<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Dynamic Access Policy (DAP) relationship with Self-signed Certific in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5300386#M1121359</link>
    <description>&lt;P&gt;Good morning, MHM,&lt;BR /&gt;"How is the self-signed certificate deployed on each VPN client tied to the DAP configuration?"&amp;nbsp;&amp;nbsp; We only picked two criteria in the DAP config at this time and did not use certificate criteria in the AAA of the record we created.&amp;nbsp; I just want to get a deeper understanding why enabling the DAP in the working RAVPN policy affect the behavior of the VPN connection, specifically, when the certificate criteria is not even being used.&amp;nbsp;&amp;nbsp; If we un-assigned the DAP policy to the RAVPN policy, it works.&amp;nbsp; Thank you very much again for your guidance.&amp;nbsp; AR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 18 Jun 2025 13:56:59 GMT</pubDate>
    <dc:creator>ArielAR</dc:creator>
    <dc:date>2025-06-18T13:56:59Z</dc:date>
    <item>
      <title>Dynamic Access Policy (DAP) relationship with Self-signed Certificates</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5300206#M1121352</link>
      <description>&lt;P&gt;Currently, we have one of our NGFW configured for VPN use and able to connect to it successfully.&amp;nbsp; We are exploring the use of DAP for added control in who can connect to our VPN, so, we had configured some basic settings.&amp;nbsp; If we don't have it assigned and turned on for the existing working Remote Access VPN policy, all is well.&amp;nbsp; However, as soon as we assign/turn it on, when connecting via the VPN client, we get a message about the certificate that says... "untrusted server connection" in a red background (as far as what was initially described).&amp;nbsp; The self-signed cert is installed on the client side.&amp;nbsp; I am about to be part of the test group as well and will find out the exact error window that pops out.&amp;nbsp;&amp;nbsp; With the above scenario, my initial question is that, what causes this to happen if we are actually not even using the certificate as a criteria in our DAP records?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Jun 2025 23:07:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5300206#M1121352</guid>
      <dc:creator>ArielAR</dc:creator>
      <dc:date>2025-06-17T23:07:09Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Access Policy (DAP) relationship with Self-signed Certific</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5300331#M1121357</link>
      <description>&lt;P&gt;I dont fully understand get your Q&lt;/P&gt;
&lt;P&gt;Can you more elaborate&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 11:32:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5300331#M1121357</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-06-18T11:32:58Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Access Policy (DAP) relationship with Self-signed Certific</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5300386#M1121359</link>
      <description>&lt;P&gt;Good morning, MHM,&lt;BR /&gt;"How is the self-signed certificate deployed on each VPN client tied to the DAP configuration?"&amp;nbsp;&amp;nbsp; We only picked two criteria in the DAP config at this time and did not use certificate criteria in the AAA of the record we created.&amp;nbsp; I just want to get a deeper understanding why enabling the DAP in the working RAVPN policy affect the behavior of the VPN connection, specifically, when the certificate criteria is not even being used.&amp;nbsp;&amp;nbsp; If we un-assigned the DAP policy to the RAVPN policy, it works.&amp;nbsp; Thank you very much again for your guidance.&amp;nbsp; AR&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 13:56:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5300386#M1121359</guid>
      <dc:creator>ArielAR</dc:creator>
      <dc:date>2025-06-18T13:56:59Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Access Policy (DAP) relationship with Self-signed Certific</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5300538#M1121370</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/cluster/ftd_dap_usecases.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/secure-firewall/management-center/cluster/ftd_dap_usecases.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;There are many match conditions for DAP' do you use AAA ?&lt;/P&gt;
&lt;P&gt;Check link to see how we can match conditions of AAA attributes&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Wed, 18 Jun 2025 20:08:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5300538#M1121370</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-06-18T20:08:26Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Access Policy (DAP) relationship with Self-signed Certific</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5300548#M1121371</link>
      <description>Hi, MHM,&lt;BR /&gt;Thank you for your email.&lt;BR /&gt;Here is the confirmed details of our environment.&lt;BR /&gt;We are currently using a valid self-signed certificate which is also installed in each of the VPN client system - it does not expire until 2031.&lt;BR /&gt;With DAP unassigned, our Remote Access VPN policy works good, and client experience is as expected - can connect with no extra steps to do.&lt;BR /&gt;With DAP assigned to the Remote Access VPN, when launching the VPN client, it first presents a message about the certificate being untrusted. Clicking "Connect" any allows us to proceed with the connection.&lt;BR /&gt;We are wondering why this is still being presented as such, when the self-signed certificate is still valid? Would a new certificate need to be recreated after the DAP is configured and have it redeployed to the client to get rid of the certificate message despite the current still being active?&lt;BR /&gt;We are trying to see if we can set it so it will not present such message, specially if the cert is still good.&lt;BR /&gt;Thank you in advance.&lt;BR /&gt;&lt;BR /&gt;</description>
      <pubDate>Wed, 18 Jun 2025 21:25:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5300548#M1121371</guid>
      <dc:creator>ArielAR</dc:creator>
      <dc:date>2025-06-18T21:25:12Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Access Policy (DAP) relationship with Self-signed Certific</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5301896#M1121427</link>
      <description>&lt;P&gt;Sorry for late reply' you use only cert. For auth anyconnect?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 08:46:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5301896#M1121427</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-06-24T08:46:36Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Access Policy (DAP) relationship with Self-signed Certific</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5302003#M1121432</link>
      <description>&lt;P&gt;Actually, we do have a self-signed certificate created under Objects &amp;gt; PKI &amp;gt; Certificate Enrollment - it is deployed client system.&amp;nbsp; Without DAP enable, the VPN connection goes smooth and presents just the normal dialog boxes associated to the connection - and successfully connects.&amp;nbsp;&amp;nbsp; With DAP enable, regardless if there is only one endpoint criteria used (e.g. terminate connection if not running Windows 11), an extra dialog box associated to connecting to an untrusted server displays. If we select "Connect Anyway", it does a successful connection.&amp;nbsp;&amp;nbsp; Just want to understand how the DAP is associated to the enrolled certificate as mentioned previously.&amp;nbsp;&amp;nbsp; To re-iterate, we are also current not using the certificate as a criteria of the endpoint.&amp;nbsp;&amp;nbsp;&amp;nbsp; In addition, to add a bit more, during our investigation, we found that using the endpoint criteria seems to be a hit and miss, and that it also seems that it does not like to have more than one criteria in one record.&amp;nbsp; Right now, it is not making sense to me why...&lt;BR /&gt;Thanks so much again for your thoughts on this.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 13:14:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5302003#M1121432</guid>
      <dc:creator>ArielAR</dc:creator>
      <dc:date>2025-06-24T13:14:19Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Access Policy (DAP) relationship with Self-signed Certific</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5302023#M1121433</link>
      <description>&lt;P&gt;Is the certificate of your FTD headend also self-signed? I suspect when you use DAP there is an additional communication via client services that invokes the certificate via a separate "channel" than the usual login. I've always used CA-signed certificates with remote access VPN and in those cases DAP does not present any certificate errors.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 13:53:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5302023#M1121433</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-06-24T13:53:56Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Access Policy (DAP) relationship with Self-signed Certific</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5302026#M1121434</link>
      <description>&lt;P&gt;Good morning, Marvin...Thank you so very much for your response. So far, that is the only certificate we are using for the FTD and is self-signed.&amp;nbsp; If we would like to keep it as such (self-signed) did you happen to stumble on a possible work around it so that it will behave like how if the cert as created from a CA?&amp;nbsp;&amp;nbsp; Just wondering if there is a way to find that possible "channel"&amp;nbsp; and turn it off from there, per se :-).&amp;nbsp;&amp;nbsp; Thanks so very much again - a cup of hot coffee for you and MHM.&amp;nbsp; &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 14:01:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5302026#M1121434</guid>
      <dc:creator>ArielAR</dc:creator>
      <dc:date>2025-06-24T14:01:09Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Access Policy (DAP) relationship with Self-signed Certific</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5302062#M1121435</link>
      <description>&lt;P&gt;Sorry but a self-signed certificate will often present itself in undesirable ways. Why is there a desire to avoid using a proper certificate issued from either an internal or public CA?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jun 2025 15:42:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5302062#M1121435</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2025-06-24T15:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Access Policy (DAP) relationship with Self-signed Certific</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5302070#M1121436</link>
      <description>Hi, Marvin,&lt;BR /&gt;Thank you for your response. Not actually a desire to avoid using CA cert but more on if we can get it working and have the VPN client recognize the self-signed certificate.&lt;BR /&gt;</description>
      <pubDate>Tue, 24 Jun 2025 16:02:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5302070#M1121436</guid>
      <dc:creator>ArielAR</dc:creator>
      <dc:date>2025-06-24T16:02:12Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic Access Policy (DAP) relationship with Self-signed Certific</title>
      <link>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5306186#M1121640</link>
      <description>&lt;P&gt;Sorry for late reply&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Server - client&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Client use self signed certification of server to authc server&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But server I think dont use self signed certification&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is Key&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What server use to authc client '&lt;/P&gt;
&lt;P&gt;I dont get clear reply&amp;nbsp;&lt;/P&gt;
&lt;P&gt;MHM&lt;/P&gt;</description>
      <pubDate>Sun, 06 Jul 2025 16:42:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/dynamic-access-policy-dap-relationship-with-self-signed/m-p/5306186#M1121640</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2025-07-06T16:42:23Z</dc:date>
    </item>
  </channel>
</rss>

