Cisco Cisco AnyConnect Secure Mobility Client v2.x Technical Manual

Page of 16
AnyConnect. This time full network access is provided (DAP policy called FileExists will be
matched).
HostScan module can be installed manually on the endpoint. Example files (hostscan-win-
4.0.00051-pre-deploy-k9.msi) are shared on CCO. But it could be also pushed from ASA.
HostScan is a part of CSD which could be provisioned from ASA. That second approach is used in
this example.
For older versions of AnyConnect (3.1 and before) there was a separate package available on
CCO (example: hostscan_3.1.06073-k9.pkg) which could have been configured and provisioned
on ASA separately (using "csd hostscan image" command) - but that option is not existing
anymore for AnyConnect version 4.0.
Configure
ASA
Step1. Basic SSL VPN configuration
ASA is preconfigured with basic remote VPN access (SSL).
AnyConnect package has been downloaded and used.
Step2.  CSD installation
Subsequent configuration is performed using ASDM. CSD package needs to be downloaded to
flash and referenced from configuration:
Without enabling Secure Desktop it would not be possible to use CSD attributes in DAP policies: