Are you using ssh on the vty lines, and IOS lower than 12.2(25)SE? If so, you may be running into a know bug
The CNA RElease Notes here ( http://www.cisco.com/en/US/partner/docs/net_mgmt/cisco_network_assistant/version5_0/release/notes/OL12210a.html#wp710973 ) refer to a workaround:
Network Assistant fails when a device is running the cryptographic software image and the vty lines have been configured with the transport input ssh and line vty 0 15 global configuration commands only use SSH.
The workaround is to use the transport input ssh telnet and line vty 0 15 global configuration commands to allow SSH and Telnet access through the vty lines. After you upgrade to Cisco IOS 12.2(25)SE or higher, you can enable http or https separately from Telnet. (CSCdz01037)
If that does not help... let us know the device and version, the version of CNA, and what configuration the device has fot http, https, telnet, and ssh.
Thanks,
Curtis