
That second approach is used in this example.įor older versions of An圜onnect (3.1 and earlier), there was a separate package available on CCO (example: hostscan_3-k9.pkg) which could have been configured and provisioned on ASA separately (with csd hostscan image command) - but that option do not exists anymore for An圜onnect version 4.0.ĪSA is preconfigured with basic remote VPN access (Secure Sockets Layer (SSL)): webvpnĪnyconnect image disk0:/anyconnect-win-1-k9.pkg 1 HostScan is a part of CSD which could be provisioned from ASA. Example files (hostscan-win-1-pre-deploy-k9.msi) are shared on Cisco Connection Online (CCO). HostScan module can be installed manually on the endpoint.

This time, full network access is provided (DAP policy called FileExists are matched).

Cisco An圜onnect Secure Mobility Client, Version 4.0 and Later.Cisco Identity Services Engine (ISE) Software, Versions 1.3 and Later.The information in this document is based on these software and hardware versions: Cisco An圜onnect Secure Mobility Client.Prerequisites RequirementsĬisco recommends that you have knowledge of these topics: After VPN session is established, compliant station are allowed full network access whereas non-compliant station has limited network access.Īlso, CSD and An圜onnect 4.0 provisioning flows are presented. The posture is performed locally by ASA with the use of Cisco Secure Desktop (CSD) with HostScan module.


This document describes how to perform the posture for remote VPN sessions terminated on Adaptive Security Appliance (ASA).
