The CEC Client Validation Program: How Our Network is Secured

The campus has repeatedly been plagued by unpatched and infected computers. To prevent such problems in the College of Engineering and Computing, we have employed Cisco's Dynamic VLAN feature and created a Client Validation Program.
Student Computer Network Access

Since student computers are notorious for not being properly patched, we require that student computers be validated before receiving full network access. To do this we have created the Client Validation Program and linked it with our Dynamic VLAN Registration System. Students download, install, and run the Client Validation Program to perform three categories of checks that the College of Engineering and Computing requires before network access can be granted.
The three categories are:
- Windows Critical Patches: The computer must have all Windows Critical Patches installed.
- McAfee VirusScan Installation: The computer must have McAfee VirusScan installed with the scan engine and DAT file up-to-date.
- Current Infections: The computer must not be already infected as determined by McAfee's Stinger software.
Once the Client Validation Program verifies these three categories, the student is presented a web page for login that automatically submits the computer's MAC addresses for registration. Thus, through this system, only the members of our CEC community have access to the CEC network, and only with properly secured computers. Once registered, the computer is allowed full network access for seven days. After this time, the computer is required to re-validate. If the computer re-validates before the automatic expiration, then the expiration timer is reset for an additional seven days.
Faculty and Staff Computer Network Access

Every faculty, staff, and lab computer in the college is assigned a qualified administrator. This responsible individual knows how and when to patch and secure a computer for network access. The Dynamic VLAN Registration System, a web browser interface accessible only to these administrators, allows or disallows a computer's network access. Administrators use this web page to register, unregister, or block network access for the computers for which they are responsible.