Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
New to Anyconnect DAP.Got some existing setup with dozen of Tunnel groups and dozen of DAP policy configured.Scratching my head , how DAP policies are mapped to tunnel groups?How does tunnel group know, which policy to call for applying policies?Is t...
Hi, I am unable to understand Point 3. Seems like its missing some clarity. Can someone expand on step 3 please?Does NAD send Radius Challenge to Endpoint and then NAD forward it to PSN through RADIUS protocol? Is that what point 3 trying to say ? or...
Hi All,We do static endpoint assignment to Identity groups in ISE. But even if endpoint is active the assignment changes to a different identity group after few hours or days.Any idea how to troubleshoot such situation to narrow down the issue?
Hi All,Pretty new to DAP in Anyconnect.2 Basic questions.1- I inherited few firewalls. Which has DAP policy name in running config. But reading documentation. It seems DAP.XML should be in flash: . What is the difference between DAP Profile in Runn...
Hi Team.I have a host on LAN that is trying to build IPSEC VPN with remote site.I am using Dynamic PAT for all traffic.I believe it should work.But interestingly, I see all traffic getting NAT but not UDP 500.Any idea why? Ideally i want UDP 500 and ...
No. Using script to manually add macs in identity group.But next day . They are in different group. How can i find reason of this change.Any logs that provide source that triggered change to move to other group?
Issue is resolved after enabling NAT-T on SRXUpdating local identity and remote identity local identity Egress public IP of FTDremote identity public IP of remote peerAlso SRX Egress interface had IKE system service enabled on untrust zone. But then ...