User Guide

OmniAccess 3500 Nonstop Laptop Guardian Release 1.2
10
Problem Description: User-installed Cygwin software may not work or stop
working after installing the OmniAccess 3500 NLG client software.
Impact: The Cygwin application may not work for the end user.
Workaround/s: The installation of the OmniAccess 3500 NLG client software
includes a particular version of Cygwin. Please make sure that your installed
version of Cygwin is the same as the one installed with the OmniAccess 3500 NLG
client software. Two different versions of Cygwin cannot coexist.
A
NTI
-T
AMPERING
11. Internal tracking ID: 1244
Problem Description: The OmniAccess 3500 NLG client software can be uninstalled
using the Windows restore utility.
Impact: An attacker that manages to log into the laptop may get rid of the
enterprise-enforced security controls. However, logging into the laptop is not
sufficient to obtain access to the sensitive data stored in the encrypted volume.
Workaround/s: To prevent anyone from removing the client software by invoking
an older restore point, make sure that there are no Windows System Restore
points in the laptop when the OmniAccess 3500 NLG client software is installed.
12. Internal tracking ID:
Problem Description: The OmniAccess 3500 NLG-enabled laptop can be booted
using an external boot medium.
Impact: Someone having physical access to the laptop may get rid of the
enterprise enforced security controls. Still this would not give access to the
sensitive data stored in the encrypted volume.
Workaround/s: To prevent the capability to boot the laptop from an external
medium, first disable in the BIOS the booting from all external means such as CD,
USB, network, etc., and then password-lock the BIOS.
13. Internal tracking ID: 767
Problem Description: It is not possible to connect to the enterprise network while
the one-time password is in effect, not even with a third-party IPsec client.
Impact: The end user may not be able to access the enterprise network.
Workaround/s: This is a security requirement. However this behavior will be
reviewed and possibly modified in the next release of the OmniAccess 3500 NLG
platform based on customer feedback.
A
UTO
VPN
14. Internal tracking ID:
Problem Description: The laptop cannot be connected directly to the Internet.
Impact: Direct access to the Internet is not possible even if needed.
Workaround/s: This is a security feature and is requested by most customers. In
case of emergency, pull the card out of the laptop, get the one time password
from your administrator, unlock the laptop and, for the duration of the one time