Juniper SA2500 doesnt recognize newest Avast software

It’s amazing how many business packages require this (yet they state that they “work” with Windows 7). “Sage Construct” would be one that immediately comes to mind.

I’m interested to know why Juniper can’t check with Windows Security Center to see if AV software is installed and up to date.

Stephen

Juniper uses a third-party software for this and acquire this from OPSWAT. Why OPSWAT requires this for detection i do not know, maybe Lukas can explain this ?

and yes i know a lot of software still requires these privileges but where-ever i can i will kick out that kind of crap :slight_smile:
(Unfortunately our payroll software runs on windows 7, but its completely not ready for it, it requires regular users to have write access in c:\program files\ to make updates to settings on the station, without the update the program doesnt run blablabla… so im not happy with that at all and im looking into the hosted package for that particular software to replace it asap :))

so actually, yes it is happening and yes i have 1 program (luckely) that does that too…
but this is because the program had a last major update before win7 was released and we was already running it.
Now there is a possibility to run it “in the cloud” which does not have my preference, but the crap the program needs (im 1 hour actively busy installing it and configuring it on 1 desktop) to get it working enlightens me to make an exception for this program. (it also takes a database load of my db server ;))

at this time im still in support.

This week i received an update from Juniper, which in turn has been in contact with OPSWAT (the developer of the host checker)

This is (edited) what came out:

With the current implementation with opswat, check if RTP is enabled is through Security Center, and Security Center requires admin access for any data inquiries. Opswat were checking some other way to achieve this( get the RTP status), however came to know that, this is working as per the design and there is no other way to query ?CheckRTP? for Avast! Business Protection apart from using Security Center.

So this is a limitation with OPSWAT. They will check for RTP status through Security Center.

Then i asked if there has been contact between Avast and OPSWAT or Juniper.
The answer to that was that OPSWAT made an enchancement (?) request to Avast about this, and basicly based on the history they dont expect an update soon…

The only temporary solution for me right now is to disable the client AV RTP check on my security device and allow people without the RTP status to enter my network. Which i find a huge security risk, but its the only way at this moment to get those users the really badly needed VPN connection.

@studio_two maybe a bit late but this is what OPSWAT says:

to read the real time protection from security center the user executing the check has to have administrative rights, which my users dont have and wont get.
So at this moment i have 2 evil choices

  1. gamble that administrative rights will work, and give my users a huge potential to install malicious shit or uninstall stuff and thus risk infection of my network since they hookup with VPN
  2. disable the real time protection check on the SA2500 until this problem is fixed. Again risking massive infection when one of the devices is infected some how. The devices that hook up with VPN are outside the office 100% of the time unless there is some sort of special maintenance that I need to do, so i do not control what is happening to the devices that much.

Tomorrow (20-02-2012) i will HAVE to start going for option 2 since option 1 is absolutely not going to happen, but the keys that would get refreshed by the VPN connection are going to expire and then I have to recall those devices again which means at least 1 day of not working for those users.

Right now (last week) i have given the contact details from an OPSWAT person that claimed Avast was not replying and stuff, and im waiting for VLK or Lukas to inform me with some sort of information about the situation to resolve it.

No, not too late. Thanks for the update.

@avast team

I am waiting for answers here by mail since February??
I have send the contact information in February, meanwhile Juniper asked me to temporary close the case because its stale without updates since they are also waiting for news from me from avast.

last week i asked one of the avast teammembers to get me in contact again and havent heard from it so far…

In the mean time i have a big security hole in my network now
i have been forced to stop checking for AV products on my business laptops.
They are mainly outside the office so i have no insight on what exactly is attacking them and since they need to make vpn connection (which is possible only because i had to turn of the AV check) im opening my company network to potential infestation disaster…

VLK i know that Avast became bronze partner with OPSWAT, but its not enough like you said unfortuanately

please give me an update here or in my mail

@other evangelists: can someone report this to a mod so this can escalate into the avast team again, thnx

Hi wpn,
we are in direct contact with the Opswat guys. I’ll let you know when the negotiations end.

best regards
Lukas.

Sweet, thanks Lukas

Not sure if you guys care, but ESET SmartSecurity 5.x has exactly the same problem.
So far, Juniper has been anything but helpful :frowning:

At any rate … I managed to find a workaround with ESET - maybe it will work for Avast! as well.

Start Internet Explorer as administrator (Right-click, Run as administrator).
Navigate to your VPN login page and enter credentials.
Now HostChecker will succeed, and I will be logged in and have access to install NetworkConnect.
Install NetworkConnect.

Now on new VPN logins, I don’t have to start anything as admin … I can just click directly on the NetworkConnect icon, and it works!

@uxorious, interesting way to approach
as said i already changed the check to get things to work and unfortunately i have no time at this moment to test your work around.

i hopefully receive some communication about this soon from VLK or Lucas

I noticed that the last 2 release notes from Juniper (http://www.juniper.net/support/products/esap/) lists this a known issue/limitation.
From my dealings with Juniper support, I did not get the impression that it is going to change any time soon.

Hi,
some update. We are working with opswat on solution for this case. It seems that they need to check state of the real time protection but they require to do it without admin rights (weird…). It’s really complicating things however we are looking for some way how to fix it.
And yes, avast is not the only AV with the same “issue” :frowning:

regards
Lukas.

Thanks for the update

What has changed between the detecting the real time state from Avast 6/7 and the old 4.8 net client?
With the netclient there was no problem, but then again the netclient was aimed to be for XP not vista/7, but maybe there is a clue there

I’ve logged a fault call with Juniper on this. Currently I’ve only been given a workaround which is:

“The Current implementation of OPSWAT needs UAC elevation and administrator’s privilege.
The workaround is to turn set ‘run as administrator’ on for dsHostChecker.exe, which is
present in the HC installed folder (C:\User<username>\AppData\Roaming\Juniper
Networks\HostChcker).” This can be done by going to the properties of the .exe file and going to the Compatability tab.

This is not an acceptable solution for our work environment but it’s a workaround if anyone wants to use it.

@spirro thank you for this

i have been extensively busy with Juniper and opswat and Avast about this. Indeed the solution that you propose is not acceptable in my environment either.

right now im posting again to see if there is an update to this issue since its been since 21-10-2011 that i have this problem and 11-04-2012 the last update from avast side :slight_smile:

so hereby the question: What is the status of this issue?

status is - we provided a way to OPSWAT to “workaround” the admin right elevation issue with avast!. However it seems that our solution solves only one particular issue - “av real time status”. Now we are working on other requirement from their side.
And in the meanwhile we are proceeding with the OPSWAT bronze certification for v7 business products.

regards
Lukas.

sweet to hear that, thank you for the quick reply

keep me updated please :slight_smile:

Hello

Is there any new update on this issue ?
Has OPSWAT released that workaround sollution yet for Juniper to incorporate it in their updates?

BUMP

Hoi WPN,
we worked on the issue with OPSWAT and provided them a solution - or let’s call it rather a workaround - for the Threat History.

hth
Lukas.