65-6
Cisco ASA 5500 Series Configuration Guide using ASDM
OL-20339-01
Chapter 65 Configuring Dynamic Access Policies
Understanding VPN Access Policies
Endpoint Attribute Definitions
Table 65-3 defines the endpoint selection attribute names that are available for DAP use.The Attribute
Name field shows you how to enter each attribute name in a Lua logical expression, which you might do
in the Advanced area in the Add/Edit Dynamic Access Policy pane. The label variable identifies the
application, filename, process, or registry entry.
Table 65-3 Endpoint Attribute Definitions
Attribute Type Attribute Name Source Value
Max
String
Length Description
Antispyware
(Requires
Cisco Secure
Desktop)
endpoint.as["label"].exists Host Scan true — Antispyware program exists
endpoint.as["label"].version string 32 Version
endpoint.as["label"].description string 128 Antispyware description
endpoint.as["label"].lastupdate integer — Seconds since update of antispyware
definitions
Antivirus
(Requires
Cisco Secure
Desktop)
endpoint.av["label"].exists Host Scan true — Antivirus program exists
endpoint.av["label"].version string 32 Version
endpoint.av["label"].description string 128 Antivirus description
endpoint.av["label"].lastupdate integer — Seconds since update of antivirus
definitions
Application endpoint.application.clienttype Application string — Client type:
CLIENTLESS
ANYCONNECT
IPSEC
L2TP
File endpoint.file["label"].exists Secure
Desktop
true — The files exists
endpoint.file["label"].lastmodifi
ed
integer — Seconds since file was last modified
endpoint.file["label"].crc.32 integer — CRC32 hash of the file
NAC endpoint.nac.status NAC string — User defined status string
Operating
System
endpoint.os.version Secure
Desktop
string 32 Operating system
endpoint.os.servicepack integer — Service pack for Windows
Personal
firewall
(Requires
Secure
Desktop)
endpoint.fw["label"].exists Host Scan true — The personal firewall exists
endpoint.fw["label"].version string 32 Version
endpoint.fw["label"].description string 128 Personal firewall description
Policy endpoint.policy.location Secure
Desktop
string 64 Location value from Cisco Secure
Desktop
Process endpoint.process["label"].exists Secure
Desktop
true — The process exists
endpoint.process["label"].path string 255 Full path of the process