The big problem here is that these programs automatically update themselves to the latest versions. Then users can't login and we (IT) can't really do anything for them except help install a different product that does work.
Good to hear that Cisco is working on a better solution to deal with updated AV/AS apps.
We are on later versions than 4.1.8 with 'ANY' selected to allow Webroot, but it's not being recognized. I had a student in just yesterday that has Webroot and NAC wouldn't recognize it. We put AVG 8.5 on and it came up fine.
We have configured the outside and inside Interface with official ipv6 adresses, set a default route on outside Interface to our router, we also have definied a rule , which also gets hits, to permit tcp from inside Interface to any6.
In Syslog I also se...