 |
|
Lee University Information Services & Technology Top Menu
|
Clean Access FAQ |
General Information
Validation Process
Login / Logoff Process
Troubleshooting
Key Terms
General Information|
|
Q: What is Clean Access?
A: Clean Access is a network security
solution that will provide you with a
secure and clean network environment by
preventing infected and vulnerable
machines in the residence halls from
joining the university’s network. At the
same time, it will provide necessary
directions and help pages for machines
that do not pass the security
requirements.
Q:
Why are we introducing this solution
now?
A: Lee University is making every effort
to make your network experience
productive and secure. In the past,
students, through no fault of their own
in most cases, had difficulty dealing
with virus infections and OS
vulnerabilities. It has been determined
that the best way to prevent this from
happening again is to ensure that virus
software and OS critical updates and
patches are current and maintained.
Q: Am I required to install any software
on my computer?
A: All Microsoft Windows computers are
required to install the Clean Access
Agent client software to connect to the
university residence hall network. You
will also be required to install
Microsoft critical OS updates and
patches as well as an Anti-virus program
with latest virus definitions.
Q:
What is Clean Access Agent, and what
requirements does it check in order to
successfully connect to the network?
A: Clean Access Agent is a client
application that will check certain
security settings on your Microsoft
Windows PC to make sure that your system
is up-to-date with required security
patches and report this status to the
server. No information about you is sent
to the server. You must use Clean Access
Agent for your Microsoft Windows PC in
order to authenticate and use the
university network. The required
security settings will soon include:
Turning on Automatic Updates, OS service
pack level, critical OS updates and
patches, anti-virus software with the
latest virus definitions.
Top
|
Validation Process
| |
Q:
What is validation?
A: The process of confirming that
certain security measures are in place
on your computer.
Q:
How
does validation work?
A: The validation solution will
“intercept” any Internet browser access
and redirect the user to a web page that
instructs the user to download and
install the validation client known as
“Clean Access Agent”. This will happen
only if you do not have the client
installed on your machine already. Once
launched, the client downloads the
validation rules and processes these. If
the workstation fails the test, it is
allowed Internet access but only to the
remediation sites for a specific amount
of time depending on which test failed.
Q:
What
networks require validation?
A: Validation is required only if
students/faulty/staff are connecting to
the network from the Dorms or from any
of the open wireless areas throughout
the campus.
Q:
What
validation checks are being
performed? A: Machines connecting to the network
will soon be required to meet the
following criteria:- Have the current Windows Operating
System Critical Updates & Hot Fixes
- Have turned on Automatic Updates feature
for Microsoft Windows on the machine
- Have supported Anti-virus software
running
- Have latest virus definitions for the
anti-virus software
- Note: Nessus scans are performed on
Linux and Macintosh machines for known
vulnerabilities. In the near future we
will be checking for anti-virus software
and current virus definitions.
Q:
How
long do the validation checks
take? A: In general, the checks take between
10 and 20 seconds.
Q:
How
does validation work for
Microsoft users?
A: All Microsoft Windows computers are
required to install the Clean Access
Agent client software to connect to the
university network. You will also be
required to install Microsoft critical
OS patches and updates, must be running
supported anti-virus software with
latest virus definitions.
Q:
How does validation work for Linux,
Macintosh and Non-Windows Users?
A: Linux, Macintosh and Non-Windows
users must authenticate by logging in
via a web page. The only validation
check (performed in the background) for
Linux, Macintosh and Non-Windows systems
at this time is the Nessus scan. There
is no client needed for Linux, Macintosh
and Non-Windows systems. However, all
users must accept Network Policy
Agreement before signing in.
Q: What am I allowed to access when
Unauthenticated or Quarantined?
A: For the most part, remediation and
help sites such as
windowsupdate.microsoft.com and various
anti-virus updates sites are available
for access.
Q:
What
remediation is available?
A: If a user's systems fails
authentication, the user is instructed
to provide the correct university
network username and password. If the
user does not have or has forgotten
his/her password, he/she is instructed
to visit the Help Desk located in the
first floor of the Pentecostal Resource
Center. You must bring your Lee
University ID card with you for
identification purposes.
Q:
What happens when a new patch or
updates are available?
A: As new critical Microsoft updates
become available, the security
requirements will be updated to reflect
the new patches. It is a mandatory
requirement for all users to keep their
Operating System patches up to date. If
vulnerability is reported or the threat
of a virus storm or worm attack emerges,
we could add another validation check
(in addition to existing security
checks) in reaction to the threat.
Top
|
Login/Logoff Process| |
Q: When and how often do I have to
login?
A: You will be logged off the network
automatically if you become disconnected
from the network for 20 minutes or
longer. For example, if you shut down
your machine for more than 20 minutes,
you will be required to re-authenticate
and re-validate to regain network
access. The first time you access the
network may take additional time, please
be patient. If you are already logged in
successfully to the network and have to
restart your machine for some reason,
then after the reboot, your machine
should connect to the network
successfully without requiring you to
login again.
Q: How will I know when I am logged out
of the network?
A: Right click the Clean Access Agent
icon in the system tray and check the
status. If you choose to logout of the
network from the system try icon, but
the Clean Access Agent is running is
still running in the system tray, the
login screen should pop-up instantly.
Other indications that your network
connection has been terminated are: -
Email may fail to send or receive
-
Instant messaging fails or suddenly
stops working
-
File downloads may suddenly stop
-
Browser may be redirected to login page
Q:
Each time I try to use my computer to
access the internet, my browser tells me
that I need to login. Do I have to login
frequently?
A: Many computers are configured to
“sleep” when not in use, if your
computer is set this way, you will be
logged off the network and must
authenticate to regain access each time
your computer is in “sleep” mode for
more than 20 minutes.
Q: How do I tell if I am already logged
in?
A: The best way is to try to go to an
internet site. In most cases, if you are
able to access a site such as
www.leeuniversity.edu or
www.google.com,
you are online and logged in. Also, if
you check the Clean Access Agent icon in
the system tray, it will show only the
‘Logout' option in the menu.
Q:
How do I check to see if I have a
valid IP address?
A: Complete following steps:
- Go to the Start menu and click on "Run"
Type cmd, and click "OK" -
At the prompt, type C:\ ipconfig
-
The IP address you receive will depend
on which network you are connected to.
The IP range for dorms and wireless
areas are between 10.101.XXX.XXX to
10.119.XXX.XXX. For example, if you are
connecting to the wireless areas outside
of the PCSU you should have an IP
address of 10.119.XXX.XXX.
Q: I use a personal firewall; will this
cause a problem?
A: We have not had many problems with
the Firewall built into Windows XP,
however other Security Software bundles
such as Norton Internet Security Suite
and McAfee Internet Security Suite have
cause problems. (A Security Bundle is a
software bundle that contains a personal
Firewall, Anti-Virus program, Spyware/Adware
software, etc…) Using these programs
will require you to configure the
Firewall to allow the Clean Access Agent
to communicate with the Server.
Configuring your Firewall varies greatly
and may require you to get help from the
vendor. We have listed below some simple
steps to configure a few of the personal
firewalls we have dealt with.
Norton Internet Security Suite: -
Double click the Norton Security Icon in
the system tray
Click ‘Personal Firewall' Option in the
window -
Click ‘Configure' and then choose
‘Programs'
-
Scroll down to the list of programs to
find Cisco Clean Access Agent
-
From the drop down list, select ‘Permit
All' and then press Okay
Windows XP: -
Start → Control panel → Windows
Firewall
-
Go to the table ‘Exceptions' and click
‘Add Program'
-
From the list of program, select ‘Cisco
Clean Access' and then press Okay.
-
Make sure the square box in the program
list is checked for Cisco Clean Access
-
If the Clean Access Agent is downloaded
and installed correctly, and the
Firewall is configured properly to allow
Clean Access Agent, the Clean Access
Agent Login Screen will pop-up instantly
for you to login and validate.
-
Typically, if the Firewall is not
configured properly, you will see that
Clean Access is running either by
looking at the right hand corner system
tray icon or by double clicking the
desktop icon for Clean Access Agent, but
the login screen will not appear. Go
back and verify the Firewall settings.
If the problem still persists then
contact the Help Desk for further
assistance.
-
An additional note: Every time there is
a new patch or version upgrade available
for Clean Access Agent and you choose to
upgrade, please make sure that you allow
Clean Access through your Firewall if
the message appears from the Firewall
software that it had found new software.
Top
|
Troubleshooting Tips| |
Q: I cannot access the login page. I get
the redirection page but then my browser
gives an error and stops.
A: Generally, this is caused by an
encryption (SSL) problem with your
browser. Encryption is required for
authentication to complete. Try another
browser if you are unable to correct the
problem with the first browser. Also
verify the settings in your browser by
doing the following: - Go into Tools → Internet Options and
then make changes under the following
tabs and save the changes upon each
execution.
-
General → Clear all Temporary Files,
and Cookies
-
Security → Select ‘Default Level'
-
Privacy → Select ‘Default'
-
Advanced → Select ‘Restore Defaults'
Q: I am unable to ping the default
gateway address; shouldn’t I be able to
do this?
A: No, you will not be able to ping the
default gateway. This is normal.
Q: What am I allowed to access when
Unauthenticated or Quarantined?
A: For the most part, remediation and
help sites such as anti-virus update
sites and
windowsupdate.microsoft.com.
Q: I’m on a Macintosh or Linux machine.
I’ve opened my browser but I am not
redirected to a login page. What do I
do?
A: You must try to go to a non-local
site such as
www.google.com.
Q: I’m on a Windows machine. Sometimes I
can login using the web page and at
other times, the web page tells me that
I must use Clean Access Agent, why?
A: It depends on when the last time your
computer was “validated” to the network.
By simply restarting the machine will
not loose your validation and Clean
Access will connect you automatically.
However, if you have logged out manually
or have shut down your machine for a
long time, then you will be required to
login through Clean Access Agent.
Q: I am able to access the internet but
the Clean Access Agent still allows me
to “login”. Am I logged in?
A: Yes, the Clean Access Agent may not
always detect your network status. If
you can access normal internet sites
such as
www.leeuniversity.edu or
www.google.com, then you are
authenticated.
Q:
I am not able to access the internet
and the Clean Access Agent only allows
me to “logout”. What’s going on?
A: The Clean Access Agent may not always
detect your network status. Please
choose “logout” and then choose “login”.
Q:
How do I logout?
A: Currently, the only way to manually
logout is to use the Clean Access Agent
“logout” feature. Right-click the Clean
Access Agent icon in the system tray and
choose logout. The Clean Access Agent
icon appears in the system tray. Once
you are logged out, the login screen for
Clean Access will pop-up again. If this
bothers you then you can exit out the
program by right clicking the Clean
Access Agent icon in the system tray and
choosing the option ‘Exit'. If you do
this, next time you need to connect to
the Internet, you either have to start
the program from the desktop icon or by
restarting your machine.
Q: I do not have a “logout” option in
Clean Access Agent.
A: The Clean Access Agent does not
always detect your network status. Once
you login through the Clean Access
Agent, you will have the “logout”
feature.
Q: Can I update Windows before I login?
A: Yes, you should be able to go to
windowsupdate.microsoft.com. You may not
be able to use the direct link in your
browser on your desktop to other sites.
If your home page is set for a website
not allowed under Unauthenticated or
Temporary role, you will get the
Security Access Disabled message. This
is normal. You can only access complete
Internet after your machine passes all
the requirements.
Q: When I run Windows Update, I get a
message stating that the product key
used to install windows is invalid?
A: Windows Update will fail if your
Windows OS is not properly licensed. You
must have a legal copy of the operating
system to connect to the university
network.
Q: Do I have to use the Clean Access
Agent client?
A: Yes. All Windows PCs are required to
use Clean Access Agent for network
access.
Q: What happens if I uninstall the Clean
Access Agent client?
A: You will be required to reinstall the
client to re-authenticate when your
login expires. Also, please note that if
you re-install Clean Access and you are
running Firewall on your machine, then
that Firewall must be reconfigured as
well to allow Clean Access program.
Q: The Clean Access Agent client does
not offer a “login,” just a “logout,”
and the web page tells me that I must
now use Clean Access Agent to login;
what do I do?
A: The Clean Access Agent does not
always detect your network status.
Please choose “logout”, and then you
will have the “login” feature.
Q: I keep trying to install the Clean
Access Agent but it tells me that I can
either Modify/Repair or Remove the
program.
A: Clean Access Agent is currently
installed on your machine. You do not
need to install it again. You can verify
by going in to Control Panel → Add
Remove Programs and see if the Cisco
Clean Access is listed there.
Q: How do I know Clean Access Agent is
running?
A: Look in the “System Tray” for in the
lower right corner near the time
display. You may need to select the “<“
to expand the list and show clean access
agent. A Clean Access Agent icon
normally looks like a Green Square with
a key.
Q: I do not see the Clean Access Agent
icon in my system tray; what do I do?
A: There are a few possibilities: -
Clean Access Agent has not been
installed. → Please install Clean
Access Agent to continue.
-
Clean Access Agent has been installed
but you did not select “Launch” at the
end of the installation. → From the
“Start” menu, then “Programs”, then
“Clean Access”, then “Clean Access
Agent” to launch the program.
-
Clean Access Agent is “hidden” in the
System tray. → Please click on “<<“ to
expand the system tray list and show
clean access agent, then login.
-
Your computer has a problem showing
System tray icons. → You may be able to
use “Task manager” to halt Clean Access
Agent and then launch it again.
-
Clean Access Agent is installed but not
running. → From the “Start” menu, then
“Programs”, then “Clean Access”, then
“Clean Access Agent”, then “Clean Access
Agent” to launch the program.
Q: I get a ‘Network Error' when
connecting with Clean Access Agent.
A: Verify the TCP/IP settings under
local area connection and make sure you
have ‘Obtain IP address automatically'
and ‘Obtain DHCP address automatically'
options checked.
Q: Microsoft Windows Patch Failure.
A: If the user's system fails the check
for current critical OS patches, the
user is instructed to click on the URL
for the Microsoft Windows update site
and follow the instructions.
Additionally, the user is provided the
option to download a program that can
assist in configuration of Microsoft
Windows Automatic Updates. If you have
installed all the patches from Microsoft
Website and Clean Access Agent still put
you in temporary role and give ‘Missing
Critical Windows Update' message, then
please call University Computing Help
Desk for further Assistance.
Q: What About Xboxes, PlayStations,
etc.?
A: You will need to bring the MAC
address of your gaming console to the
Help Desk located in the first floor of
the Pentecostal Resource Center. Please
allow 24-48 hours for your console to be
added to the network.
Q: What are general troubleshooting
steps or checklist I can follow?
A: If you are having trouble connecting
to the network go through this quick
checklist to make sure you have not
missed anything: -
You have the Ethernet Cable with RJ-45
connector type. This connector is a
little bigger in size than the phone
jack. The cable itself is thicker than
the phone cable.
-
If the network card in your computer has
small LEDs next to the Interface Card,
and when you plug the cable in firmly
(one end to the face place on the wall
and other to the network card) you see
the lights blinking or any light. Some
Ethernet cards do not have LEDs so that
does not necessarily mean no
connectivity. Also, make sure that
Ethernet card is not disabled in the
system tray.
-
You start the computer and everything
starts normally. No error messages or
unwanted windows with errors. Meaning a
healthy machine with no issues.
-
You are getting a proper IP address
starting with 10.1xx.xx.xx. Check the
TCP/IP settings. If the output of
‘ipconfig' is blank. Chances are that
your Ethernet Card/ or TCP/IP settings
are not correct. A normal TCP/IP
settings should have ‘Obtain IP address
automatically' and ‘Obtain DNS
information automatically' checked. Any
IP addresses in the DNS settings will
give you ‘Network Error'.
-
If you are getting 169.254.xxx address,
try ‘ipconfig /release' and then
‘ipconfig /renew' on prompt. Usually a
169.xx address means you are not getting
proper IP from the DHCP server.
-
You have configured the XP Firewall and
third party Anti-virus vendor software
Firewall.
-
You can authenticate to the initial page
and taken to the download page for Clean
Access Agent. Otherwise, you may have to
check your Username and Password. Upon
several unsuccessful attempts (or
expired password), your credentials are
locked for 15 minutes. Wait and try
again.
-
You have successfully downloaded and
installed the Clean Access Agent . Make
sure upon completion of installation,
your firewall will prompt you to
allow/block this program. Always choose
the option “Allow” for Clean Access
Agent.
-
After installation, the login screen for
Clean Access does not appear . No login
screen usually means Firewall settings
or if you are trying it a different time
then it could also means no network
connection. If the icon for your network
connection in the system tray says
‘Network cable unplugged' it means you
have lost connectivity to the network.
Also check to make sure you are not
behind a router or non-Lee University
access point. Both of which are not
allowed on campus.
-
You have logged in with Clean Access and
it says you have temporary access.
Click next to find out what you are
missing. Follow the directions to get
Critical Updates or whatever the
requirements you fail.
-
You got all the updates from Microsoft
and still it put you in temporary role
and wants you to get critical updates,
contact Help Desk for assistance .
-
You logged in successfully and still no
page is displayed with Internet Explorer
. Check the browser settings and verify
that it has ‘never dial a connection'
under Tools → Internet Options →
Connections. Try another browser or
Internet application such as MSN or
Yahoo messenger.
-
It was working fine and then stopped
working . Track back and research
what changes you recently made on your
computer. If you know the changes but do
not know how to go back, call the Help
Desk for assistance (x8027).
-
You are not getting any page displayed
in your Internet Explorer . Please check
File → Work Offline is not checked
-
You open Internet Explorer and nothing
is displayed. Please make sure that your
browser default home page is set to a
valid website such as www.google.com and
not ‘Blank'
Q: Clean Access Agent gives error:
Network Error: SSL Certificate REV
failed [12057]
A: This can be fixed by following these
steps:
- Open up Internet Explorer
-
Click on Tools → Internet Options
-
Click on the Advaced Tab
-
Scroll down towards the bottom to the
Security section
-
Uncheck "Check for server certificate
revocation"
-
Close Internet Explorer and the Clean
Access Agent
-
Start the Clean Access Agent and login
Q: When I try to connect I get the
message “Sever cannot be parsed.”
A: To fix this follow these steps: -
Open up Internet Explorer
-
Go to Tools → Internet Options
-
Click on Connections Tab
-
Click on LAN settings
-
UNCHECK "Automatically detect settings"
-
OK → OK
Q: Clean Access gives me an error that
says “Unknown Trust Provider” with the
code “-2146762751.”
A: This error is due to faulty security
polices. To fix this you can follow
these steps. -
Click on Start → Run
-
In the command box type in “Regsvr32
Softpub.dll” (without the quotations
and make sure you put the space in
between the two)
-
Most of the time this will fix the
problem, if not you can try the
following two commands
-
“Regsvr32 Mssip32.dll”
-
“Regsvr32 Initpki.dll”
Q:
I am getting an Error 87 message in
Clean Access, what should I do?
A:
It has been found that when
installing the Cisco Clean Access Agent
and you receive Error 87 that you have
the new Internet Explorer 7 Beta
installed. You MUST uninstall
this software in order to use the ResNet.
Cisco ensures us that IE7 will be
supported later in the semester but at
this time it is not. It is estimated
that when Microsoft releases IE7 as a
stable version, rather than Beta, that
Cisco Clean Access will have its support
in place. Until then, please refrain
from using IE7 while on ResNet.
Sorry for the inconvenience.
Top
|
Key Terms| |
Network Access Procedure: The process
of authentication and validation of your
computer required for university network
access.
Authentication: The process of
verifying your access to the network by
confirming your username and password
and associating it with your computer.
Validation: The process of confirming
that certain security measures are in
place on your computer.
Client: A software program that
describes the actions that are to be
carried out by your computer.
Quarantine: A place on the network that
has restricted access, where infected
machines reside until they are cleaned.
Nessus Scans: A comprehensive
vulnerability scanning program used by
the server to scan machines against
known vulnerabilities. The process is
transparent to the end-user, nor is
anything installed on the end-users
machine.
Top
|
|
|
|
Current Students Menu
|
|