70-18
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter70 Configuring Dynamic Access Policies
Configuring Endpoint Attributes Used in DAPs
Configuring Endpoint Attributes Used in DAPs
Endpoint attributes contain information about the endpoint system environment, posture assessment
results, and applications. The ASA dynamically generates a collection of endpoint attributes during
session establishment and stores these attributes in a database associated with the session. There is no
limit for the number of endpoint attributes for each DAP record.
Each DAP record specifies the endpoint selection attributes that must be satisfied for the ASA to select
it. The ASA selects only DAP records that satisfy every condition configured.
For detailed information about Endpoint attributes, see Endpoint Attribute Definitions.
Configuring endpoint attributes as selection criteria for DAP records is part of the larger process of
Configuring Dynamic Access Policies. Read Configuring Dynamic Access Policies, page 70-10 before
you configuring endpoint attributes in DAPs.
This section includes the following topicss:
Adding an Anti-Spyware or Anti-Virus Endpoint Attribute to a DAP, page 70-19
Adding an Application Attribute to a DAP, page 70-20
Adding Mobile Posture Attributes to a DAP, page 70-21
Adding a File Endpoint Attribute to a DAP, page 70-22
Adding a Device Endpoint Attribute to a DAP, page 70-23
Adding a NAC Endpoint Attribute to a DAP, page 70-24
Adding an Operating System Endpoint Attribute to a DAP, page 70-25
Adding a Personal Firewall Endpoint Attribute to a DAP, page 70-26
Adding a Policy Endpoint Attribute to a DAP, page 70-26
Adding a Process Endpoint Attribute to a DAP, page 70-27
Adding a Registry Endpoint Attribute to a DAP, page 70-28
Figure 70-6 shows the Add Endpoint Attributes dialog box.
aaa.cisco.ipaddress AAA number - Assigned IP address for full tunnel VPN
clients (IPsec, L2TP/IPsec, SSL VPN
AnyConnect)
aaa.cisco.tunnelgroup AAA string 64 Connection profile (tunnel group) name
aaa.cisco.username AAA string 64 Name of the authenticated user (applies if
using Local authentication/authorization)
LDAP aaa.ldap.<label> LDAP string 128 LDAP attribute value pair
RADIUS aaa.radius.<number> RADIUS string 128 Radius attribute value pair
See Security Appliance Supported RADIUS Attributes and Values for a table that lists RADIUS attributes that the security
appliance supports.
Table70-2 AAA Selection Attributes for DAP Use (continued)