cancel
Showing results for 
Search instead for 
Did you mean: 

How many of you are using Host checker policies for your production remote access ?

Mrkool_
Super Contributor

How many of you are using Host checker policies for your production remote access ?

We have a fairly big user base 30k+ users and we are using host checker polcies for AV, OS to enforce compliance. I want to turn on remediation but i want to see how many of you are using these features in production?
10 REPLIES 10
DanSmart_
Contributor

Re: How many of you are using Host checker policies for your production remote access ?

I use two primary hostcheck rules:  One checks for McAfee VS anti-virus version, and the other checks the issuer name of the machine certificate on Windows computers.  We use Windows Certificate Auto-enroll for computers, and check this certificate for both Wireless EAP-TLS and on the IVE for proving domain membership of computers.

They are enforced on a role, but must be evaluated on the realm, of course.

To avoid issues with hostchecker and realms with Mac and Linux and hotel kiosks, we check custom user agent string values in realm resrictions since this doesn't kick off Hostcheck which will lockup machines not supporting it.  (These are pushed to users using Group Policy)  

-=Dan=-



Message Edited by DanSmart on 04-08-2009 02:11 PM




-=Dan=-
Kernal95_
Occasional Contributor

Re: How many of you are using Host checker policies for your production remote access ?

We use host checker policies to verify if the remote computer has certain Reg. entries. If they have these policy supplied reg. entries, then we allow the user to have access to the Network Connect option at the welcome page.

Other wise, they just are granted access to the book marks.

ksantema_
New Contributor

Re: How many of you are using Host checker policies for your production remote access ?

It's about the same here. All I do is look for a certain file that I've created and put in c:\Windows. If the file exists the user has Network Connect capabilities. If the file does not exist then the user only has certain bookmarks, such as OWA and a basic intranet site.
Mrkool_
Super Contributor

Re: How many of you are using Host checker policies for your production remote access ?

thanks for the reply guys so any reason why you are not using the more advanced features of host checker to check for AV and OS compliance and / or remediation or even SVW?
Inyoka_
Occasional Contributor

Re: How many of you are using Host checker policies for your production remote access ?

We're using Host Checker to assure that the clients (mostly from suppliers that do remote maintenance on production machines) are equipped with a virus scanner nd also have the latest Virus signatures and Windows Service Packs installed before Network Access is allowed.

We had no luck with the ckeck for individual Windows Patches (6.2R4, ESAP 1.4.7), Windows clients for which the chosen Patches were not applicable (due to another Windows Version), had also been blocked.

ksantema_
New Contributor

Re: How many of you are using Host checker policies for your production remote access ?

In our case we already have Systems Center doing remediation on the remote laptops. The only systems we allow NC are company laptops. If people connect from a non-company resource I simply don't let them NC. Instead I push them towards one of our VDI solutions (or towards Citrix if they annoy me).

Mrkool_
Super Contributor

Re: How many of you are using Host checker policies for your production remote access ?

Mathias if you dont mine me asking how is your av host checker policy setup? client specific or vendor? also any issues with setting the number of updates vs the days option that we had in the past?

Mrkool_
Super Contributor

Re: How many of you are using Host checker policies for your production remote access ?

this is what i want to do as well but the company does not want to hand out laptops to all it's user base so i am playing with svw and citirix / windows terminal based virtual workstation.
Inyoka_
Occasional Contributor

Re: How many of you are using Host checker policies for your production remote access ?

We separated Win- and AV-HostChecker Policy. The AV-HC-Policy is divided into several rules, but those are mainly used to group the AV-Clients from the different vendors, so this serves mainly an organizational purpose. We select single products, not Vendors, so we can be sure that a halfway actual Virus scanner is used. I someone uses a virus scanner that we did not pick yet, we add it most of the time. Exceptions are outdated Scanners and those not supported by the IVE. We allow a grace period of up to 3 updates, depending on how often a vendor publishes AV-Patterns. We do not use the X days option anymore.