<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Anyconnect features support on newest FTD code in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/anyconnect-features-support-on-newest-ftd-code/m-p/4267292#M1077046</link>
    <description>&lt;P&gt;SAML SSO is supported as of FTD 6.7&lt;/P&gt;
&lt;P&gt;DAP and Hostscan are not yet supported via the GUI although they are exposed via the REST API. We hope to see them in the 6.8 GUI this spring, but Cisco doesn't confirm the features in unreleased code until the last minute.&lt;/P&gt;</description>
    <pubDate>Tue, 05 Jan 2021 18:59:16 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2021-01-05T18:59:16Z</dc:date>
    <item>
      <title>Anyconnect features support on newest FTD code</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-features-support-on-newest-ftd-code/m-p/4267242#M1077042</link>
      <description>&lt;P&gt;We have a client that wants to migrate their ASA 5525X AnyConnect configuration to an Firepower 2130 running on FTD code, they have these feature currently enabled for AnyConnect:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Dynamic Access Policies&lt;/P&gt;&lt;P&gt;Host Scan&lt;/P&gt;&lt;P&gt;SAML SSO&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Last summer I had another customer with the same requirements and we found from a Cisco engineer and later on documentation that the features below were not supported on FTD 6.4 and there were no plans to develop support for the features described below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Does anyone know if these features are still not supported in the newest FTD code? And are there any plans in the road map to support these features? Thank you&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;Currently unsupported on FTD, but available on ASA:&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p2"&gt;&amp;nbsp;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- Double AAA Authentication&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- Dynamic Access Policy&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- Host Scan&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- ISE posture&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- RADIUS CoA&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- VPN load-balancer&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- Local authentication&lt;/SPAN&gt;&lt;SPAN class="apple-converted-space"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- LDAP attribute map&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- AnyConnect customization&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- AnyConnect scripts&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- AnyConnect localization&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- Per-app VPN&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- SCEP proxy&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- WSA integration&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- SAML SSO&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- Simultaneous IKEv2 dynamic crypto map for RA and L2L VPN&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- AnyConnect modules (NAM, Hostscan, AMP Enabler etc.) – DART is&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;installed by default&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- TACACS, Kerberos (KCD Authentication and RSA SDI)&lt;/SPAN&gt;&lt;/P&gt;&lt;P class="p1"&gt;&lt;SPAN class="s1"&gt;- Browser Proxy&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 17:54:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-features-support-on-newest-ftd-code/m-p/4267242#M1077042</guid>
      <dc:creator>borman.bravo</dc:creator>
      <dc:date>2021-01-05T17:54:52Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect features support on newest FTD code</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-features-support-on-newest-ftd-code/m-p/4267245#M1077044</link>
      <description>&lt;P&gt;This is the latest release and supported feature mentioned in the release notes.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/670/relnotes/firepower-release-notes-670/m_features_functionality.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/670/relnotes/firepower-release-notes-670/m_features_functionality.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 17:58:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-features-support-on-newest-ftd-code/m-p/4267245#M1077044</guid>
      <dc:creator>balaji.bandi</dc:creator>
      <dc:date>2021-01-05T17:58:12Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect features support on newest FTD code</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-features-support-on-newest-ftd-code/m-p/4267292#M1077046</link>
      <description>&lt;P&gt;SAML SSO is supported as of FTD 6.7&lt;/P&gt;
&lt;P&gt;DAP and Hostscan are not yet supported via the GUI although they are exposed via the REST API. We hope to see them in the 6.8 GUI this spring, but Cisco doesn't confirm the features in unreleased code until the last minute.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 18:59:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-features-support-on-newest-ftd-code/m-p/4267292#M1077046</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-01-05T18:59:16Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect features support on newest FTD code</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-features-support-on-newest-ftd-code/m-p/4267295#M1077047</link>
      <description>&lt;P&gt;Hi Marvin, could you please clarify what you mean by "although they are exposed via the REST API" can I configure and maintain these features (DAP and Hostscan) via the API tool for anyconnect? is this API on the FMC or FTD? thank you&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 19:03:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-features-support-on-newest-ftd-code/m-p/4267295#M1077047</guid>
      <dc:creator>borman.bravo</dc:creator>
      <dc:date>2021-01-05T19:03:49Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect features support on newest FTD code</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-features-support-on-newest-ftd-code/m-p/4267300#M1077048</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/276553"&gt;@borman.bravo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;double authentication, ISE posture, RADIUS CoA, SCEP proxy, anyconnect modules are all supported as of 6.7&lt;/P&gt;
&lt;P&gt;VPN Load Balancer is planned, no timescales yet though.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 19:05:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-features-support-on-newest-ftd-code/m-p/4267300#M1077048</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-01-05T19:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect features support on newest FTD code</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-features-support-on-newest-ftd-code/m-p/4267313#M1077049</link>
      <description>&lt;P&gt;The API support for DAP and Hostscan is limited to non-FMC managed FTD devices as of 6.7. The FMC 6.7 API does not currently have DAP or Hostscan support.&lt;/P&gt;
&lt;P&gt;So you would need to have an FDM- or CDO-managed FTD and interact with it directly via the API using your own code.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FDM 6.7 API - DAP" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/100942i9C346FEC9EB42BE4/image-size/large?v=v2&amp;amp;px=999" role="button" title="FDM 6.7 API - DAP.PNG" alt="FDM 6.7 API - DAP" /&gt;&lt;span class="lia-inline-image-caption" onclick="event.preventDefault();"&gt;FDM 6.7 API - DAP&lt;/span&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 19:19:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-features-support-on-newest-ftd-code/m-p/4267313#M1077049</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2021-01-05T19:19:01Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect features support on newest FTD code</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-features-support-on-newest-ftd-code/m-p/4267352#M1077052</link>
      <description>&lt;P&gt;Thanks Rob, for "anyconnect modules are all supported as of 6.7" is this on the FMC or non-FMC managed?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 20:07:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-features-support-on-newest-ftd-code/m-p/4267352#M1077052</guid>
      <dc:creator>borman.bravo</dc:creator>
      <dc:date>2021-01-05T20:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: Anyconnect features support on newest FTD code</title>
      <link>https://community.cisco.com/t5/network-security/anyconnect-features-support-on-newest-ftd-code/m-p/4267353#M1077053</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/276553"&gt;@borman.bravo&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Both, via FMC and FDM. Although if using FDM you have to use the API to upload the modules&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/670/relnotes/firepower-release-notes-670/m_features_functionality.html" target="_self"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/670/relnotes/firepower-release-notes-670/m_features_functionality.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Jan 2021 20:12:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/anyconnect-features-support-on-newest-ftd-code/m-p/4267353#M1077053</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2021-01-05T20:12:48Z</dc:date>
    </item>
  </channel>
</rss>

