<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Microsoft Direct Access VPN Interoperability in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/microsoft-direct-access-vpn-interoperability/m-p/3517580#M511144</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote" style="color: #000000; font-family: -webkit-standard;"&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #44546a; font-size: 14.6667px;"&gt;Dear TME,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #44546a; font-size: 14.6667px;"&gt;I need to know about Compatibility of Microsoft Direct Access VPN along with Cisco ISE &amp;amp; Cisco any connect.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #44546a; font-size: 14.6667px;"&gt;I could not find alot of data about it. So :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- Can ISE see the Microsoft direct access VPN server as a NAD &amp;amp; communicate with it via Radius &amp;amp; Issue COA?&lt;/P&gt;&lt;P&gt;2- Can anyconnect coexist with the Microsoft direct access VPN agent to do the posture part only?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly do share more details or links about this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Wissam&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 02 Apr 2018 14:16:37 GMT</pubDate>
    <dc:creator>welchari</dc:creator>
    <dc:date>2018-04-02T14:16:37Z</dc:date>
    <item>
      <title>Microsoft Direct Access VPN Interoperability</title>
      <link>https://community.cisco.com/t5/network-access-control/microsoft-direct-access-vpn-interoperability/m-p/3517580#M511144</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;BLOCKQUOTE class="jive-quote" style="color: #000000; font-family: -webkit-standard;"&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #44546a; font-size: 14.6667px;"&gt;Dear TME,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #44546a; font-size: 14.6667px;"&gt;I need to know about Compatibility of Microsoft Direct Access VPN along with Cisco ISE &amp;amp; Cisco any connect.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #44546a; font-size: 14.6667px;"&gt;I could not find alot of data about it. So :&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1- Can ISE see the Microsoft direct access VPN server as a NAD &amp;amp; communicate with it via Radius &amp;amp; Issue COA?&lt;/P&gt;&lt;P&gt;2- Can anyconnect coexist with the Microsoft direct access VPN agent to do the posture part only?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Kindly do share more details or links about this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Wissam&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Apr 2018 14:16:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/microsoft-direct-access-vpn-interoperability/m-p/3517580#M511144</guid>
      <dc:creator>welchari</dc:creator>
      <dc:date>2018-04-02T14:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Direct Access VPN Interoperability</title>
      <link>https://community.cisco.com/t5/network-access-control/microsoft-direct-access-vpn-interoperability/m-p/3517581#M511146</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #000000; font-family: -webkit-standard, serif; font-size: 10.5pt;"&gt;I am pretty sure that Microsoft direct access doesn't act like a &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: -webkit-standard, serif; font-size: 14px;"&gt;traditional&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: -webkit-standard, serif; font-size: 10.5pt;"&gt; VPN service like anyconnect where you would bring up a tunnel and be required to do &lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-family: -webkit-standard, serif; font-size: 14px;"&gt;posture&lt;/SPAN&gt;&lt;SPAN style="color: #000000; font-size: 10.5pt; font-family: -webkit-standard, serif;"&gt; and then do a COA after posture is complete. Regardless only cisco VPNs support COA &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Therefore there is no integration or co-existence.&lt;/P&gt;&lt;P&gt;&lt;A href="http://techgenix.com/microsoft-directaccess-overview/" title="http://techgenix.com/microsoft-directaccess-overview/"&gt;Microsoft DirectAccess: An Overview&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; font-family: '-webkit-standard',serif; color: black;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; font-family: '-webkit-standard',serif; color: black;"&gt;Added our VPN SME as well to keep me honest&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; font-family: '-webkit-standard',serif; color: black;"&gt;&lt;A href="https://community.cisco.com//u1/148562"&gt;pcarco&lt;/A&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10.5pt; font-family: '-webkit-standard',serif; color: black;"&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Apr 2018 15:54:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/microsoft-direct-access-vpn-interoperability/m-p/3517581#M511146</guid>
      <dc:creator>Jason Kunst</dc:creator>
      <dc:date>2018-04-02T15:54:51Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Direct Access VPN Interoperability</title>
      <link>https://community.cisco.com/t5/network-access-control/microsoft-direct-access-vpn-interoperability/m-p/3517582#M511148</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Wissam &amp;amp; Jason,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Microsoft Direct Access is a Machine Tunnel and uses a certificate to achieve this tunnel - there is no user auth&amp;nbsp;&amp;nbsp;&amp;nbsp; The tunnel is established by the machine and not the user which is completely different than AnyConnect.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;CoA requires Radius for the AuthN&amp;nbsp; or AuthZ so an endpoint with Direct Access is not going to work with ISE the way AnyConnect / System Scan and ISE integrate for CoA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No, it can not co-exist the way you describe if the user is remote then then AnyConnect must establish the tunnel to the ASA and Auth to ISE.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;Paul&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 02 Apr 2018 20:15:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/microsoft-direct-access-vpn-interoperability/m-p/3517582#M511148</guid>
      <dc:creator>pcarco</dc:creator>
      <dc:date>2018-04-02T20:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft Direct Access VPN Interoperability</title>
      <link>https://community.cisco.com/t5/network-access-control/microsoft-direct-access-vpn-interoperability/m-p/3517583#M511149</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks alot guys for the helpful answers.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 03 Apr 2018 07:14:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/microsoft-direct-access-vpn-interoperability/m-p/3517583#M511149</guid>
      <dc:creator>welchari</dc:creator>
      <dc:date>2018-04-03T07:14:45Z</dc:date>
    </item>
  </channel>
</rss>

