I think I need to give some additiona information.
Since I currently do not use DAP, ezvpn remote and client is allowed to communicate by default DAP record which is DfltAccessPolicy.
After depolying SSL VPN, I would like to use DfltAccessPolicy to block the session. (like an "implicit deny all" in ACL)
I belive usually DfltAccessPolicy is used in this way..
That means I need to create another DAP rule for ezvpn remote and client to prevent being blocked.
My question is what kind of attribute I need to look at to allow ezvpn remote.
Thanks in advance.