if not&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2005 12:49:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347042#M96750</guid>
      <dc:creator>mattcooling</dc:creator>
      <dc:date>2005-03-24T12:49:40Z</dc:date>
    </item>
    <item>
      <title>Re: Suspend security on UI</title>
      <link>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347043#M96753</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Oh man!&lt;/P&gt;&lt;P&gt;You're right!&lt;/P&gt;&lt;P&gt;It was the missundestood between the service stop and the suspend security feature.&lt;/P&gt;&lt;P&gt;I guess I can't configure my CSA, the admisitrators can suspend, but noone else! Maybe in 4.5? &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2005 15:22:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347043#M96753</guid>
      <dc:creator>teperjesi</dc:creator>
      <dc:date>2005-03-24T15:22:10Z</dc:date>
    </item>
    <item>
      <title>Re: Suspend security on UI</title>
      <link>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347044#M96755</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unless I've misunderstood it, any user can 'suspend security' if the setting is in place; the 'stop service' setting is the one that depends if you are an administrator or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Matt&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2005 15:43:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347044#M96755</guid>
      <dc:creator>mattcooling</dc:creator>
      <dc:date>2005-03-24T15:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: Suspend security on UI</title>
      <link>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347045#M96758</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Like Matt said:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any user can suspend the agent from the UI if you have a rule that allows it (by default it is denied).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any Administrator can stop the agent service (net stop csagent) if the rule allows it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This can be done in this version....&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 24 Mar 2005 19:10:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347045#M96758</guid>
      <dc:creator>tsteger1</dc:creator>
      <dc:date>2005-03-24T19:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: Suspend security on UI</title>
      <link>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347046#M96761</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are we talking about CSA 5.0 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is for me clear:&lt;/P&gt;&lt;P&gt;"Any user can suspend the agent from the UI if you have a rule that allows it (by default it is denied). "&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But untill now All local Administrators are able to start and stop the CSAgent Service - even if i try to configure something else. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Greetings&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jarle&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 26 Jul 2006 08:35:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/suspend-security-on-ui/m-p/347046#M96761</guid>
      <dc:creator>jsteffensen</dc:creator>
      <dc:date>2006-07-26T08:35:31Z</dc:date>
    </item>
  </channel>
</rss>

