cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
147
Views
0
Helpful
2
Replies

Anyconnect (Secureclient) 5.x issues with posture - No attributes sent

Rodrigo Gurriti
Level 3
Level 3

Hi, 

Has anyone had issues where you are running FTD with AnyConnect (secureclient) with Posture (DAP) enabled and some computers are sending the attribute endpoint.am=xxx and others aren't? 

I have several devices not sending the anti-malware attribute and failing the posture on the RA-VPN. 

 

2 Replies 2

BlakeBratu
Cisco Employee
Cisco Employee

What anti-malware are you using? Is the version number at parity between the working and non-working devices?

 

 I have a DAP policy looking for MS Defender, MS Defender ATP,  SentinelOne, Cisco AMP, Cortex, VMware Carbon Black, and others. 

They are all listed here https://www.cisco.com/c/en/us/td/docs/security/vpn_client/anyconnect/secure-firewall-posture/support/charts/Secure_Firewall_Posture_Support_Charts_Version_5_1_2_42.html

As I have said, the DAP log on the firewall does not show any endpoint.am attribute which is quite odd.