70-2
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter70 Configuring Dynamic Access Policies
Information About Dynamic Access Policies
DfltAccess Policy—Always the last entry in the DAP summary table, always with a priority of 0.
You can configure Access Policy attributes for the default access policy, but it does not contain—and
you cannot configure—AAA or endpoint attributes. You cannot delete the DfltAccessPolicy, and it
must be the last entry in the summary table.
Refer to the Dynamic Access Deployment Guide (https://supportforums.cisco.com/docs/DOC-1369) for
additional information.
DAP and Endpoint Security
The ASA obtains endpoint security attributes by using posture assessment tools that you configure.
These posture assessment tools include the AnyConnect posture module, the independent Host Scan
package, Cisco Secure Desktop, and NAC.
Table 7 0-1 identifies each of the remote access protocols DAP supports, the posture assessment tools
available for that method, and the information that tool provides.
DAP Support for Remote Access Connection Types
The DAP system supports the following remote access methods:
IPsec VPN
Clientless (browser-based) SSL VPN
Cisco AnyConnect SSL VPN
PIX cut-through proxy (posture assessment not available)
Remote Access Connection Sequence with DAPs
The following sequence outlines a typical remote access connection establishment.
1. A remote client attempts a VPN connection.
2. The ASA performs posture assessment, using configured NAC and Cisco Secure Desktop Host Scan
values.
Table70-1 DAP Posture Assessment
Remote Access Protocol
AnyConnect Posture Module
Host Scan package
Cisco Secure Desktop
(without Endpoint Assessment
Host Scan Extension enabled)
AnyConnect Posture Module
Host Scan package
Cisco Secure Desktop
(with Endpoint Assessment
Host Scan Extension enabled)
NAC
Cisco NAC
Appliance
Returns files information,
registry key values, running
processes, operating system
Returns antivirus,
antispyware, and personal
firewall software information
Returns NAC
status
Returns VLAN
Type and
VLAN IDs
IPsec VPN No No Yes Yes
Cisco AnyConnect VPN Yes Yes Yes Yes
Clientless VPN Yes Yes No No
PIX Cut-through Proxy No No No No