We have a staff VPN that uses hostscan to check the system connecting to the VPN before allowing it to connect. For Macs, we only require that the firewall be turned on. We've had a few users who upgraded to macOS Sierra that are now failing the hostscan. Looking at the logs and DART information, it appears that hostscan is not returning any "endpoint.fw" information like it does with Yosemite (10.10.x) and El Capitan (10.11.x). The users checked and the firewall is enabled so it appears that Hostscan is not finding the firewall in Sierra. Is anyone else seeing this?
We are using v4.2.05015 of AnyConnect and Hostscan.