<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic ASA: AnyConnect uses wrong Group Policy when using DAC in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-anyconnect-uses-wrong-group-policy-when-using-dac/m-p/4493518#M1084653</link>
    <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;our customer uses a Firepower 2101 running a ASA OS 9.10(1)44 and has many Dynamic Access Policies (DAC) for their business partners.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;He created a new AD Group and a new DAC and specifies a new&amp;nbsp;Group Policy for this new&amp;nbsp;business partner named Pavis (see attached screen dump).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The login is working for a test-user of this group but AnyConnect is using another&amp;nbsp;Group Policy (GroupPolicy_Bionorica_SE_EXTERN) as specifies (GroupPolicy_Bionorica_SE_EXTERN_Pavis) in the DAC. So the IP-Address pool is wrong and the ACLs dont't meet their requirements.&lt;BR /&gt;&lt;BR /&gt;I assume that the reason for this misbehaviour in not on the ASA but on the AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Question is: What could cause the usage of the wrong&amp;nbsp;Group Policy even if the right one is specified in the DAC and where I need to check this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attached you find the configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Every hint is welcome!!!&lt;BR /&gt;&lt;BR /&gt;Thanks a lot!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Bye&lt;/P&gt;&lt;P&gt;R.&lt;/P&gt;</description>
    <pubDate>Wed, 27 Oct 2021 14:25:45 GMT</pubDate>
    <dc:creator>swscco001</dc:creator>
    <dc:date>2021-10-27T14:25:45Z</dc:date>
    <item>
      <title>ASA: AnyConnect uses wrong Group Policy when using DAC</title>
      <link>https://community.cisco.com/t5/network-security/asa-anyconnect-uses-wrong-group-policy-when-using-dac/m-p/4493518#M1084653</link>
      <description>&lt;P&gt;Hello everybody,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;our customer uses a Firepower 2101 running a ASA OS 9.10(1)44 and has many Dynamic Access Policies (DAC) for their business partners.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;He created a new AD Group and a new DAC and specifies a new&amp;nbsp;Group Policy for this new&amp;nbsp;business partner named Pavis (see attached screen dump).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The login is working for a test-user of this group but AnyConnect is using another&amp;nbsp;Group Policy (GroupPolicy_Bionorica_SE_EXTERN) as specifies (GroupPolicy_Bionorica_SE_EXTERN_Pavis) in the DAC. So the IP-Address pool is wrong and the ACLs dont't meet their requirements.&lt;BR /&gt;&lt;BR /&gt;I assume that the reason for this misbehaviour in not on the ASA but on the AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Question is: What could cause the usage of the wrong&amp;nbsp;Group Policy even if the right one is specified in the DAC and where I need to check this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Attached you find the configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Every hint is welcome!!!&lt;BR /&gt;&lt;BR /&gt;Thanks a lot!&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;Bye&lt;/P&gt;&lt;P&gt;R.&lt;/P&gt;</description>
      <pubDate>Wed, 27 Oct 2021 14:25:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-anyconnect-uses-wrong-group-policy-when-using-dac/m-p/4493518#M1084653</guid>
      <dc:creator>swscco001</dc:creator>
      <dc:date>2021-10-27T14:25:45Z</dc:date>
    </item>
  </channel>
</rss>

