Cisco Systems ASA 5585-X Network Router User Manual


  Open as PDF
of 2086
 
70-26
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter 70 Configuring Dynamic Access Policies
Configuring Endpoint Attributes Used in DAPs
Adding a Personal Firewall Endpoint Attribute to a DAP
Prerequisites
Configuring Personal Firewall endpoint attributes as selection criteria for DAP records is part of a
larger process. Read Configuring Dynamic Access Policies, page 70-10 before you configure Personal
Firewall endpoint attributes.
Detailed Steps
Step 1 In the Endpoint Attribute Type list box, select Operating System.
Step 2 Click the appropriate Enabled, Disabled, or Not Installed button to indicate whether the selected
endpoint attribute and its accompanying qualifiers (fields below the Enabled/Disabled/Not Installed
buttons) must be enabled, disabled, or are not installed.
Step 3 From the Vendor ID list box, click the name of the personal firewall vendor you are testing for.
Step 4 Check the Product Description check box and select from the list box the vendor’s product name you
are testing for.
Step 5 Check the Version checkbox and set the operation field to equal to (=), not equal (!=), less than (<),
greater than (>), less that or equal to (<=), or greater than or equal to (>=) the product version number
you select from ther Version list box.
If the choice in the Version list box has an x, such as 3.x, replace the x with a specific release number,
for example, 3.5.
Step 6 Click OK.
Step 7 Return to Configuring Dynamic Access Policies, page 70-10.
Additional References
See Endpoint Attribute Definitions, page 70-29 for additional information on the Personal Firewall
endpoint attribute requirements.
See DAP and AntiVirus, AntiSpyware, and Personal Firewall Programs, page 70-29 for information
on how Host Scan checks for antivirus, antispyware, and personal firewall programs that are
memory-resident.
Adding a Policy Endpoint Attribute to a DAP
Prerequisites
Configuring Policy endpoint attributes as selection criteria for DAP records is part of a larger process.
Read Configuring Dynamic Access Policies, page 70-10 before you configure Policy endpoint attributes.
Guidelines
You can create multiple instances of each type of endpoint attribute. For each of these types, you need
to decide whether the DAP policy should require that the user have all instances of a type (Match all =
AND) or only one of them (Match Any = OR).