<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Show applied dap policies in FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/show-applied-dap-policies-in-ftd/m-p/5243054#M1118557</link>
    <description>&lt;P&gt;I believe you can only get these via a DART file (from the client) or from a debug (on FTD headend). The LINA engine in FTD handles DAP pretty much the same as an ASA does, so the following article (old but mostly relevant) may help:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/information-to-acquire-for-dap-troubleshooting/ta-p/3145426" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-knowledge-base/information-to-acquire-for-dap-troubleshooting/ta-p/3145426&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The RA VPN dashboard or show command mentioned by &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt; unfortunately do not reveal this info. See sample output from the show command here (see Step 6):&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.defenseorchestrator.com/t_verify-remote-access-vpn-configuration-of-asa.html" target="_blank" rel="noopener"&gt;https://docs.defenseorchestrator.com/t_verify-remote-access-vpn-configuration-of-asa.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 03 Jan 2025 13:14:18 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2025-01-03T13:14:18Z</dc:date>
    <item>
      <title>Show applied dap policies in FTD</title>
      <link>https://community.cisco.com/t5/network-security/show-applied-dap-policies-in-ftd/m-p/5243019#M1118550</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;Does anyone know if its possible to see what DAP policies or ACLSs are applied to a Remote access VPN session on the FTD?&lt;/P&gt;&lt;P&gt;We can do it on the ASDM on our ASA, but where can we find this info on the FTD?&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 11:27:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/show-applied-dap-policies-in-ftd/m-p/5243019#M1118550</guid>
      <dc:creator>carl_townshend</dc:creator>
      <dc:date>2025-01-03T11:27:06Z</dc:date>
    </item>
    <item>
      <title>Re: Show applied dap policies in FTD</title>
      <link>https://community.cisco.com/t5/network-security/show-applied-dap-policies-in-ftd/m-p/5243021#M1118551</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/320506"&gt;@carl_townshend&lt;/a&gt; To see what was applied to an actual user session, the "Remote Access VPN Dashboard" on the FMC may display this information (I don't have access to confirm). Else from the FTD CLI run "show vpn-sessiondb detail anyconnect" and filter on the user to see what has been applied.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 11:59:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/show-applied-dap-policies-in-ftd/m-p/5243021#M1118551</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-01-03T11:59:47Z</dc:date>
    </item>
    <item>
      <title>Re: Show applied dap policies in FTD</title>
      <link>https://community.cisco.com/t5/network-security/show-applied-dap-policies-in-ftd/m-p/5243035#M1118552</link>
      <description>&lt;P&gt;Hi Rob&lt;/P&gt;&lt;P&gt;I just tried that command on my ASA and it does not show you the DAP records applied.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 12:23:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/show-applied-dap-policies-in-ftd/m-p/5243035#M1118552</guid>
      <dc:creator>carl_townshend</dc:creator>
      <dc:date>2025-01-03T12:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: Show applied dap policies in FTD</title>
      <link>https://community.cisco.com/t5/network-security/show-applied-dap-policies-in-ftd/m-p/5243039#M1118554</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/320506"&gt;@carl_townshend&lt;/a&gt; For example, if you assign an ACL via the DAP, this will appear as "Filter Name: &amp;lt;name of ACL&amp;gt;" when you look at the session using the "show vpn-sessiondb detail anyconnect " command. Example of that scenario here - &lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-firewalls/200238-ASA-VPN-posture-with-CSD-DAP-and-AnyCon.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-firewalls/200238-ASA-VPN-posture-with-CSD-DAP-and-AnyCon.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 12:37:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/show-applied-dap-policies-in-ftd/m-p/5243039#M1118554</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2025-01-03T12:37:53Z</dc:date>
    </item>
    <item>
      <title>Re: Show applied dap policies in FTD</title>
      <link>https://community.cisco.com/t5/network-security/show-applied-dap-policies-in-ftd/m-p/5243043#M1118555</link>
      <description>&lt;P&gt;We just get the below&lt;/P&gt;&lt;P&gt;There is no such ACL as&amp;nbsp;DAP-ip-user-60A28A09 on our ASA.&lt;/P&gt;&lt;P&gt;SSL-Tunnel:&lt;BR /&gt;Tunnel ID : 1237.2&lt;BR /&gt;Assigned IP : x.x.x.x Public IP : x.x.x.x&lt;BR /&gt;Encryption : AES-GCM-256 Hashing : SHA384&lt;BR /&gt;Ciphersuite : ECDHE-RSA-AES256-GCM-SHA384&lt;BR /&gt;Encapsulation: TLSv1.2 TCP Src Port : 51761&lt;BR /&gt;TCP Dst Port : 443 Auth Mode : userPassword&lt;BR /&gt;Idle Time Out: 30 Minutes Idle TO Left : 28 Minutes&lt;BR /&gt;Conn Time Out: 720 Minutes Conn TO Left : 469 Minutes&lt;BR /&gt;Client OS : Windows&lt;BR /&gt;Client Type : SSL VPN Client&lt;BR /&gt;Client Ver : Cisco AnyConnect VPN Agent for Windows 4.10.04065&lt;BR /&gt;Bytes Tx : 11198 Bytes Rx : 894&lt;BR /&gt;Pkts Tx : 18 Pkts Rx : 17&lt;BR /&gt;Pkts Tx Drop : 0 Pkts Rx Drop : 0&lt;BR /&gt;Filter Name : DAP-ip-user-60A28A09&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 12:44:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/show-applied-dap-policies-in-ftd/m-p/5243043#M1118555</guid>
      <dc:creator>carl_townshend</dc:creator>
      <dc:date>2025-01-03T12:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: Show applied dap policies in FTD</title>
      <link>https://community.cisco.com/t5/network-security/show-applied-dap-policies-in-ftd/m-p/5243049#M1118556</link>
      <description>&lt;P&gt;&lt;CODE class="cCN_CmdName"&gt;&lt;STRONG&gt; debug dap trace &amp;lt;&amp;lt;- use this debug to check if Server send DAP or not and what is name of DAP&amp;nbsp;&lt;/STRONG&gt;&lt;/CODE&gt;&lt;/P&gt;
&lt;P&gt;&lt;CODE class="cCN_CmdName"&gt;&lt;STRONG&gt;MHM&lt;/STRONG&gt;&lt;/CODE&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 12:56:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/show-applied-dap-policies-in-ftd/m-p/5243049#M1118556</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-01-03T12:56:40Z</dc:date>
    </item>
    <item>
      <title>Re: Show applied dap policies in FTD</title>
      <link>https://community.cisco.com/t5/network-security/show-applied-dap-policies-in-ftd/m-p/5243054#M1118557</link>
      <description>&lt;P&gt;I believe you can only get these via a DART file (from the client) or from a debug (on FTD headend). The LINA engine in FTD handles DAP pretty much the same as an ASA does, so the following article (old but mostly relevant) may help:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/security-knowledge-base/information-to-acquire-for-dap-troubleshooting/ta-p/3145426" target="_blank" rel="noopener"&gt;https://community.cisco.com/t5/security-knowledge-base/information-to-acquire-for-dap-troubleshooting/ta-p/3145426&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;The RA VPN dashboard or show command mentioned by &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/97036"&gt;@Rob Ingram&lt;/a&gt; unfortunately do not reveal this info. See sample output from the show command here (see Step 6):&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.defenseorchestrator.com/t_verify-remote-access-vpn-configuration-of-asa.html" target="_blank" rel="noopener"&gt;https://docs.defenseorchestrator.com/t_verify-remote-access-vpn-configuration-of-asa.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jan 2025 13:14:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/show-applied-dap-policies-in-ftd/m-p/5243054#M1118557</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-01-03T13:14:18Z</dc:date>
    </item>
  </channel>
</rss>

