<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Preventing mac osx users from using cisco vpn in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838201#M459828</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Mvsheik123....thank you! That worked beautifully. I was able to block Mac OS X users by defining a policy and allow everyone else in. Perfect!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now is there a way to also get an email alert?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 09 Feb 2012 17:05:47 GMT</pubDate>
    <dc:creator>howithink</dc:creator>
    <dc:date>2012-02-09T17:05:47Z</dc:date>
    <item>
      <title>Preventing mac osx users from using cisco vpn</title>
      <link>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838193#M459805</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have setup ASA to act as our vpn server with radius as my authentication server. Users use the cisco vpn client utility to vpn in which has the .pcf file. This .pcf file has the group password, name and so on. Some users went online and found websites to decrypt the group password and have used that on their local macs to vpn in. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That irritates me and i want to know how i can prevent them from logging on. Are there any ways to block by os type within ASA?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please help!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 22:26:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838193#M459805</guid>
      <dc:creator>howithink</dc:creator>
      <dc:date>2019-03-11T22:26:14Z</dc:date>
    </item>
    <item>
      <title>Preventing mac osx users from using cisco vpn</title>
      <link>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838194#M459809</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So you want to block the remote users vpn connections by the OS, witch kind of vpn is this: SSL vpn or IPSEC remote access vpn?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Feb 2012 23:23:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838194#M459809</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-08T23:23:45Z</dc:date>
    </item>
    <item>
      <title>Preventing mac osx users from using cisco vpn</title>
      <link>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838195#M459811</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; We use ipsec remote access vpn&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Feb 2012 23:25:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838195#M459811</guid>
      <dc:creator>howithink</dc:creator>
      <dc:date>2012-02-08T23:25:00Z</dc:date>
    </item>
    <item>
      <title>Preventing mac osx users from using cisco vpn</title>
      <link>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838196#M459814</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately it is not going to work as you will need to use the CSD ( Cisco Secure Desktop) witch will make a host scan and that will work on anyconnect setup not on IPsec remote access configurations.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Julio&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do rate all the helpful posts!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Feb 2012 23:36:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838196#M459814</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-08T23:36:04Z</dc:date>
    </item>
    <item>
      <title>Preventing mac osx users from using cisco vpn</title>
      <link>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838197#M459817</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Thank you for that response. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With that said is there a way to have at leaset an email alert sent to me by my ASA that states they type of client OS. I know there is a syslog id message which shows you the client type: osx mac or wint nt and so on. Is that email possible?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Feb 2012 23:49:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838197#M459817</guid>
      <dc:creator>howithink</dc:creator>
      <dc:date>2012-02-08T23:49:08Z</dc:date>
    </item>
    <item>
      <title>Preventing mac osx users from using cisco vpn</title>
      <link>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838198#M459821</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;That is correct, you can send a syslog list or message via emai, in order to accomplish that do the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE&gt;&lt;STRONG&gt;Logging list test &lt;/STRONG&gt;&lt;STRONG&gt; message x.x.x.x( syslog message for the O.S) &lt;BR /&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;PRE&gt;&lt;STRONG&gt;logging mail &lt;/STRONG&gt;&lt;STRONG&gt;test&lt;/STRONG&gt;
&lt;PRE&gt;&lt;STRONG&gt;logging recipient-address&lt;/STRONG&gt; email_address

&lt;STRONG&gt;logging from-address&lt;/STRONG&gt; email_address

&lt;STRONG&gt;smtp-server&lt;/STRONG&gt; ip_address&lt;BR /&gt;&lt;BR /&gt;That shoud make it work!!&lt;BR /&gt;&lt;BR /&gt;Regards,&lt;BR /&gt;&lt;BR /&gt;Julio&lt;BR /&gt;&lt;BR /&gt;Do rate all the helpful posts&lt;/PRE&gt;
&lt;BR /&gt;&lt;/PRE&gt;
&lt;BR /&gt;&lt;BR /&gt;&lt;/PRE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 08 Feb 2012 23:56:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838198#M459821</guid>
      <dc:creator>Julio Carvajal</dc:creator>
      <dc:date>2012-02-08T23:56:25Z</dc:date>
    </item>
    <item>
      <title>Preventing mac osx users from using cisco vpn</title>
      <link>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838199#M459824</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; thanks i set it up to get 2 syslog messages: 713120 and 713904.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;lt;165&amp;gt;Feb 09 2012 06:48:56: %ASA-5-713120: Group = vpnaccess-xyz123, Username = xyzcompany\jdoe, IP = 10.10.10.10, PHASE 2 COMPLETED (msgid=xxxxxx).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which is good, now i know who is connected to my vpn and i get an alert, but i also want to know they type of OS they are using. When i do a lookup of syslog message id: 713904, that is suppose to give me the OS type (ex: winnt mac ox and so on), but i am not getting that.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any reason why i dont get an alert from message id 713904, but i get one from 713120.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 14:53:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838199#M459824</guid>
      <dc:creator>howithink</dc:creator>
      <dc:date>2012-02-09T14:53:04Z</dc:date>
    </item>
    <item>
      <title>Preventing mac osx users from using cisco vpn</title>
      <link>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838200#M459826</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I never tried this but the 'client-access-rules' command under group policy might work for you to restrict the MAC client by setting up deny /permit OS type. Check the below discussion...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A _jive_internal="true" href="https://community.cisco.com/message/3533229#3533229"&gt;https://supportforums.cisco.com/message/3533229#3533229&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;hth&lt;/P&gt;&lt;P&gt;MS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 16:10:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838200#M459826</guid>
      <dc:creator>mvsheik123</dc:creator>
      <dc:date>2012-02-09T16:10:46Z</dc:date>
    </item>
    <item>
      <title>Preventing mac osx users from using cisco vpn</title>
      <link>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838201#M459828</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt; Mvsheik123....thank you! That worked beautifully. I was able to block Mac OS X users by defining a policy and allow everyone else in. Perfect!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Now is there a way to also get an email alert?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 17:05:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838201#M459828</guid>
      <dc:creator>howithink</dc:creator>
      <dc:date>2012-02-09T17:05:47Z</dc:date>
    </item>
    <item>
      <title>Re: Preventing mac osx users from using cisco vpn</title>
      <link>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838202#M459831</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Glad to hear that. Now, are you looking to receive an email when the mac users access denied? If so - as long as the deny message is in ASA logs ( you may need to test by enablling different logging methods for exact message ID), please follow config provided by Julio.it should work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thx&lt;/P&gt;&lt;P&gt;MS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Feb 2012 17:17:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/preventing-mac-osx-users-from-using-cisco-vpn/m-p/1838202#M459831</guid>
      <dc:creator>mvsheik123</dc:creator>
      <dc:date>2012-02-09T17:17:06Z</dc:date>
    </item>
  </channel>
</rss>

