Search This Blog

Tuesday, January 12, 2010

Windows 7 64bit VPN client - Cisco ASA

Had a minor issue with connecting my 64bit Win7 client to our Cisco ASA.
Our ASA does not currently support the AnyConnect Cisco client (our firmware/software combo does not support this yet).

So, I had to go looking for a VPN client that could connect my laptop....found it with a company called NCP.  Look for their Universal IPSec client.

http://www.ncp-e.com/

Purchased their client - installed the client.
Now - how do I configure this thing.....

Turns out it is very, very easy.

Just do a file/open in NCP and point it at your Cisco config file - it magically does the rest.

Fully configured and ready to go without my having to do anything other than an installation.

I Love it!

Software List - WIndows 7 64bit

Here is my updated list of software I have running on my Windows 7 64bit machine:

  • Flash 10
  • Apple iTunes with iPhone support
  • Java 6 update 17 (32 and 64 bit)
  • JRE 1.6.0_10
  • KeePass 2.09
  • Microsoft Live Meeting
  • Microsoft Forefront Client
  • Microsoft Office Communicator 2007 R2 (OCS)
  • Microsoft Office 2007 Professional Plus
  • NCP VPN Client (for 64 bit VPN access to Cisco ASA)
  • Nitro PDF Pro
  • OpenEdge 10.1B
  • PGP Desktop
  • QuickTime
  • Royal TS
  • Skype 4.1
  • TinyTerm
  • TreeSize Pro 5.3.2
  • Vmware Infrastructure Client 2.5
  • VMware Workstation
  • WebEx Client
  • Windows Live Essentials
  • Windows XP Mode (just about to ditch this and go total VMware Workstation)
  • WinRAR

Sunday, January 10, 2010

Forefront Corporate AV Malware Solution - Single Server

I have finished a project to install and configure a Forefront single server solution.  We are using this to replace a current TrendMicro Officescan product.
     My experience with Trend was that it did great with AV but was very lacking in tools and detection of malware.  So far Forefront has been excellent at detection and cleaning of malware issues.

This solution is installed under VMWare ESX v3.5 running a guest OS of Windows 2003 R2.

Installed Forefront server in a single server mode using most of the default settings.
http://technet.microsoft.com/en-us/library/bb404225.aspx

Once installed you have to setup your initial Forefront policies - this is done in the admin console.  Once you have defined a policy for scanning and what the client will allow you have the option to either add this to an existing GPO or create/link a new GPO.  This is very easy and the software does most of the work for you.

Now that you have a policy linked in GPO you have to deploy the client software.
For us, we use SCCM and this was setup to push to all of our Office grade machines.  Just created a silent installation package and pushed it via SCCM.
       This link my help in locating the new Forefront client installation MSI:
http://blogs.technet.com/fcsnerds/archive/2009/04/01/slipstreaming-a-client-security-client-installation.aspx
       Here is a good blog entry on how to create the package in SCCM (it is very straightforward to do)
http://blogs.microsoft.co.il/blogs/yanivf/archive/2008/02/20/deploying-forefront-client-security-using-sccm-2007-step-by-step.aspx

Lastly, we have to setup SCCM to update all the definitions.  I used the following post as a template for how to get this done:
http://technet.microsoft.com/en-us/library/dd185652.aspx

I have had great success with this setup.  If you want to experiment with Forefront prior to your own installatoin I suggest the Technet Virtual Labs:
http://technet.microsoft.com/en-us/forefront/clientsecurity/bb499665.aspx