cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
746
Views
0
Helpful
3
Replies

Cisco FTD VPN and compliance rules

eduardo0407
Level 1
Level 1

Hello, I have a question regarding Cisco FTD and client VPN with AnyConnect.

Is it possible to configure compliance rules for FTD VPN Clients and quarantine a host if it is not compliant?

Thanks in advance.

Regards.

3 Replies 3

Dennis Perto
Level 5
Level 5

Hi eduardo0407

I have not tried this yet, but I have some thoughts that I would like to share.

I don't see a way to quarantine a host from the FMC it self. You would need to use Cisco ISE to handle this part.

  1. Make a compliance rule for the network range of your VPN Clients with the Operating Systems, protocols and applications allowed.
  2. Make a correlation rule, triggering a Quarantine event for the user in ISE.

A search on the web gave me this, to help you with the ISE quarantine part.

https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/119370-configure-ise-00.pdf

Thanks for the reply.

I'm aware of the possibility to use ISE to change an endpoint to a quarantine zone and use this inside an FTD access rule.

I was just wondering if there is anything close to a VPN compliance rule inside FMC/FTD without ISE.

Not to my knowledge.

You will need to disable the access for the user, and not the IP address, or else your RA VPN scope would run dry at some point.

Review Cisco Networking products for a $25 gift card