cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
739
Views
0
Helpful
3
Replies

CSD, DAP, Host Scans, etc.

richardblair
Level 1
Level 1

    I have a Cisco ASA 5515, running 9.0(2) and device manager version 7.1(2).  What I am trying to accomplish is to examine SSL/AnyConnect client requests, check to see if they are from a company PC and allow them access if the are.  If they are not, I would like to check for AV/Spyware/Firewall and start them/update them if the need it, or deny access if they are missing, will not start or will not update.  It seems to me that I need to implement a combination of features to accomplish this.  The problem I am having is understanding which pieces of which I actually need.  My ASA is licensed for AnyConnect Premium and Advanced Endpoint Assessment, so I think I have everything I need except the brain power to untangle this.

Any help, such as good examples to follow would be much appreciated!

1 Accepted Solution

Accepted Solutions

Marvin Rhoads
Hall of Fame
Hall of Fame

Yes, the AnyConnect Premium plus AEA license using CSD should cover what you need.

Have you had a look at this whitepaper on configuring Dynamic Access Policies? I believe it covers everything you're wanting to do and then some.

View solution in original post

3 Replies 3

Marvin Rhoads
Hall of Fame
Hall of Fame

Yes, the AnyConnect Premium plus AEA license using CSD should cover what you need.

Have you had a look at this whitepaper on configuring Dynamic Access Policies? I believe it covers everything you're wanting to do and then some.

Marvin, this is excellent!  Not sure why I was never able to find it before, but thanks!

You're welcome. Glad it helped.

Thanks for the rating - that one broke me into the VPN Leaderboard.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: