<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic It should be irrespective of in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-ad-security-event-log/m-p/3047531#M24313</link>
    <description>&lt;P&gt;It should be irrespective of AD/LDAP. As during authentication of user, ISE talks to Kerberos and for group retrieval/Lookup&amp;nbsp;from AD, it uses LDAP application.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In both cases, event should generate on AD.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Request can be DOT1X which uses RADIUS protocol or it can be TACACS user authentication from AD/LDAP server.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;PS : rate if it helps!!!!!&lt;/P&gt;</description>
    <pubDate>Wed, 25 Jan 2017 18:02:35 GMT</pubDate>
    <dc:creator>Gagandeep Singh</dc:creator>
    <dc:date>2017-01-25T18:02:35Z</dc:date>
    <item>
      <title>ISE AD Security Event log?</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-security-event-log/m-p/3047528#M24306</link>
      <description>&lt;P&gt;If you have ISE integrated with AD, when a user authenticates with ISE does it create a login event on the DC security event log?&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 07:23:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-security-event-log/m-p/3047528#M24306</guid>
      <dc:creator>rangerdangerx</dc:creator>
      <dc:date>2019-03-11T07:23:41Z</dc:date>
    </item>
    <item>
      <title>Yes, it does as ISE sends</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-security-event-log/m-p/3047529#M24307</link>
      <description>&lt;P&gt;Yes, it does as ISE sends request to DC for user check and once it gets confirmation then ISE looks for authorizing that AD user. So in a nutshell, DC should have a log for that user event viewer.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;PS : rate if it helps!!!!!&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2017 23:48:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-security-event-log/m-p/3047529#M24307</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2017-01-24T23:48:06Z</dc:date>
    </item>
    <item>
      <title>but it would be a dot1x login</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-security-event-log/m-p/3047530#M24309</link>
      <description>&lt;P&gt;but it would be a dot1x login event and not &lt;G class="gr_ gr_25 gr-alert gr_spell gr_run_anim gr_inline_cards ContextualSpelling ins-del multiReplace" id="25" data-gr-id="25"&gt;ldap&lt;/G&gt;&amp;nbsp;correct?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 15:03:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-security-event-log/m-p/3047530#M24309</guid>
      <dc:creator>rangerdangerx</dc:creator>
      <dc:date>2017-01-25T15:03:29Z</dc:date>
    </item>
    <item>
      <title>It should be irrespective of</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-security-event-log/m-p/3047531#M24313</link>
      <description>&lt;P&gt;It should be irrespective of AD/LDAP. As during authentication of user, ISE talks to Kerberos and for group retrieval/Lookup&amp;nbsp;from AD, it uses LDAP application.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;In both cases, event should generate on AD.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Request can be DOT1X which uses RADIUS protocol or it can be TACACS user authentication from AD/LDAP server.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;PS : rate if it helps!!!!!&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 18:02:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-security-event-log/m-p/3047531#M24313</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2017-01-25T18:02:35Z</dc:date>
    </item>
    <item>
      <title>lets say I have a firepower</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-security-event-log/m-p/3047532#M24319</link>
      <description>&lt;P&gt;&lt;G class="gr_ gr_53 gr-alert gr_spell gr_run_anim gr_inline_cards ContextualSpelling" id="53" data-gr-id="53"&gt;lets&lt;/G&gt; say I have a firepower user agent, which picks up login events from a dc, would the user agent see those events?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 18:05:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-security-event-log/m-p/3047532#M24319</guid>
      <dc:creator>rangerdangerx</dc:creator>
      <dc:date>2017-01-25T18:05:07Z</dc:date>
    </item>
    <item>
      <title>We can do that from ISE by</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-security-event-log/m-p/3047533#M24325</link>
      <description>&lt;P&gt;We can do that from ISE by sending logs to Syslog server. But don't know how to do that from Microsoft end. It would be better to open a thread with Microsoft team.&lt;/P&gt;
&lt;P&gt;You can keep this thread running if required any further questions from our end.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Gagan&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;PS : rate helpful posts...&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2017 18:24:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-security-event-log/m-p/3047533#M24325</guid>
      <dc:creator>Gagandeep Singh</dc:creator>
      <dc:date>2017-01-25T18:24:03Z</dc:date>
    </item>
    <item>
      <title>Re: We can do that from ISE by</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-ad-security-event-log/m-p/3945904#M24329</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How do we configure ISE to send those logs to FMC or FTD?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 04:15:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-ad-security-event-log/m-p/3945904#M24329</guid>
      <dc:creator>Sakun Sharma</dc:creator>
      <dc:date>2019-10-23T04:15:46Z</dc:date>
    </item>
  </channel>
</rss>

