Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations Mike Lewis on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Challenge and response

Status
Not open for further replies.

37grove

MIS
Jun 29, 2002
65
US
Hello,

I’m new to McAfee and I was given the following task. What my boss wants to do is setup McAfee 8.5.0i to scan a system during the logon to our network using RAS. If during the scan it does not identify the systems as having any antivirus it will not allow them to proceed and disconnect them.

Can this be done with McAfee VirusSacn Enterprise 8.5.0i and ePolicy 3.6.1?

Thanks,
 
Looks to me like Network Access Control (NAC) Task.

As far as I know, EPO can't do that , and it's not meant for that.

Chris
 
Chris,

Appreciate the information, now I need to find a solution for what he wants.

Gary


 
Strictly speaking: invest in NAC solution :)

if your boss does not agree:), Logon script can help you detect the AV (query te registry + services running to be sure)

For non-compliant PC, they must be using VBS to drop the RAS connection, but i don't have ready solutions
 
McAfee also has another product called Policy Enforcer (additional license, more licensing $$$, but still much cheaper than most NAC solutions) that snaps into ePO 3.5 and above called Policy Enforcer--am currently doing a proof-of-concept of it. When an unmanaged rogue device is discovered on the network based on O/S platform, patch level, A/V and other administrator-configured policies, the product can communicate directly with a variety of network switches (Cisco specifically in my case) to drop the offending switch port or quarantine the device in an isolated VLAN. LOTS of engineering decisions and configuration work to do before you're ready to lock out your first intruder, but every NAC solution is pretty much like that.--The Bug Guy
 
FrogEater,

My boss does want a NAC. He's got me looking at McAfee Network Access Control, part of policy enforcer to see how much it's going to cost us. In the mean time if you have a script to query for AV on a system will you posted it here for me to take a look at?


Bug Guy,

Thanks for the info about the amount of work it's going to take to get any NAC solution in place. I'm going to let my boss know and hopefully we'll get a vendor to do it all instead of me.

 
Yeah, I had considered handing it off to a vendor, but, thinking it through to its logical conclusion, I'll eventually be managing it, so I need to make a lot of the platform policy decisions. Improves my chances of correcting the problem the day that it quarantines a half-dozen production servers and bumps a C-level officer's machine off the network. I wouldn't necessarily be a hero, but I'd probably be less a goat....--The Bug Guy
 
Chris,

Thank you very much for you time and really appreciate your help.

Gary
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top