Does the ASA VPN or ASA Any Connect have the ability to check for anti-virus and/or firewall stuff from the connecting endpoint? I know there was limited support with the dedicated VPN concentrators such as the 3020 but need to know if this support is in the ASA and if so to what extent. I am having limited success in finding this out from teh configuration guides and examples on CCO.
For Cisco ASA and ISE products capable of performing a registry/process check on the endpoint device, you can use a solution from OPSWAT called GEARS. GEARS will check and report on the compliance of endpoints with respect to:
1) applications designed to protect it such as antivirus, personal firewalls, antiphishing, hard disk encryption, patch management, etc.
2) potentially unwanted applications such as public file sharing
3) whether or not the endpoint is infected with malware
GEARS can be configured to take remediation actions such as:
1) enabling a disabled firewall or antivirus application
2) disabling an unwanted application such as public file sharing
A HowTo Guide providing step-by-step instructions for ASA and ISE administrators to configure a registry/process check to read GEARS compliance information is posted at https://gears.opswat.com/integration/secure-access