<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD 6.3 Posture support in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-6-3-posture-support/m-p/3853664#M925499</link>
    <description>&lt;P&gt;When doing posture, the assessment is done between the client and ise over anyconnect.&lt;BR /&gt;Between ftd and ise, you need coa, communication with ise and url redirect. The first 2 I'm sure these are working fine but for the last one (url redirect), not tested yet and not sure if that works.&lt;BR /&gt;Maybe &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/34902"&gt;@marvin&lt;/a&gt; has tested this last capability.&lt;/P&gt;</description>
    <pubDate>Fri, 10 May 2019 02:55:47 GMT</pubDate>
    <dc:creator>Francesco Molino</dc:creator>
    <dc:date>2019-05-10T02:55:47Z</dc:date>
    <item>
      <title>FTD 6.3 Posture support</title>
      <link>https://community.cisco.com/t5/network-security/ftd-6-3-posture-support/m-p/3851209#M925495</link>
      <description>&lt;P&gt;Hi Community,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cisco released note for FTD 6.3 has not officially included posture in this version, would this create an issue with future support assuming we successfully implement posture?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:06:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-6-3-posture-support/m-p/3851209#M925495</guid>
      <dc:creator>dfinibg6</dc:creator>
      <dc:date>2020-02-21T17:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 6.3 Posture support</title>
      <link>https://community.cisco.com/t5/network-security/ftd-6-3-posture-support/m-p/3851239#M925496</link>
      <description>Hi&lt;BR /&gt;&lt;BR /&gt;Even if it's not supported, this doesn't mean it can't work. Like you said you have it working.&lt;BR /&gt;If you have any issues, you won't get any support and in a production environment it could be a big issue.&lt;BR /&gt;&lt;BR /&gt;Now, we don't know when this feature will be there (even in 6.4 i believe it's not supported). If Cisco implement this feature in a different way it works in asa today, you'll probably have your actual config failing and you'll impact all users but again, this is an assumption. You're kind of gambling by deploying this feature without any support and if you make this call you are aware that potentially you can face some impacting issues.</description>
      <pubDate>Tue, 07 May 2019 04:33:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-6-3-posture-support/m-p/3851239#M925496</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2019-05-07T04:33:43Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 6.3 Posture support</title>
      <link>https://community.cisco.com/t5/network-security/ftd-6-3-posture-support/m-p/3851356#M925497</link>
      <description>&lt;P&gt;The RADIUS + Change of Authorization (CoA) feature support in FTD 6.4 includes using ISE (as a RADIUS server) to assess posture and then send a CoA to FTD as a result of the posture assessment.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;See&amp;nbsp;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/113005"&gt;@hslai&lt;/a&gt;&amp;nbsp;'s posting here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.cisco.com/t5/firepower/ftd-remote-access-vpn-with-ise-posture/m-p/3848834" target="_blank"&gt;https://community.cisco.com/t5/firepower/ftd-remote-access-vpn-with-ise-posture/m-p/3848834&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 07 May 2019 08:46:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-6-3-posture-support/m-p/3851356#M925497</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-05-07T08:46:22Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 6.3 Posture support</title>
      <link>https://community.cisco.com/t5/network-security/ftd-6-3-posture-support/m-p/3853643#M925498</link>
      <description>&lt;P&gt;Hi Marvin,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is that also true for the support for AnyConnect ISE posture in Firepower 6.4? The release notes for 6.3 and 6.4 doesn't state this explicitly, and the config guides for 6.3 and 6.4 are identical on support for ise posture&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/firepower_threat_defense_remote_access_vpns.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/firepower_threat_defense_remote_access_vpns.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/firepower_threat_defense_remote_access_vpns.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/640/configuration/guide/fpmc-config-guide-v64/firepower_threat_defense_remote_access_vpns.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H3&gt;Unsupported Features of AnyConnect&lt;/H3&gt;&lt;P class="p"&gt;The only supported VPN client is the Cisco AnyConnect Secure Mobility Client. No other clients or native VPNs are supported. Clientless VPN is not supported for VPN connectivity; it is only used to deploy the AnyConnect client using a web browser.&lt;/P&gt;&lt;P class="p"&gt;The following AnyConnect features are not supported when connecting to an&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph"&gt;FTD&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;secure gateway:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;Secure Mobility, Network Access Management, and all other AnyConnect modules and their profiles beyond the core VPN capabilities and the VPN client profile.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Posture variants such as&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="ph"&gt;Hostscan and Endpoint Posture Assessment&lt;/SPAN&gt;&lt;SPAN&gt;, and any Dynamic Access Policies based on the client posture.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Regards,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rick.&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 02:14:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-6-3-posture-support/m-p/3853643#M925498</guid>
      <dc:creator>rick505d3</dc:creator>
      <dc:date>2019-05-10T02:14:39Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 6.3 Posture support</title>
      <link>https://community.cisco.com/t5/network-security/ftd-6-3-posture-support/m-p/3853664#M925499</link>
      <description>&lt;P&gt;When doing posture, the assessment is done between the client and ise over anyconnect.&lt;BR /&gt;Between ftd and ise, you need coa, communication with ise and url redirect. The first 2 I'm sure these are working fine but for the last one (url redirect), not tested yet and not sure if that works.&lt;BR /&gt;Maybe &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/34902"&gt;@marvin&lt;/a&gt; has tested this last capability.&lt;/P&gt;</description>
      <pubDate>Fri, 10 May 2019 02:55:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-6-3-posture-support/m-p/3853664#M925499</guid>
      <dc:creator>Francesco Molino</dc:creator>
      <dc:date>2019-05-10T02:55:47Z</dc:date>
    </item>
    <item>
      <title>Re: FTD 6.3 Posture support</title>
      <link>https://community.cisco.com/t5/network-security/ftd-6-3-posture-support/m-p/4188065#M1076082</link>
      <description>&lt;P&gt;Can the &lt;EM&gt;PostureRedirectSGT&lt;/EM&gt; be replaced to a final SGT by means of CoA ?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Nov 2020 13:34:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-6-3-posture-support/m-p/4188065#M1076082</guid>
      <dc:creator>Peter Koltl</dc:creator>
      <dc:date>2020-11-24T13:34:13Z</dc:date>
    </item>
  </channel>
</rss>

