cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
369
Views
5
Helpful
1
Replies

Need a rule on NAC to Deny Access to XP machines

Pete89
Level 2
Level 2

We are running NAC 4.9.1 and I am trying to think of a way to deny any Windows XP client from getting full network acces. I created a new check that looks at the registry key under:

 

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProductName

 

For any string that contains "Windows XP". I have it on Audit right now and I can see in the logs the XP mahcines are hitting this requirement.

 

Now, how can I deny on this check?

 

 

1 Accepted Solution

Accepted Solutions

edelgado
Level 1
Level 1

Hello,

 

The NAC itself has on the compliance rules the different OS's that you want to allow on your network.

 

Just create a compliance rule saying that you only allow windows 7. This will work much better than the registry condition.

 

I used to support this product back in Cisco but unfortunately I dont have access to one NAC server so I dont remember where is this option exactly.

 

If you need more assistance feel free to ask and I will be happy to assist.

 

Regards,

 

Erdelgad

View solution in original post

1 Reply 1

edelgado
Level 1
Level 1

Hello,

 

The NAC itself has on the compliance rules the different OS's that you want to allow on your network.

 

Just create a compliance rule saying that you only allow windows 7. This will work much better than the registry condition.

 

I used to support this product back in Cisco but unfortunately I dont have access to one NAC server so I dont remember where is this option exactly.

 

If you need more assistance feel free to ask and I will be happy to assist.

 

Regards,

 

Erdelgad