<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Centralized Configuration for WSA with Authentication Realm in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/centralized-configuration-for-wsa-with-authentication-realm/m-p/3821416#M8367</link>
    <description>&lt;P&gt;Hi I cannot find clarification with regard to the above topic.&lt;/P&gt;
&lt;P&gt;We have 8 WSA in various cities across the country. Each have a realm configured with the same name. All are using the same configuration otherwise. Each locations Realm is slightly different in terms of the AD server they are configured with. Each has 3 targets the first of which is the local Domain Controller, then one in another city and finally the one in the data center.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I don't understand is the comments in the user guide about using different authentication realms. Since the realm itself is local to the WSA and can't be configured on the SMA it is my expectation that the Realm itself is not centrally managed and not pushed to the individual WSA's. The only thing that would be an issue if different Realm names were in use the the policies configured. Is this a correct statement?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are getting ready to do centralized config and would like to know other's experiences in this regard.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
    <pubDate>Mon, 18 Mar 2019 17:00:45 GMT</pubDate>
    <dc:creator>Garry Cross</dc:creator>
    <dc:date>2019-03-18T17:00:45Z</dc:date>
    <item>
      <title>Centralized Configuration for WSA with Authentication Realm</title>
      <link>https://community.cisco.com/t5/web-security/centralized-configuration-for-wsa-with-authentication-realm/m-p/3821416#M8367</link>
      <description>&lt;P&gt;Hi I cannot find clarification with regard to the above topic.&lt;/P&gt;
&lt;P&gt;We have 8 WSA in various cities across the country. Each have a realm configured with the same name. All are using the same configuration otherwise. Each locations Realm is slightly different in terms of the AD server they are configured with. Each has 3 targets the first of which is the local Domain Controller, then one in another city and finally the one in the data center.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I don't understand is the comments in the user guide about using different authentication realms. Since the realm itself is local to the WSA and can't be configured on the SMA it is my expectation that the Realm itself is not centrally managed and not pushed to the individual WSA's. The only thing that would be an issue if different Realm names were in use the the policies configured. Is this a correct statement?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are getting ready to do centralized config and would like to know other's experiences in this regard.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2019 17:00:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/centralized-configuration-for-wsa-with-authentication-realm/m-p/3821416#M8367</guid>
      <dc:creator>Garry Cross</dc:creator>
      <dc:date>2019-03-18T17:00:45Z</dc:date>
    </item>
    <item>
      <title>Re: Centralized Configuration for WSA with Authentication Realm</title>
      <link>https://community.cisco.com/t5/web-security/centralized-configuration-for-wsa-with-authentication-realm/m-p/3824205#M8386</link>
      <description>&lt;P&gt;i have this problems too. can you help me?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Mar 2019 07:50:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/centralized-configuration-for-wsa-with-authentication-realm/m-p/3824205#M8386</guid>
      <dc:creator>Johnatan Dire</dc:creator>
      <dc:date>2019-03-22T07:50:14Z</dc:date>
    </item>
    <item>
      <title>Re: Centralized Configuration for WSA with Authentication Realm</title>
      <link>https://community.cisco.com/t5/web-security/centralized-configuration-for-wsa-with-authentication-realm/m-p/3828831#M8397</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;If you are using the same realm name it should not prevent you from using SMA.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sma is using the configurations under the Web Security menu.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;There, you have your identification profile. Your identification profile knows which realm it will consume to get identity information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;As long as the realm name matches, it will not consider which servers does that realm connect. (To get user ip mappings.)&lt;/P&gt;&lt;P&gt;SMA should not change the configurations of Realm even if you want it to do.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Sadik&lt;/P&gt;</description>
      <pubDate>Fri, 29 Mar 2019 12:09:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/centralized-configuration-for-wsa-with-authentication-realm/m-p/3828831#M8397</guid>
      <dc:creator>sadik.sener1</dc:creator>
      <dc:date>2019-03-29T12:09:57Z</dc:date>
    </item>
  </channel>
</rss>

