Educause Security Discussion mailing list archives

Re: Cisco Clean Access & Impulse Point...


From: Chad McDonald <chad.mcdonald () GCSU EDU>
Date: Thu, 14 Jul 2005 16:53:52 -0400

Mark we have a pilot of Impluse going live on the 22nd of this month.  You
are welcome to contact me for details, or to take a drive down to see it.


On 7/14/05 3:40 PM, "Mark Staples" <mstaples () MAIL MCG EDU> wrote:

Anyone pilot both CCA and Impulse Point (http://www.impulse.com/)?  Impulse
Point was designed for higher ed and is priced very attractively.  So far,
we've only seen presentations and nothing live.
Any feedback would be great.

Mark

-----
Mark Staples
Director of Information Security/Chief Information Security Officer
IT Research Liaison
Medical College of Georgia
Office: 706-721-1577
mstaples () mcg edu

--------

All information in the communication, including attachments, is strictly
confidential and intended solely for delivery to the addressee(s) identified
above (ie, To/cc/bc), and may contain privileged, confidential, proprietary
and /or intellectual property entitled to protection from disclosure under
applicable law.  If you are not the intended recipient, please take note that
any use, distribution or copying of this communication is unauthorized and may
be unlawful.  If you have received this communication in error, please notify
the sender, delete this correspondence from your computer, and destroy any
printed copies of this communication.

franklin () TXSTATE EDU 07/14/05 3:13 PM >>>
This is a response from our network lead who implemented CCA a month or
so ago:

I got tired of trying to keep up with the IP's used for windows update.
Using the host names is much better, but even then it's a moving target.
Microsoft sometimes adds new sub domains and in the latest version of
the update page it's a url under microsoft.com.

We are allowing traffic to everything ending in microsoft.com and
g.msn.com. That way the updates always work (so far) and students can
search for and download patches manually. There are cases when windows
update claims that a machine is fully patched but it is still missing
something. The helpdesk can tell what's missing from the reports and the
student can search for KBxxxx and download and install it manually.

Anders Engle
Systems Programmer I
Texas State University

-----Original Message-----
From: Flagg, Martin D. [mailto:FlaggMD () HIRAM EDU]
Sent: Thursday, July 14, 2005 1:13 PM
To: SECURITY () LISTSERV EDUCAUSE EDU
Subject: [SECURITY] Windows Updates and Cisco Clean Access


We are implementing Cisco Clean Access (formally Perfigo).  It has gone
really well but we keep coming up with problems with Windows Update, it
fails because CCA is blocking the IP.  When this happens, I use a
sniffer and add the new IP address that Microsoft is using and then it
works, until they change address's again.  Cisco says use the Host
setting allowing requests that end in "update.microsoft.com".  This does
not always work.

I am really at a loss because it works for 95% of the machines but I can
not afford to have 5% of the students in my office when they get back
from the summer.

Any Ideas?

Martin Flagg
Hiram College




Current thread: