03-30-2017 10:19 AM - edited 02-21-2020 09:13 PM
I have a customer who wants to provision a policy so that only domain joined computers (e.g. company owned laptops) can attach to VPN. We've talked about using certificates, but they don't want the added complexity, and they're also nervous about tech savvy employees exporting the local host's cert and importing it onto another computer in order to get around the restriction.
I'm wondering if it's possible to have the ASA pass a RADIUS attribute that includes the computer's OU through the firewall and add a policy in Microsoft NPS that will only send a radius-accept message if the user both authenticates/is in a certain group, and the computer's OU (not the user's) matches a certain group. This would in effect allow only domain-joined computers to log into VPN.
If not, I'm curious if there are other ideas on how to accomplish? We could use ISE/ AC ISE Posture Module, but they don't have those currently. Purchase and deployment of those products is not off the table, but we'd like to work with what we have if it's possible.
Solved! Go to Solution.
03-30-2017 10:43 AM
Hello Phillip Simonds,
You can use DAP to detect domain computer based on the registry setting. Here is a sample doc
https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/115947-dap-adv-functions-00.pdf
You should look for "Enforce DAP Based on CSD Host Scan for Domain Registry
Thanks
Shakti
03-30-2017 10:43 AM
Hello Phillip Simonds,
You can use DAP to detect domain computer based on the registry setting. Here is a sample doc
https://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/115947-dap-adv-functions-00.pdf
You should look for "Enforce DAP Based on CSD Host Scan for Domain Registry
Thanks
Shakti
03-30-2017 10:54 AM
Shakti, thanks for the info.
This looks like it requires CSD to scan the host for that domain registry key. I believe CSD is EoS/EoL and replaced by ISE Posture Assessment - but I could be wrong - starting to get out of my depth in this product line.
If I'm incorrect on that point, is CSD automatically pushed down with the AnyConnect client? And is any additional licensing required to have it scan the host for a registry key? The customer is using PLUS licensing for the AnyConnect client.
Thanks in advance.
04-02-2017 08:55 PM
Hi Phillip Simonds,
Posture assessment isn't EOL feature, only the pre-login component of posture assessment is
Thanks
Shakti
04-03-2017 10:25 AM
Thanks Shakti! I really appreciate it.
04-13-2017 07:16 AM
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide