(I had to change the title because the name of the bug is too long.) This bug has been reported since June. I notice the status is "unrepeatable". That is certainly not our experience. When we updated only the hostscan module the bug immediately appeared. It happens only when an upgrade is attempted—either of AnyConnect or hostscan. It does not happen on our old 5508-x. A workaround would be to have our users upgrade using the 5508 and keep the old modules on the ASAv. However, I just discovered some other anomalous behavior. I'm running AnyConnect 5.1.6.103 on a Mac on Sequoia 15.1 . The 5508 is running hostscan 5.1.6.108. If I attempt to connect to the ASAv, which is running 9.20.3 with hostscan 5.1.3.62, the posture assessment fails:
DAP_TRACE: endpoint.pfw["100022"].description = "Mac OS X Builtin Firewall (Mac)"
DAP_TRACE: endpoint.pfw["100022"].version = "15.1"
DAP_TRACE: endpoint.pfw["100022"].enabled = "failed"
The same check on the 5508 passes.
I'm not sure if upgrading the hostscan on the ASAv will fix it, but I am unable to test it without exposing our users to the original bug.