Lee University, Cleveland TN
Lee University, Cleveland TN
Lee University Information Services & Technology Top Menu

Clean Access FAQ
General Information Validation Process Login / Logoff Process Troubleshooting Key Terms


General Information
  Q: What is Clean Access?
A: Clean Access is a network security solution that will provide you with a secure and clean network environment by preventing infected and vulnerable machines in the residence halls from joining the university’s network. At the same time, it will provide necessary directions and help pages for machines that do not pass the security requirements.

Q: Why are we introducing this solution now?
A: Lee University is making every effort to make your network experience productive and secure. In the past, students, through no fault of their own in most cases, had difficulty dealing with virus infections and OS vulnerabilities. It has been determined that the best way to prevent this from happening again is to ensure that virus software and OS critical updates and patches are current and maintained.

Q: Am I required to install any software on my computer?
A: All Microsoft Windows computers are required to install the Clean Access Agent client software to connect to the university residence hall network. You will also be required to install Microsoft critical OS updates and patches as well as an Anti-virus program with latest virus definitions.

Q: What is Clean Access Agent, and what requirements does it check in order to successfully connect to the network?
A: Clean Access Agent is a client application that will check certain security settings on your Microsoft Windows PC to make sure that your system is up-to-date with required security patches and report this status to the server. No information about you is sent to the server. You must use Clean Access Agent for your Microsoft Windows PC in order to authenticate and use the university network. The required security settings will soon include: Turning on Automatic Updates, OS service pack level, critical OS updates and patches, anti-virus software with the latest virus definitions.

Top

Validation Process
  Q: What is validation?
A: The process of confirming that certain security measures are in place on your computer.

Q: How does validation work?
A: The validation solution will “intercept” any Internet browser access and redirect the user to a web page that instructs the user to download and install the validation client known as “Clean Access Agent”. This will happen only if you do not have the client installed on your machine already. Once launched, the client downloads the validation rules and processes these. If the workstation fails the test, it is allowed Internet access but only to the remediation sites for a specific amount of time depending on which test failed.

Q: What networks require validation?
A: Validation is required only if students/faulty/staff are connecting to the network from the Dorms or from any of the open wireless areas throughout the campus.

Q: What validation checks are being performed?
A: Machines connecting to the network will soon be required to meet the following criteria:
  • Have the current Windows Operating System Critical Updates & Hot Fixes
  • Have turned on Automatic Updates feature for Microsoft Windows on the machine
  • Have supported Anti-virus software running
  • Have latest virus definitions for the anti-virus software
  • Note: Nessus scans are performed on Linux and Macintosh machines for known vulnerabilities. In the near future we will be checking for anti-virus software and current virus definitions.
Q: How long do the validation checks take?
A: In general, the checks take between 10 and 20 seconds.

Q: How does validation work for Microsoft users?
A: All Microsoft Windows computers are required to install the Clean Access Agent client software to connect to the university network. You will also be required to install Microsoft critical OS patches and updates, must be running supported anti-virus software with latest virus definitions.

Q: How does validation work for Linux, Macintosh and Non-Windows Users?
A: Linux, Macintosh and Non-Windows users must authenticate by logging in via a web page. The only validation check (performed in the background) for Linux, Macintosh and Non-Windows systems at this time is the Nessus scan. There is no client needed for Linux, Macintosh and Non-Windows systems. However, all users must accept Network Policy Agreement before signing in.

Q: What am I allowed to access when Unauthenticated or Quarantined?
A: For the most part, remediation and help sites such as windowsupdate.microsoft.com and various anti-virus updates sites are available for access.

Q: What remediation is available?
A: If a user's systems fails authentication, the user is instructed to provide the correct university network username and password. If the user does not have or has forgotten his/her password, he/she is instructed to visit the Help Desk located in the first floor of the Pentecostal Resource Center. You must bring your Lee University ID card with you for identification purposes.

Q: What happens when a new patch or updates are available?
A: As new critical Microsoft updates become available, the security requirements will be updated to reflect the new patches. It is a mandatory requirement for all users to keep their Operating System patches up to date. If vulnerability is reported or the threat of a virus storm or worm attack emerges, we could add another validation check (in addition to existing security checks) in reaction to the threat.

Top
Login/Logoff Process
  Q: When and how often do I have to login?
A: You will be logged off the network automatically if you become disconnected from the network for 20 minutes or longer. For example, if you shut down your machine for more than 20 minutes, you will be required to re-authenticate and re-validate to regain network access. The first time you access the network may take additional time, please be patient. If you are already logged in successfully to the network and have to restart your machine for some reason, then after the reboot, your machine should connect to the network successfully without requiring you to login again.

Q: How will I know when I am logged out of the network?
A: Right click the Clean Access Agent icon in the system tray and check the status. If you choose to logout of the network from the system try icon, but the Clean Access Agent is running is still running in the system tray, the login screen should pop-up instantly. Other indications that your network connection has been terminated are:
  • Email may fail to send or receive
  • Instant messaging fails or suddenly stops working
  • File downloads may suddenly stop
  • Browser may be redirected to login page
Q: Each time I try to use my computer to access the internet, my browser tells me that I need to login. Do I have to login frequently?
A: Many computers are configured to “sleep” when not in use, if your computer is set this way, you will be logged off the network and must authenticate to regain access each time your computer is in “sleep” mode for more than 20 minutes.

Q: How do I tell if I am already logged in?
A: The best way is to try to go to an internet site. In most cases, if you are able to access a site such as www.leeuniversity.edu or www.google.com, you are online and logged in. Also, if you check the Clean Access Agent icon in the system tray, it will show only the ‘Logout' option in the menu.

Q: How do I check to see if I have a valid IP address?
A: Complete following steps:
  • Go to the Start menu and click on "Run"
    Type cmd, and click "OK"
  • At the prompt, type C:\ ipconfig
  • The IP address you receive will depend on which network you are connected to. The IP range for dorms and wireless areas are between 10.101.XXX.XXX to 10.119.XXX.XXX. For example, if you are connecting to the wireless areas outside of the PCSU you should have an IP address of 10.119.XXX.XXX.
Q: I use a personal firewall; will this cause a problem?
A: We have not had many problems with the Firewall built into Windows XP, however other Security Software bundles such as Norton Internet Security Suite and McAfee Internet Security Suite have cause problems. (A Security Bundle is a software bundle that contains a personal Firewall, Anti-Virus program, Spyware/Adware software, etc…) Using these programs will require you to configure the Firewall to allow the Clean Access Agent to communicate with the Server. Configuring your Firewall varies greatly and may require you to get help from the vendor. We have listed below some simple steps to configure a few of the personal firewalls we have dealt with.

Norton Internet Security Suite:
  • Double click the Norton Security Icon in the system tray
    Click ‘Personal Firewall' Option in the window
  • Click ‘Configure' and then choose ‘Programs'
  • Scroll down to the list of programs to find Cisco Clean Access Agent
  • From the drop down list, select ‘Permit All' and then press Okay
Windows XP:
  • Start → Control panel → Windows Firewall
  • Go to the table ‘Exceptions' and click ‘Add Program'
  • From the list of program, select ‘Cisco Clean Access' and then press Okay.
  • Make sure the square box in the program list is checked for Cisco Clean Access
  • If the Clean Access Agent is downloaded and installed correctly, and the Firewall is configured properly to allow Clean Access Agent, the Clean Access Agent Login Screen will pop-up instantly for you to login and validate.
  • Typically, if the Firewall is not configured properly, you will see that Clean Access is running either by looking at the right hand corner system tray icon or by double clicking the desktop icon for Clean Access Agent, but the login screen will not appear. Go back and verify the Firewall settings. If the problem still persists then contact the Help Desk for further assistance.
  • An additional note: Every time there is a new patch or version upgrade available for Clean Access Agent and you choose to upgrade, please make sure that you allow Clean Access through your Firewall if the message appears from the Firewall software that it had found new software.
Top
Troubleshooting Tips
  Q: I cannot access the login page. I get the redirection page but then my browser gives an error and stops.
A: Generally, this is caused by an encryption (SSL) problem with your browser. Encryption is required for authentication to complete. Try another browser if you are unable to correct the problem with the first browser. Also verify the settings in your browser by doing the following:
  • Go into Tools → Internet Options and then make changes under the following tabs and save the changes upon each execution.
  • General → Clear all Temporary Files, and Cookies
  • Security → Select ‘Default Level'
  • Privacy → Select ‘Default'
  • Advanced → Select ‘Restore Defaults'
Q: I am unable to ping the default gateway address; shouldn’t I be able to do this?
A: No, you will not be able to ping the default gateway. This is normal.

Q: What am I allowed to access when Unauthenticated or Quarantined?
A: For the most part, remediation and help sites such as anti-virus update sites and windowsupdate.microsoft.com.

Q: I’m on a Macintosh or Linux machine. I’ve opened my browser but I am not redirected to a login page. What do I do?

A: You must try to go to a non-local site such as www.google.com.

Q: I’m on a Windows machine. Sometimes I can login using the web page and at other times, the web page tells me that I must use Clean Access Agent, why?
A: It depends on when the last time your computer was “validated” to the network. By simply restarting the machine will not loose your validation and Clean Access will connect you automatically. However, if you have logged out manually or have shut down your machine for a long time, then you will be required to login through Clean Access Agent.

Q: I am able to access the internet but the Clean Access Agent still allows me to “login”. Am I logged in?
A: Yes, the Clean Access Agent may not always detect your network status. If you can access normal internet sites such as www.leeuniversity.edu or www.google.com, then you are authenticated.

Q: I am not able to access the internet and the Clean Access Agent only allows me to “logout”. What’s going on?
A: The Clean Access Agent may not always detect your network status. Please choose “logout” and then choose “login”.

Q: How do I logout?
A: Currently, the only way to manually logout is to use the Clean Access Agent “logout” feature. Right-click the Clean Access Agent icon in the system tray and choose logout. The Clean Access Agent icon appears in the system tray. Once you are logged out, the login screen for Clean Access will pop-up again. If this bothers you then you can exit out the program by right clicking the Clean Access Agent icon in the system tray and choosing the option ‘Exit'. If you do this, next time you need to connect to the Internet, you either have to start the program from the desktop icon or by restarting your machine.

Q: I do not have a “logout” option in Clean Access Agent.
A: The Clean Access Agent does not always detect your network status. Once you login through the Clean Access Agent, you will have the “logout” feature.

Q: Can I update Windows before I login?
A: Yes, you should be able to go to windowsupdate.microsoft.com. You may not be able to use the direct link in your browser on your desktop to other sites. If your home page is set for a website not allowed under Unauthenticated or Temporary role, you will get the Security Access Disabled message. This is normal. You can only access complete Internet after your machine passes all the requirements.

Q: When I run Windows Update, I get a message stating that the product key used to install windows is invalid?
A: Windows Update will fail if your Windows OS is not properly licensed. You must have a legal copy of the operating system to connect to the university network.

Q: Do I have to use the Clean Access Agent client?
A: Yes. All Windows PCs are required to use Clean Access Agent for network access.

Q: What happens if I uninstall the Clean Access Agent client?
A: You will be required to reinstall the client to re-authenticate when your login expires. Also, please note that if you re-install Clean Access and you are running Firewall on your machine, then that Firewall must be reconfigured as well to allow Clean Access program.

Q: The Clean Access Agent client does not offer a “login,” just a “logout,” and the web page tells me that I must now use Clean Access Agent to login; what do I do?
A: The Clean Access Agent does not always detect your network status. Please choose “logout”, and then you will have the “login” feature.

Q: I keep trying to install the Clean Access Agent but it tells me that I can either Modify/Repair or Remove the program.
A: Clean Access Agent is currently installed on your machine. You do not need to install it again. You can verify by going in to Control Panel → Add Remove Programs and see if the Cisco Clean Access is listed there.

Q: How do I know Clean Access Agent is running?
A: Look in the “System Tray” for in the lower right corner near the time display. You may need to select the “<“ to expand the list and show clean access agent. A Clean Access Agent icon normally looks like a Green Square with a key.

Q: I do not see the Clean Access Agent icon in my system tray; what do I do?
A:
There are a few possibilities:
  • Clean Access Agent has not been installed. → Please install Clean Access Agent to continue.
  • Clean Access Agent has been installed but you did not select “Launch” at the end of the installation. → From the “Start” menu, then “Programs”, then “Clean Access”, then “Clean Access Agent” to launch the program.
  • Clean Access Agent is “hidden” in the System tray. → Please click on “<<“ to expand the system tray list and show clean access agent, then login.
  • Your computer has a problem showing System tray icons. → You may be able to use “Task manager” to halt Clean Access Agent and then launch it again.
  • Clean Access Agent is installed but not running. → From the “Start” menu, then “Programs”, then “Clean Access”, then “Clean Access Agent”, then “Clean Access Agent” to launch the program.
Q: I get a ‘Network Error' when connecting with Clean Access Agent.
A: Verify the TCP/IP settings under local area connection and make sure you have ‘Obtain IP address automatically' and ‘Obtain DHCP address automatically' options checked.

Q: Microsoft Windows Patch Failure.
A: If the user's system fails the check for current critical OS patches, the user is instructed to click on the URL for the Microsoft Windows update site and follow the instructions. Additionally, the user is provided the option to download a program that can assist in configuration of Microsoft Windows Automatic Updates. If you have installed all the patches from Microsoft Website and Clean Access Agent still put you in temporary role and give ‘Missing Critical Windows Update' message, then please call University Computing Help Desk for further Assistance.

Q: What About Xboxes, PlayStations, etc.?
A: You will need to bring the MAC address of your gaming console to the Help Desk located in the first floor of the Pentecostal Resource Center. Please allow 24-48 hours for your console to be added to the network.

Q: What are general troubleshooting steps or checklist I can follow?
A: If you are having trouble connecting to the network go through this quick checklist to make sure you have not missed anything:
  • You have the Ethernet Cable with RJ-45 connector type. This connector is a little bigger in size than the phone jack. The cable itself is thicker than the phone cable.
  • If the network card in your computer has small LEDs next to the Interface Card, and when you plug the cable in firmly (one end to the face place on the wall and other to the network card) you see the lights blinking or any light. Some Ethernet cards do not have LEDs so that does not necessarily mean no connectivity. Also, make sure that Ethernet card is not disabled in the system tray.
  • You start the computer and everything starts normally. No error messages or unwanted windows with errors. Meaning a healthy machine with no issues.
  • You are getting a proper IP address starting with 10.1xx.xx.xx. Check the TCP/IP settings. If the output of ‘ipconfig' is blank. Chances are that your Ethernet Card/ or TCP/IP settings are not correct. A normal TCP/IP settings should have ‘Obtain IP address automatically' and ‘Obtain DNS information automatically' checked. Any IP addresses in the DNS settings will give you ‘Network Error'.
  • If you are getting 169.254.xxx address, try ‘ipconfig /release' and then ‘ipconfig /renew' on prompt. Usually a 169.xx address means you are not getting proper IP from the DHCP server.
  • You have configured the XP Firewall and third party Anti-virus vendor software Firewall.
  • You can authenticate to the initial page and taken to the download page for Clean Access Agent. Otherwise, you may have to check your Username and Password. Upon several unsuccessful attempts (or expired password), your credentials are locked for 15 minutes. Wait and try again.
  • You have successfully downloaded and installed the Clean Access Agent . Make sure upon completion of installation, your firewall will prompt you to allow/block this program. Always choose the option “Allow” for Clean Access Agent.
  • After installation, the login screen for Clean Access does not appear . No login screen usually means Firewall settings or if you are trying it a different time then it could also means no network connection. If the icon for your network connection in the system tray says ‘Network cable unplugged' it means you have lost connectivity to the network.   Also check to make sure you are not behind a router or non-Lee University access point. Both of which are not allowed on campus.
  • You have logged in with Clean Access and it says you have temporary access. Click next to find out what you are missing. Follow the directions to get Critical Updates or whatever the requirements you fail.
  • You got all the updates from Microsoft and still it put you in temporary role and wants you to get critical updates, contact Help Desk for assistance .
  • You logged in successfully and still no page is displayed with Internet Explorer . Check the browser settings and verify that it has ‘never dial a connection' under Tools → Internet Options → Connections. Try another browser or Internet application such as MSN or Yahoo messenger.
  • It was working fine and then stopped working . Track back and research what changes you recently made on your computer. If you know the changes but do not know how to go back, call the Help Desk for assistance (x8027).
  • You are not getting any page displayed in your Internet Explorer . Please check File → Work Offline is not checked
  • You open Internet Explorer and nothing is displayed. Please make sure that your browser default home page is set to a valid website such as www.google.com and not ‘Blank'
Q: Clean Access Agent gives error: Network Error: SSL Certificate REV failed [12057]
A: This can be fixed by following these steps:
  • Open up Internet Explorer
  • Click on Tools → Internet Options
  • Click on the Advaced Tab
  • Scroll down towards the bottom to the Security section
  • Uncheck "Check for server certificate revocation"
  • Close Internet Explorer and the Clean Access Agent
  • Start the Clean Access Agent and login
Q: When I try to connect I get the message “Sever cannot be parsed.”
A: To fix this follow these steps:
  • Open up Internet Explorer
  • Go to Tools → Internet Options
  • Click on Connections Tab
  • Click on LAN settings
  • UNCHECK "Automatically detect settings"
  • OK → OK
Q: Clean Access gives me an error that says “Unknown Trust Provider” with the code “-2146762751.”
A: This error is due to faulty security polices. To fix this you can follow these steps.
  • Click on Start → Run
  • In the command box type in “Regsvr32 Softpub.dll” (without the quotations and make sure you put the space in between the two)
  • Most of the time this will fix the problem, if not you can try the following two commands
  • “Regsvr32 Mssip32.dll”
  • “Regsvr32 Initpki.dll”

Q: I am getting an Error 87 message in Clean Access, what should I do?
A:
It has been found that when installing the Cisco Clean Access Agent and you receive Error 87 that you have the new Internet Explorer 7 Beta installed. You MUST uninstall this software in order to use the ResNet. Cisco ensures us that IE7 will be supported later in the semester but at this time it is not. It is estimated that when Microsoft releases IE7 as a stable version, rather than Beta, that Cisco Clean Access will have its support in place. Until then, please refrain from using IE7 while on ResNet.

Sorry for the inconvenience.
 

Top
Key Terms
  Network Access Procedure: The process of authentication and validation of your computer required for university network access.

Authentication: The process of verifying your access to the network by confirming your username and password and associating it with your computer.

Validation: The process of confirming that certain security measures are in place on your computer.

Client: A software program that describes the actions that are to be carried out by your computer.

Quarantine: A place on the network that has restricted access, where infected machines reside until they are cleaned.

Nessus Scans: A comprehensive vulnerability scanning program used by the server to scan machines against known vulnerabilities. The process is transparent to the end-user, nor is anything installed on the end-users machine.

Top
 
Current Students Menu
  Lee University


© 1997 - 2008 · Privacy Statement · Campus Map · Weather in Cleveland · Weather in Charlotte
Lee University · 1120 North Ocoee Street · Cleveland, TN · 37320-3450 · 1-800-LEE-9930
Current Visitors for ist.leeuniversity.edu: 9 · A-Z Index · Web Requests & Standards · Send Feedback