Information Page

The Cisco Clean Access security system is a user authentication, vulnerability assessment and remediation system that checks authenticated students for vulnerabilities and directs the non-compliant computers to documentation on how to fix their issue. 

The requirements currently being enforced are ALL Windows Critical Updates, the latest version of the Clean Access Agent, and installed and updated antivirus software.  All computers compliant to their rules will be allowed access to the network.

For a better understanding of how the Cisco Clean Access system works, continue reading this document for detailed information.

 

User Authentication

User authentication simply means you need to provide proper credentials (i.e. your Immaculata username and password) in order to gain access to the network. There are two methods for entering this information: Web login and Clean Access Agent.

Web Login

Open any web browser, such as Internet Explorer, Safari, Firefox, Opera, etc. If your network settings are configured properly, you should be automatically redirected to the authentication page . Once you have read and understand the Network Acceptable Use Agreement, enter your Immaculata email user id and password and click Continue. The system will tell you if you enter an incorrect user id and/or password.

NOTE: Web Login is the user authentication method for all non-Windows XP and non-Windows 2000 computers. Windows XP and Windows 2000 computers are required to authenticate using the Clean Access Agent.

Clean Access Agent

If you have a Windows XP or Windows 2000 computer, you need to install the Clean Access Agent and use it to log in. To obtain the agent, log into the network using the web login method. You'll automatically be redirected to the Clean Access Agent Download page. Click the Download Clean Access Agent button. Although you can choose to open (i.e. install) the file directly, we recommend saving it to your hard drive so you can re-install at a later time, if necessary. Once the CCAAgentSetup installer is saved, double-click to install and simply follow the wizard installation instructions. The entire process should only take a minute or two. Once Clean Access Agent is installed, the login window will appear automatically whenever your computer attempts to access the network. Enter your Immaculata email user id and password and click Login.

NOTE: If the Clean Access Agent log in window doesn't appear automatically, you probably have an installed firewall (e.g. Norton Internet Security) preventing the window from popping up. To bypass this problem, modify your firewall rules to allow Clean Access Agent (port 8905). The method for modifying the rules vary depending on the firewall you're running.

Vulnerability assessment

After you successfully log into the system, Clean Access checks your computer for vulnerabilities to make sure it meets the necessary security requirements for connecting to the network. Only compliant computers are granted full network access.

What are the requirements for accessing the network?

It's possible that the minimum requirements may vary from time to time in order to remain proactive in preventing new viruses and trojans from infiltrating the network. Basically, all students are accountable for keeping their computer updated with current anti-virus software and all operating system security patches. Here are the current and planned specific requirements that Clean Access checks:

Windows XP

Clean Access Agent 3.5 or greater
Installed Antivirus
Up-to-date Antivirus
Running Antivirus
All Windows cirtical updates

Macintosh

None

Linux/Unix

None

If no vulnerabilities are found, your computer is considered compliant and is granted full network access. If vulnerabilities are found, your computer is moved into remediation.

Remediation

If your computer fails the vulnerability assessment, it is moved into remediation, and you are provided with directions for fixing/patching it. You are given temporary network access (to limited sites) in order to download any necessary software. Clean Access makes the distinction between REQUIRED and OPTIONAL software.

Missing REQUIRED Software

Required software must be installed before your computer will be granted network access. If your computer is missing required software, you'll see a message like the one at right.

Click the Go To Link (or Download) button to download and install the required software. Because the software is required, you must install it before full network access is granted.

Missing OPTIONAL Software

At times, Clean Access may notify you of optional software your computer is missing. If your computer is missing optional software, you'll see a message like the one at left.

In this example, the message does NOT mean you need to install McAfee VirusScan in order to gain access to the network. If you are already running an up-to-date copy of Norton/Symantec or TrendMicro, simply click Next in order to gain access to the Internet (you can disregard the on-screen timer).

If you'd like to download and install the optional software, click the Download (or Go To Link) button.

Removing the Clean Access Agent

The Clean Access Agent is required in all residence halls on campus. If you connect your computer to the Internet somewhere other than in a residence hall, the Clean Access Agent is not required and simply will not appear. However, if you move off-campus and no longer need to connect your computer to teh residential network, you'll probably want to remove the Clean Access Agent. To do so, go to Start -> Control Panel -> Add or Remove Programs. Select Clean Access Agent and click Remove.