12-26-2011 08:49 PM - edited 03-10-2019 06:39 PM
Hello guys,
I need some help here for updating the Cisco NAC AV Definition File, before that i have question.
Can i confgure cisco nac to check the Antivirus Definition file Update from AV Central Server and then check the clients for the same definition version ??? if Yes . How?
Where can i update AV Definition file regularly. because our cmopany updates the AV Definitions every day. so how cisco NAC knows which one is the latest and from where it verifies ??
Thanks in advance.
12-27-2011 04:59 AM
The condition for AV definition is "is more recent than x days old" on the NAC CAM.
So NAC doesn't need to check with any AV server what is the latest. It just checks that the client definition date is within X days of the current date. X being confurable on the CAM.
12-27-2011 05:08 AM
Ok now i forgot to tell about our network....
my NAC is not connected to internet. not possible to connect, i have created a "Check" for checking the virus definition update version in registry. it works, but when i click "Update" from the NAC Agent it is not updating antivirus. i have to manually update the antivirus.
My question is Why the NAC agent is not communicating with antivirus agent to update it?
Can you please help?
12-27-2011 05:14 AM
Ok that's a different question.
A manual update of the antivirus when the PC is in the quarantine state is working ?
This means that the clietn has the right access to the network to update itself, so that's good.
Then there's no real explanation why the NAC agent can't trigger the update. Btw, this NAC agent button to repair is actually just an API call to the AntiVirus and it's still the antivirus updating itself. So there's no real reason that it's not working. I would advise checking on the agent logs, but this is best done through a TAC case then as those logs requires TAC decoding tool
12-27-2011 05:22 AM
Yes Correct,... Manuall update of antivirus when the PC is in quarantine state is working...it updates, but same the NAC agent is not triggering the antivirus update,
Ok thanks Nicolas, i think i have to open TAC case for this issue.
One thing more, does it has anything to do with av-posture-pack-win-3.4.16.1.tar.gz ??
should i update this module ???
12-27-2011 05:26 AM
the latest is 3.4.21.1
This compliance module just contains all the details of the newest antivirus.
If you have an antivirus that was supported by your NAC version when it was out, it's ok.
If you updated the Anti-virus version then you need it yes.
The module is an alternative for when the CAM doesn't have internet access to stay up to date.
01-01-2012 11:52 PM
thanks Nicolas,
Is there anyway to update Cisco NAC Manager/Server for Antivirus Definition updates ??? because my network is not connected to Internet and there is no chance for doing the same, we can do is manaullay update every thing.
01-02-2012 12:30 AM
Well, this module above does that precisely ...
01-02-2012 12:40 AM
Nicolas, this virus Definition is updated daily from antivirus vendors..
but when i check from NAC Manager, Clean Access Agent > Rules > AV/VS Support > for McAfee inc, it is showing the lateest definition version 6183, but here we have 6586.000 even after upgrading this av module yesterday.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide