Network Access Control

 View Only
Expand all | Collapse all

Compliance Notifications from SEPM

  • 1.  Compliance Notifications from SEPM

    Posted Oct 21, 2009 08:33 AM

     

    I have a HI rule stating that client must have endpoint protection running with no worse then 7 days old defs. I also set up a compliance notification to email if there are any Compliance events. Will I get a notification if a new machine comes on the network that isn’t running the NAC agent? I will be using either a DCHP or Lan Enforcer to force the Quarantine. If so what will the notification say.? What information about the client would it show, Or will it just quarantine the machine, without any alert.

    The notifcation I set up is under client security. All Compliance  events.  Is there a another notification besides that.  My goal is to get alerts everytime someone fails a Compliance check, with or without the agent installed.


  • 2.  RE: Compliance Notifications from SEPM

    Posted Oct 21, 2009 12:45 PM
    Take a look at this KB - Configuring notifications for Host Integrity checks
    http://seer.entsupport.symantec.com/docs/333040.htm

    Let me know if this failed to answer your questions.

    Thomas


  • 3.  RE: Compliance Notifications from SEPM

    Posted Oct 21, 2009 03:16 PM

    This KB has to do with what the client will see if they fail a notification,  It does not answer my question.  The Alerts I'm referring to are the alert the SEPM will send to me, as the admin of SEPM

    My goal is to get alerts everytime someone fails a Compliance check, with or without the agent installed.



  • 4.  RE: Compliance Notifications from SEPM

    Posted Oct 21, 2009 04:48 PM

    THis may or may not be where you went to add your notification, but I figured I'd add my 2 cents. 

    Notifications are set on the SEPM via "Monitors" --> "Notifications" Tab.  Here, you can choose add notificationsNew Picture (2).png

    Once you click on "Client Security Alert", you will have a number of options to choose from.  You can choose to filter whether to monitor by Group, Domain, Server, or even individual computer.

    If you check the options "Compliance events" and "Write the notification to the database"  you should be notified if a Client passing through the Enforcer is Allowed or denied.  Another key option to select is report type (Summary Report or Client List).

    Excerpt from the Help Article:
    COMPLIANCE EVENTS: For Client security alert, specifies that a compliance-related event, such as a Host Integrity failure, should trigger this notification.

    REPORT TYPE: Specifies the content of the email notification.
    This option is only available for the Client security alert, New risk detected, Risk outbreak, and Virus definitions out-of-date notification conditions.
    Note: 
     This option does not apply when the action is to run a batch file or executable file.
     
    You can select one of the following to be attached to the email notification as a .mht file:

    Summary report
    A report that summarizes the activity that triggered the notification

    Client list
    The event list that triggered the notification

    New Picture (4).png

     



  • 5.  RE: Compliance Notifications from SEPM

    Posted Oct 21, 2009 05:05 PM
    The above is what I configured. 


    Now to the big question.

    Will I get a notification if a new machine comes on the network that isn’t running the NAC agent? I will be using either a DCHP or Lan Enforcer to force the Quarantine. If so what will the notification say.? What information about the client would it show, Or will it just quarantine the machine, without any alert.


  • 6.  RE: Compliance Notifications from SEPM

    Posted Oct 22, 2009 12:11 PM

    It should show in the report "Symantec Agent is not running or running an incompatible version."  This is a generic message that may be seen for other reasons (requiring further investigation), but mostly covers clients that have not had the Agent installed yet. 

    You can go a step further and have a message displayed on the client when it has been blocked by the Enforcer.  You do this through the Enforcer Properties, in the Authentication Tab.  You can edit the message to say whatever you would like the user to see.



  • 7.  RE: Compliance Notifications from SEPM

    Posted Oct 22, 2009 12:35 PM

     Policy manager(10.22.17.178) failed to verify client's UID.                                                                                                                                                     
    Symantec Agent is not running or running an incompatible version.



  • 8.  RE: Compliance Notifications from SEPM

    Posted Oct 22, 2009 12:54 PM
    Will the report show the hostname or ip-address of the client without the agent.  If they dont have the agent, how will it get the message displayed on the client.

    Would I get an email with this information if I have the Client Security Alert/Compliance events


  • 9.  RE: Compliance Notifications from SEPM

    Posted Oct 22, 2009 06:01 PM
    I am having trouble finding what the report will show, but in the meantime I have found where to locate the IP Address of the rejected clients.

    From the SEPM:
    Click the "Monitors" Icon
    Log Type: Compliance
    Log Content: Enforcer Client

    Click "View Log"
    Sort by "Action"  You will see "Authenticated" , "Passed" , "Rejected"
    under the "Remote Host" Column, you will see all of the IP addresses of clients that have been rejected.


    I will continue my search....


  • 10.  RE: Compliance Notifications from SEPM

    Posted Oct 24, 2009 03:19 PM
    Will it show the Rejected IP even if the client doesnt have the agent installed.


  • 11.  RE: Compliance Notifications from SEPM

    Posted Oct 25, 2009 08:50 AM
    SNAC clients have to be installed on the computers for new computers coming on to the network you can go for Dissolvable Clients
    https://www-secure.symantec.com/connect/forums/snac-agentless-configuration 


  • 12.  RE: Compliance Notifications from SEPM

    Posted Oct 26, 2009 12:25 PM
    I installed a DCHP Enforcer and did a test.

    In the Logs I see this from a client without the agent.

    Site Name: Sepm Server
    Event time: 10/26/2009 11:49:40
    Enforcer Name: DHCO Enforcer
    Enforcer type: Integrated Enforcer
    Remote Host vistahomeSP2VM[from 192.168.1.23]
    Action: Rejected
    Period: 1256572180
    Description: Symantec Agent is not running or running an incompatible version.
    Remote MAC: 00-1C-19-15-1C-1E
    Remote info: MSFT 5.0

    I have tried every possible notification on client security alert to have it send me an email if this occurs. I cant get an email to trigger off.
    I am able to get a notification after I install the client and it fails a HI check.

    As for the Dissolvable Clients, where is the setting to have the client download this agent. Does the setting exist with just a DHCP Enforcer.
    The document and post you mentioned doest give that information. Where is the exe for this agent.  

    Can you give me screenshots with how to set it up.


  • 13.  RE: Compliance Notifications from SEPM

    Posted Oct 26, 2009 02:04 PM
     
    Regarding the issue of the “Agent-less” Client not displaying a pop-up message after it has been rejected, I found some more information:
     
    This feature relies on Windows Messenger service to deliver the message, which Microsoft has removed from Windows since Vista and 2008.  Other methods of utilizing this feature are currently under research by our development team, and should be included in a later release.
     
    If you would like to go the route of providing a Temporary client on non-compliant machines, I have found the following information:
     
    Pg. 267 of the Enforcer Implentation Guide mentions more about the "On-Demand"  Feature on the Enforcer
    ftp://ftp.symantec.com/public/english_us_canada/products/symantec_network_access_control/11.0/manuals/mr4/Enforcer_Implementation_Guide.pdf



    This kb will help if you have problems configuring the HTTP Redirect on the SEPM
    http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/4ff1e3f54ef14f0a8825753e00646bc5?OpenDocument
     

    I am still working on finding an answer for you regarding notfications delivered by the SEPM.


  • 14.  RE: Compliance Notifications from SEPM

    Posted Oct 26, 2009 02:37 PM

    Based on the document and where the setting should be it looks like the DHCP add on Enforcer does not have this option to install the "On-Demand".  



  • 15.  RE: Compliance Notifications from SEPM

    Posted Oct 26, 2009 03:24 PM
    yeah, you're right.  I guess that would be available if you decided to purchase the Appliance in the future. 

    Regarding your statement on Notifications:
    "I have tried every possible notification on client security alert to have it send me an email if this occurs. I cant get an email to trigger off.
    I am able to get a notification after I install the client and it fails a HI check."

    It sounds like you may need to open a case with our support team regarding this.  Once you have done this, you can PM me the case number, and I can provide technical assistance, if needed.