07-22-2020 07:53 AM
Hi,
I have a Firepower in ASA mode (9.14) for anyconnect VPN and cisco ISE for posture (Apex license).
I am trying to find if there is an option to force the VPN session to disconnect if the posture is not compliant.
For the moment when the PC is not compliant there is just the DACL pushed by the ISE to the firewall that prevents access to the network, but now I need to just disconnect the VPN if it's not compliant.
Does this feature exist, and how do I configure it ?
Best regards
Solved! Go to Solution.
08-07-2020 06:48 AM - edited 08-07-2020 06:48 AM
Hi,
I tried the access-reject option, but this triggers an error on the anyconnect side, something like unknown interruption error : general error.
I've also contacted TAC for this and they responded that it is impossible to disconnect the tunnel if the posture is not compliant.
This is a strange "feature" but it is what it is.
Best regards
07-22-2020 01:06 PM
07-23-2020 01:49 AM
Hi,
We check for specific running process on corporate computers. If the process is not running it means that the client corporate computer is not configured properly or have a big problem (they would have to call the IT support and maybe bring their PC for checking etc...)
Why does it matter : there is no point that they stays connected to the tunnel with a deny ACL that allows access to nothing.
Best regards
07-23-2020 04:42 AM
08-07-2020 06:48 AM - edited 08-07-2020 06:48 AM
Hi,
I tried the access-reject option, but this triggers an error on the anyconnect side, something like unknown interruption error : general error.
I've also contacted TAC for this and they responded that it is impossible to disconnect the tunnel if the posture is not compliant.
This is a strange "feature" but it is what it is.
Best regards
08-07-2020 10:05 AM
08-12-2020 01:48 AM
Hi,
The Session-Timeout is not taken into account by the ASA, I don't see the max session value changed after receiving the COA.
The DACL is received on the other hand.
I'll try to push a whole group-policy with a short max session timeout.
Best regards
08-12-2020 08:08 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide