AnyConnect Basic Host Scan

- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-06-2019 08:50 AM - edited 02-21-2020 09:35 PM
Hello,
I would like to configure basic hostscan to prevent from connecting VPN if some file doesnt exist on the endpoint or some proccess is not running on the endpoint.
I made some hostscan rules but it doesn't work - VPN connects every time.
Do I have to make some connection between my VPN configuration and hostscan configuration?
Hostscan documentation doesn't tell how to configure it.
- Labels:
-
AnyConnect
-
Remote Access
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-07-2019 02:55 AM
Under your webvpn section you need to have "csd enable" to associate your hostscan setup with the SSL VPN.
https://community.cisco.com/t5/security-documents/how-to-configure-anyconnect-host-scan/ta-p/3118732
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-07-2019 05:30 AM
Cisco Adaptive Security Appliance Software Version 9.10(1)11
hostscan package version 4.7
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-08-2019 12:41 AM
OK, so do you have the newer "hostscan enable" under your webvpn section?
If you do and it is not working, you can use _debug dap trace " (at ASA end) and DART package (at client side) to gather more details. TAC can assist for specific questions if you want to open a case and share those outputs with them.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
03-07-2019 05:33 AM
