02-13-2013 04:09 AM
Hi All,
As the tittle suggests, I need a way to block MAC OS X users connecting remotely to our coporate users over VPN. I know there is an option to block connections based on VPN client Version, but cant find a way to block users based on operating system.
We use Cisco ASA 5510 firewals one with v8.2(1) and other with v7.2(3). I need to do on both firewalls. They are both at diffrent sites.
Help would be greatly appreciated
Thanks,
Sam
Solved! Go to Solution.
02-13-2013 04:27 AM
You can match on the Operating System in the Dynamic Access Policies. But there are some restrictions. You need the HostScan-License which only works with the AnyConnect Premium license. And if I remember right, the DAPs were introduced in ASA v8, so the older ASA has to be updated (an update would be a good idea anyway).
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
02-13-2013 04:27 AM
You can match on the Operating System in the Dynamic Access Policies. But there are some restrictions. You need the HostScan-License which only works with the AnyConnect Premium license. And if I remember right, the DAPs were introduced in ASA v8, so the older ASA has to be updated (an update would be a good idea anyway).
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
02-13-2013 04:35 AM
Thanks Karsten for reply.
We dont not use AnyConnect. We currently have Remote IPsec connection and have a Security Plus license. Does that cover the HostScan License?
If not are there any other solutions maybe ACL based etc.?
Thanks
Sam
02-13-2013 04:46 AM
The hostscan needs AnyConnect, so there is nothing for the IPSec-Client. Also the ACL is not aware of the OS, so that won't work.
Perhaps you can match on the Client-Version >= v5. The MAC-client is only available in version 4.9.
--
Don't stop after you've improved your network! Improve the world by lending money to the working poor:
http://www.kiva.org/invitedby/karsteni
02-13-2013 04:49 AM
Cool, thanks for your help
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide