tgreene
Executive Editor

Student dodges Cisco NAC scan

Opinion
May 1, 20072 mins

* Cisco adjusts its default settings following student hack

A University of Portland student has figured out how to evade the NAC endpoint check that was supposed to be part of logging into the campus network.

It turned out he discovered that under certain circumstances the default setting for the Cisco Clean Access NAC device the school uses would allow access without requiring a scan of the endpoint configuration posture.

So he configured endpoints to return a null value when they were queried about what operating system they were running, and that triggered the default that gave access right away, no scan required. (Cisco has since changed the default to deny access.)

The student, described by the campus newspaper as one of the brightest computer-science students at the school, was suspended for the rest of the current semester and for the upcoming fall semester.

It seems pretty harsh for an act that did no damage to the school network and may have been useful by highlighting exactly what NAC endpoint checks do and what they don’t do.

Depending on the vendor and the method they use, endpoint scans can check whether an endpoint meets certain requirements like whether it has updated virus signatures and has antivirus software that is turned on; whether the personal firewall is configured properly and turned on; and whether the operating system is patched to the right degree.

The value of the endpoint check is that it can make sure that only machines that meet posture policies gain network access. At least in most cases it can make sure – not all cases, as the University of Portland case demonstrates.

If the policies are met, they increase the likelihood that the machine is clean, but that’s not a guarantee that it won’t be infected.