I’d like to know if it’s possible to restrict which version of SVC it’s possible to allow for remote users to connect to my AnyConnect VPN. I know it’s possible with IPSEC clients – i.e.
group-policy [policy_name] attributes
client-access-rule 1 permit type WinNT version 5.0.05.0290
client-access-rule 2 deny type * version *
Is there something similar for SVC ? Thanks.
Unfortunately there is no client-access-rule restriction with anyconnect client.
However, only anyconnect image/version that you install on the ASA will allow user to connect.