<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>tema Yes.  en Web Security</title>
    <link>https://community.cisco.com/t5/web-security/transparent-user-id-vs-authenticated-user/m-p/2638494#M5473</link>
    <description>&lt;P&gt;Yes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 12 Aug 2015 19:58:49 GMT</pubDate>
    <dc:creator>Ken Stieers</dc:creator>
    <dc:date>2015-08-12T19:58:49Z</dc:date>
    <item>
      <title>Transparent user ID vs Authenticated user</title>
      <link>https://community.cisco.com/t5/web-security/transparent-user-id-vs-authenticated-user/m-p/2638487#M5466</link>
      <description>&lt;P&gt;Reviewing a setup, and noticed in the later version of code, 8.0 for example, there are two methods for access.&amp;nbsp; Since FF and Safari have issues authenticating access when browsing, and IE does not, would the transparent user ID work the same way for authenticated users, and how would that work with AD?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2015 18:48:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/transparent-user-id-vs-authenticated-user/m-p/2638487#M5466</guid>
      <dc:creator>tahequivoice</dc:creator>
      <dc:date>2015-03-24T18:48:39Z</dc:date>
    </item>
    <item>
      <title>When you have transparent</title>
      <link>https://community.cisco.com/t5/web-security/transparent-user-id-vs-authenticated-user/m-p/2638488#M5467</link>
      <description>&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="font-family:arial,helvetica,sans-serif;"&gt;When you have transparent user ID enable and using AD agent(Context Directory Agent - CDA), this&amp;nbsp;&lt;SPAN style="color: rgb(0, 0, 0); line-height: normal; widows: 1;"&gt;mechanism that maps IP Addresses to usernames in order to allow security gateways to understand which user is using which IP Address in the network, so those security gateways can now make decisions based on those users (or the groups to which the users belong to).&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;SPAN style="color: rgb(0, 0, 0); font-family: Arial, Helvetica, sans-serif; line-height: normal; widows: 1;"&gt;CDA&amp;nbsp;monitors in real time a collection of Active Directory domain controller (DC) machines for authentication-related events that generally indicate user logins; learns, analyzes, and caches mappings of IP Addresses and user identities in its database; and makes the latest mappings available to its consumer devices.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;Scenario example:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;User machine logs in to the domain and CDA agent will catch the user credentials information and map with the IP address of the client and store it in local cache then pass the info to the WSA.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;If the AD server down for example, the CDA will still be able to relay information regarding the users from its local cache to WSA.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;For more information regarding Transparent user identification or CDA, please see below link for overview:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size:14px;"&gt;&lt;A href="http://www.cisco.com/c/en/us/td/docs/security/ibf/cda_10/Install_Config_guide/cda10/cda_oveviw.html"&gt;http://www.cisco.com/c/en/us/td/docs/security/ibf/cda_10/Install_Config_guide/cda10/cda_oveviw.html&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 29 Mar 2015 01:18:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/transparent-user-id-vs-authenticated-user/m-p/2638488#M5467</guid>
      <dc:creator>Handy Putra</dc:creator>
      <dc:date>2015-03-29T01:18:14Z</dc:date>
    </item>
    <item>
      <title>Hello, mates, I have a S170</title>
      <link>https://community.cisco.com/t5/web-security/transparent-user-id-vs-authenticated-user/m-p/2638489#M5468</link>
      <description>&lt;P&gt;Hello, mates,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a S170 WSA with AsyncOS version&amp;nbsp;8.5.1-021. &amp;nbsp;I also have CDA deployed and configured. &amp;nbsp;Authentication tests say everything is good, including connection with CDA. &amp;nbsp;HTTPS decryption is activated as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, my users are still getting authentication prompts everyday and many times inside the same day. &amp;nbsp;It happens randomly and is browser-independent. &amp;nbsp;I changed authentication timeouts from default values of 3600 seconds to 86400 (one day) but it did not solve the issue (please check attached image).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could you please help me find the final solution to this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appreciate,&lt;/P&gt;&lt;P&gt;Mauricio Harley&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jul 2015 08:58:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/transparent-user-id-vs-authenticated-user/m-p/2638489#M5468</guid>
      <dc:creator>mauricioharley</dc:creator>
      <dc:date>2015-07-03T08:58:34Z</dc:date>
    </item>
    <item>
      <title>If CDA is down will the WSA</title>
      <link>https://community.cisco.com/t5/web-security/transparent-user-id-vs-authenticated-user/m-p/2638490#M5469</link>
      <description>&lt;P&gt;If CDA is down will the WSA use the pass thru authentication from the user's browser as a failback authentication mechanism?&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2015 16:39:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/transparent-user-id-vs-authenticated-user/m-p/2638490#M5469</guid>
      <dc:creator>David Niemann</dc:creator>
      <dc:date>2015-07-20T16:39:00Z</dc:date>
    </item>
    <item>
      <title>Yes.</title>
      <link>https://community.cisco.com/t5/web-security/transparent-user-id-vs-authenticated-user/m-p/2638491#M5470</link>
      <description>&lt;P&gt;Yes.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jul 2015 20:22:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/transparent-user-id-vs-authenticated-user/m-p/2638491#M5470</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2015-07-20T20:22:26Z</dc:date>
    </item>
    <item>
      <title>If CDA doesn't have the</title>
      <link>https://community.cisco.com/t5/web-security/transparent-user-id-vs-authenticated-user/m-p/2638492#M5471</link>
      <description>&lt;P&gt;If CDA doesn't have the authentication information will the WSA try to get the creds from the browser?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2015 18:48:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/transparent-user-id-vs-authenticated-user/m-p/2638492#M5471</guid>
      <dc:creator>David Niemann</dc:creator>
      <dc:date>2015-08-12T18:48:54Z</dc:date>
    </item>
    <item>
      <title>You actually configure it to</title>
      <link>https://community.cisco.com/t5/web-security/transparent-user-id-vs-authenticated-user/m-p/2638493#M5472</link>
      <description>&lt;P&gt;You actually configure it to use the CDA agent under Identities.&amp;nbsp; In one of your Identities, you select Identify Users Transparently under Identification and Authentication.&amp;nbsp; This also assumes you have the CDA enabled under Network -&amp;gt; Authentication -&amp;gt; Authentication Realm -&amp;gt;Active Directory Agent.&amp;nbsp; You have to check the box for Enable Transparent User Identification using Active Directory Agent.&amp;nbsp; You need to have the Server defined under Primary Active Directory agent along with the shared secret you created on the CDA system.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2015 19:53:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/transparent-user-id-vs-authenticated-user/m-p/2638493#M5472</guid>
      <dc:creator>David Niemann</dc:creator>
      <dc:date>2015-08-12T19:53:49Z</dc:date>
    </item>
    <item>
      <title>Yes. </title>
      <link>https://community.cisco.com/t5/web-security/transparent-user-id-vs-authenticated-user/m-p/2638494#M5473</link>
      <description>&lt;P&gt;Yes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 12 Aug 2015 19:58:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/transparent-user-id-vs-authenticated-user/m-p/2638494#M5473</guid>
      <dc:creator>Ken Stieers</dc:creator>
      <dc:date>2015-08-12T19:58:49Z</dc:date>
    </item>
  </channel>
</rss>

