COME VISIT MY NEW BLOG:

Friday, September 28, 2007

Custom Checks - Integration with Big Fix for Remediation

Background:

BigFix (www.bigfix.com) is one of the many remediation software solutions available that can work with NAC for a better end user experience. BigFix can enforce that a client has the proper software, patches, and updates on a device. This sounds a bit like NAC, but the missing puzzle piece is how to enforce that bigfix is really on the connecting device and doing its job? This posting will talk about some of checks that may be created to enforce the presence and compliance of bigfix on a device connecting into the network.

***Please note that there are many ways of looking for installed/running software and it is best practice to check in two different manners(e.g. service and application check), but to keep this post more straightforward, I will only shows one of the checks.


Is BigFix Installed:

In order to properly assess if BigFix is installed, the following checks if the BESClient is actually there.

Check Category: File Check
Check Type: File Existence
Check Name: BigFix_Installed
File Path: SYSTEM_PROGRAMS\BigFix Enterprise\BES Client\BESClient.exe
Check Description: Check if BigFix is Installed
Operating System: Windows All

Figure 1 - Check if BigFix is Installed

Using a Link or File type requirement for this check will give administrators the ability to offer the BESClient to users that do not have it installed. This will ultimately save on help desk calls and bring the host into compliance automatically.


Is BigFix Running:

Next, it is good to check if BigFix is actually running. The following custom check looks if the BESClient service is running.

Check Category: Service Check
Check Type: Service Status
Check Name: BigFix_Running
Service Name: BESClient
Check Description: Check if BigFix is Running
Operating System: Windows All

Figure 2 - Check if BigFix is Running

If a user does not have the BESClient running, we can use a Launch Programs requirement type to launch the BESClient. Look back to the blog for a future post on Launch Program Requirements.


Is BigFix Compliant:

Finally, BigFix has the ability to create central policy about what is needed on an end host. If the host has the latest patches, updates, etc. then the BESClient actually reports itself as "Compliant". The following custom check looks if the BESClient is reporting itself compliant.

Check Category: Registry Check
Check Type: Registry Value
Check Name: BigFix_Compliant
Registry Key: HKLM\SOFTWARE\BigFix\EnterpriseClient\Settings\Client\_BESClient_BigNACresult\
Value Data Type: String
Operator: Equals
Value Data: Compliant
Check Description: Check if BigFix is Compliant
Operating System: Windows All

Figure 3 - Check if BigFix is Compliant
This shows how if you already have policy created on your remediation platform, NAC Appliance can leverage that information by enforcing compliance to the policy before entry to the network.


Summary:

NAC Appliance may leverage the functionality of other vendors' Remediation solutions by using them to remediate non-complaint host. NAC, in some occasions, can even enforce policies or requirements of those solutions to hosts before the device is allowed on the network. This post should help administrators understand that the integration can be preformed and really will help leverage the existing investments made in remediation solutions.

Friday, September 21, 2007

Chalk Talk Series 3 - Update

To give everyone the update, the following is the schedule for the upcoming NAC chalk talks:

September 27th: Cisco NAC Profiler Introduction
Prem Ananthakrishnan will introduce the Cisco NAC Profiler, which discovers, tracks,
and monitors all non-PC endpoints attached to a network. By adding Profiler to a NAC
deployment, customers can apply policies and access prvileges to non-PC endpoints.

October 4: Secure Guest with Cisco NAC
Enhance guest access with Cisco’s NAC Guest Server. Syed Ghayur will introduce the
advanced provisioning and reporting features of this latest addition to the Cisco NAC
product line.

Access Information:

Time - 10am PDT, 12pm CDT, 1pm EDT
Audio - Toll-free US/Canada: 1-800-370-2618
Meeting ID: 321456#
Web - Disable any pop-up blocker software
http://gc46gw1.meetingplace.net
Enter Meeting ID 321456

Tuesday, September 18, 2007

Priveon Launches Real World NAC Appliance Training

Most training courses prepare individuals for certifications, but Priveon's Real-World training is the exact opposite. Their new Cisco NAC Appliance class is focused around how to design, deploy, operate and optimize Cisco NAC. With 20 labs and a topology that mimics typical organizations' environments, the class is very impressive and valuable for everyone interested or involved with Cisco NAC Appliance! I have personally reviewed the class and I highly recommend it to anyone wanting to take their expertise to the next level.


www.priveon.com

Priveon NAC Appliance Training Page
http://www.priveon.com/training/cisco-naca-training/priveon-real-world-naca-training.html

Saturday, September 15, 2007

NAC Chalk Talk Video on Demand (VOD) - A success for Force 3 and its clients

For those of you who missed the NAC Chalk Talk I did on Thursday, here is the link to the Video on Demand, so that you can catch some of the deployment best practices.

Cisco NAC Appliance: A Success for Force 3 and Its Clients


http://tools.cisco.com/cmn/jsp/index.jsp?id=65948

I also want to thank the NAC Appliance Business Unit at Cisco and specifically Prem who hosted me out in San Jose, he is the real Rock Star!

Friday, September 7, 2007

NEW NAC Chalk Talk Series - Starting Sept 13th

There is a new NAC chalk talk series starting next week and excitingly enough I will be the first person to present! My chalk talk will be focused around how to make your deployment more successful. This is your chance to ask me questions and get the answers live via IPTV! :)

If you are unfamiliar with the NAC chalktalks, they are a great source of information about how to design, deploy, configure, troubleshoot, operate and optimize Cisco NAC Appliance. Please review the existing series by visiting the below link:
View the existing NAC Chalk Talks



The details of my up coming chalk talk:

CISCO NAC APPLIANCE CHALK TALK SERIES 3

Kicking off SEPTEMBER 13th with a LIVE VIDEO BROADCAST featuring Jamie Sanbower from Force 3 --

Cisco NAC Appliance: A Success for Force 3 and Its Clients

Watch this interactive session to learn Force 3's secret to NAC success, key deployment strategies and how they use Cisco NAC to solve their client business requirements.

Date: Thursday, September 13th
Time: 10am PDT/12pm CDT/1pm EDT
Location: http://tools.cisco.com/cmn/jsp/index.jsp?id=65688 (requires CCO login)

No pre-registration required.


There will be additional chalk talks continuing the weeks following the 13th, so be sure to check back here for updates on the others!

Configure And Troubleshoot the Antivirus Definition Updates

Cisco posted a new Configuration Guide on how to configure and troubleshoot Antivirus Definition Updates. This is relevant for any deployment using Cisco Preconfigure AV definition rules.

NAC Appliance (Cisco Clean Access): Configure And Troubleshoot the Antivirus Definition Updates

Thursday, September 6, 2007

Cisco NAC Profiler Documentation

Cisco NAC Profiler is here, and let me tell you this product makes deployments go a lot smoother. How nice is it not to have to find all of your Printers, IP Fax Machines, UPS management, Game Consoles, etc.

If you are interested in NAC Profiler services or consulting, please contact me jsanbower hotmail.com or visit www.force3.com

To save everyone some time, the following is a list of all the public documentation on Cisco NAC Profiler:

Cisco NAC Profiler Data Sheet
http://www.cisco.com/en/US/products/ps6128/products_data_sheet0900aecd806b7d4e.html

Cisco NAC Profiler Brochure
http://www.cisco.com/en/US/products/ps6128/prod_brochure0900aecd806b7e8c.html

Cisco NAC Profiler Q & A
http://www.cisco.com/en/US/products/ps6128/products_qanda_item0900aecd806b5d40.shtml

Cisco NAC Profiler Ordering Guide
http://www.cisco.com/en/US/products/ps6128/prod_bulletin0900aecd806b7d69.html

Configuration Guide 2.1.7
http://www.cisco.com/en/US/docs/security/nac/profiler/configuration_guide/217/nac_profiler_cg.html

Thursday, August 23, 2007

NAC Network Modules

I just wanted to give everyone the update on the NEW NME-NAC-K9 module. They are supported as of version 4.1(2). The Cisco NAC Network Module (NME-NAC-K9) implements the Clean Access Server functionality on the next generation service module for the Cisco 2811/2821/2851 and 3825/3845 access routers. The NAC network module is pre-installed with Cisco NAC Appliance software release 4.1(2) (or later), with the Clean Access Server software running as the application code. The Clean Access Server operating system is based on an optimized version of Linux. The NAC network module is an ideal NAC solution for small groups of users in remote locations where an integrated services router is used. The NAC network module can be equipped with either a 50-user or 100-user license to support branch offices.

The following are some documents to get you started with the new NAC Network Module:


Getting Started with Cisco NAC Network Modules in Cisco Access Routers

http://www.cisco.com/en/US/products/ps6128/prod_installation_guide09186a008086aa28.html
-- New guide describing initial configuration and deployment examples


Installing Cisco Network Modules in Cisco Access Routers

http://www.cisco.com/en/US/products/hw/modules/ps2797/products_installation_guide_chapter09186a008007c8ec.html
-- New Chapter in the Cisco Network Modules Hardware Installation Guide

Tuesday, August 21, 2007

Book Review - Cisco NAC Appliance Book

Title: Cisco NAC Appliance: Enforcing Host Security with Clean Access
Author: Jamey Heary, CCIE #7680

Contributing Authors: Jerry Lin, CCIE #6469, Chad Sullivan, CCIE #6493, and Alok Agrawal
Publisher: Cisco Press

I want to start out by saying that this book completely exceeded my expectations for the first NAC Appliance book. I wish this was published 3 years ago. The author clearly articulates the business benefits of NAC, including how NAC provides return on investment (ROI), which gives any reader the know-how to wisely purchase Cisco NAC Appliance. He also shows his technical expertise by diving extremely deep into the inner workings of Cisco NAC Appliance, which gives engineers, consultants, and operations the information they need to successfully deploy or maintain the product.

This book shows great details into the process flows of In-Band & Out-of-Band users, Clean Access Agent (CAA) users and network scanning users. The information on the different deployment options and how to use them in diverse environments is great to start your NAC Design. This book makes the confusing topics seem easy and manageable.

Some of the highlights that caught my eye and I thought everyone would like were:

  • Chapter on Host Security Policy – An amazing deal of information on how to design/create a Host Security Policy as it relates to NAC Appliance is invaluable to deployments
  • Exploration of High Availability and Load Balancing – Information on how to load balance Clean Access Servers using the CSM, CSS, ACE and PBR cannot be found anywhere else. This includes saving money on Failover Bundles by using N+1 Failover
  • Layer 3 OOB Deployment options – Walk through of the benefits of the different methods of deploying L3 OOB, e.g. PBR, ACLS, VPNs, etc.
  • Deployment Best Practices – An entire chapter on how to plan, schedule, and keep all parties happy for your NAC Appliance deployment
  • Monitoring & Troubleshooting information – detailed list of all logs located on the CAM and CAS, as well as the information on how to troubleshoot and monitor online users

All in all this is a great book and I would recommend it for all people interested in Buying, Deploying, Operating, or Troubleshooting Cisco NAC Appliance. This is definitely a great reference manual to have at your desk!

Buy it at amazon or ciscopress

Friday, August 17, 2007

NAC WSUS Requirement Type

Background:

New to 4.1.1, WSUS Requirements gives NAC Appliance administrators the ability to seamlessly integrate with local WSUS servers or utilize Microsoft Servers to ensure users are up to date on their microsoft service packs and patches.

Configuring WSUS Requirements:

The following are a list of options when configuring a WSUS Requirement:

  • Update Validation source - This involves checking to see if a particular client machine is up to date with patches. This check can be done against the WSUS server itself OR against Cisco rulesets.
    • Cisco Rules - In this case, the new “WSUS Server Update services” requirement needs to be mapped to the standard Cisco rule sets such as XP_hotfixes etc. Standard registry scans will be performed on the client machine based on these rule sets.
    • WSUS Server - In this case, the CCA Agent makes an API call to the WSUS Agent on the client machine to check compliance. Since our rule set is not used here (direct interaction between WSUS client and server, no need to map the Rule set to the requirement.
  • Update Installation source - This involves remediating the user after we have established that he/she is non-compliant. The remediation can be done either from local WSUS servers OR against WindowsUpdate
    • WSUS Servers - Download and Install the patches from the local WSUS servers.
    • Windows Update - Download and install patches from Microsoft Windows Update website
  • Update Installation type - This involves deciding what type of hotfixes should be downloaded and installed from the chosen source.
    • Express - This option installs the same Windows updates as would be available from the Windows Update application "Express" option. (For example, the Windows "Express" option may include just Critical and Important security updates or could call for installing an entire service pack update.)
    • Custom - Use this setting and the associated dropdown menu to install updates based on their severity by choosing Critical, Medium, or All from the associated dropdown menu. If you select Critical only the most severe/critical Windows updates are installed; selecting Medium means all updates (except for those classified as "low severity" by Microsoft) are installed; selecting All means that all of the currently available Windows Updates are installed, regardless of severity.
    • Upgrade to Latest OS Service Pack - automatically install the latest service pack available for the user's operating system.
  • UI Experience - This setting controls what the end user sees when the Updates are being installedlist of options when
    • Show UI - The Windows Update UI (showing that patches are being installed) is displayed to user
    • No UI: Updates are done silently and user does not see any UI that shows updates are being installed
Figure 1 - Configuring a WSUS Requirement

Notes on configuring WSUS Requirements:
  • Validation against WSUS server may take between 10-15 seconds
  • Make sure Access is opened to WSUS server or Windows update server in the temporary role (depending on what is being used)
  • Make sure that the client PC can talk to the WSUS server on port 80/443. These are the ports client machine uses to talk to WSUS server
  • WSUS updates may take long. So, it is important to set the Session Timer for the temporary role long enough to allow enough time for the updates to complete.
  • In order to support Windows Server Update Services operations, client machines must have version 5.4.3790.1000 (or a more recent version) of the WUAUENG.dll file installed.
  • If there are update errors, see C:\Windows\Windows Update.log or C:\Windows\WindowsUpdate.log.
  • To see if you have a Local WSUS server configured go to HKLM\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate and the "WUServer" key will have the server listed.
Summary:

WSUS Requirements are a great new best practice method to ensure Microsoft is truly up to date.

Sources: 4.1(2) CAM Admin Guide; Whats New 4.1(1)

Monday, August 13, 2007

CAA Requirement Best Practices - Enforce Types

In the world of NAC Appliance, when using the NAC Agent, there are 3 different type of enforcement types. At first look you have the ability to use the following enforce types:

Audit—Silently audit. The client system is checked "silently" for the requirement without notifying the user, and a report is generated. The report results (pass or fail) do not affect user network access.

Optional
—Do not enforce requirement. The user is informed of the requirement but can bypass it if desired (by clicking "Next"). The client system does not have to meet the requirement for the user to proceed or have network access.

Mandatory—Enforce requirement. The user is informed of this requirement and cannot proceed or have network access unless the client system meets it.

So why is this so important for NAC Deployments.... This gives administrators the ability to deploy with the least impact as possible. All deployments should start with AUDIT type requirements. By doing this we are able to see how many users are coming onto the network without compliant workstations. From this information we can see if all methods of users getting patches, updates, etc are correctly working. (E.G. if WSUS or EpolicyOrch is not working correctly you will immediately see almost all hosts out of compliance)

Next, you should change all of the previous AUDIT requirements to OPTIONAL requirements. This will still allow users access, in case of any discrepancy in your policy or remediation strategy, but will get them through any hurdles of learning how to self-remediate.

Finally, utilize MANDATORY requirements to ensure that all policy is enforced.

The last major idea that should be taken into account is how to schedule this type of roll out. I typically recommend 30-45 days for AUDIT requirements and then 30-60 days for OPTIONAL requirements, but this must be determined on a per organization basis. The key thing to take from this posting is that you do have this wonderful option to phase the enforcement of policy for your NAC deployment and it will help ensure a smooth transition for administrators and end users. One less talked about configuration option that you can use to make your NAC deployment more successful.

Sunday, August 5, 2007

Jamey Heary's Cisco NAC Blog on Network World

Make sure to check out the new blog on Cisco Subnet. Jamey Heary the author of the New Cisco NAC Appliance Book is writing it. It can be checked out here:

http://www.networkworld.com/community/heary


About the Blogger:

Jamey Heary, CCIE No. 7680, is a security consulting systems engineer at Cisco. He leads its Western Security Asset team and is a field advisor for Cisco's global security virtual team. Jamey is the author of the recently published Cisco NAC Appliance: Enforcing Host Security with Clean Access. His areas of expertise include network and host security design and implementation, security regulatory compliance, and routing and switching. His other certifications include CISSP, CCSP, and Microsoft MCSE. He is also a Certified HIPAA Security Professional. Jamey has been working in the IT field for 14 years and in IT security for 9 years