<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE cannot sent TS port range to FMC in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-cannot-sent-ts-port-range-to-fmc/m-p/3589286#M496398</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Chao,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hsing-Tsu is correct, this is expected behavior.&amp;nbsp; Please see: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/user_identity_sources.html" title="https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/user_identity_sources.html"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/user_identity_sources.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN style="color: #000000; font-family: -webkit-standard; font-size: medium;"&gt;If the TS Agent monitors the same users as another passive authentication identity source (the User Agent or ISE), the Firepower Management Center prioritizes the TS Agent data. If the TS Agent and a passive identity source report activity by the same IP address, only the TS Agent data is logged to the Firepower Management Center"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:jeppich@cisco.com"&gt;jeppich@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 06 Jul 2018 23:09:55 GMT</pubDate>
    <dc:creator>jeppich</dc:creator>
    <dc:date>2018-07-06T23:09:55Z</dc:date>
    <item>
      <title>ISE cannot sent TS port range to FMC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cannot-sent-ts-port-range-to-fmc/m-p/3589282#M496394</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;i got TS agent working with ISE 2.2 .&lt;/P&gt;&lt;P&gt;on ISE 2.2, I can see the User ID, IP and Port range mapping in live session table.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="sl.JPG" class="image-1 jive-image" src="https://community.cisco.com/legacyfs/online/fusion/118179_sl.JPG" style="height: 165px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;But on FMC, it doesnt show these information.&lt;/P&gt;&lt;P&gt;&lt;IMG alt="slfmc.JPG" class="jive-image image-2" src="https://community.cisco.com/legacyfs/online/fusion/118180_slfmc.JPG" style="height: 126px; width: 620px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i use TS agent directly sent to FMC, it will work. &lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Is this some kind of&amp;nbsp; bug between ISE and FMC? &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;Because TS agent only allow to send mapping to 2 servers, if we need to see all user identity information on ISE and also works on FMC, so we have to send to both ISE and FMC, we will lose redundancy.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 13.3333px;"&gt;it doesnt make sense. &lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2018 18:48:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cannot-sent-ts-port-range-to-fmc/m-p/3589282#M496394</guid>
      <dc:creator>csco11552159</dc:creator>
      <dc:date>2018-07-06T18:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: ISE cannot sent TS port range to FMC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cannot-sent-ts-port-range-to-fmc/m-p/3589283#M496395</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I think it might be expected at present. I will check with our teams.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2018 21:23:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cannot-sent-ts-port-range-to-fmc/m-p/3589283#M496395</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-07-06T21:23:17Z</dc:date>
    </item>
    <item>
      <title>Re: ISE cannot sent TS port range to FMC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cannot-sent-ts-port-range-to-fmc/m-p/3589284#M496396</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;P&gt;and on FMC, in this way will only keep the last user login.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2018 21:36:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cannot-sent-ts-port-range-to-fmc/m-p/3589284#M496396</guid>
      <dc:creator>csco11552159</dc:creator>
      <dc:date>2018-07-06T21:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE cannot sent TS port range to FMC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cannot-sent-ts-port-range-to-fmc/m-p/3589285#M496397</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Some info from our PM indicated that our teams are still working on this to make it more consumable.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2018 23:08:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cannot-sent-ts-port-range-to-fmc/m-p/3589285#M496397</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-07-06T23:08:13Z</dc:date>
    </item>
    <item>
      <title>Re: ISE cannot sent TS port range to FMC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cannot-sent-ts-port-range-to-fmc/m-p/3589286#M496398</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hey Chao,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hsing-Tsu is correct, this is expected behavior.&amp;nbsp; Please see: &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/user_identity_sources.html" title="https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/user_identity_sources.html"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/user_identity_sources.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;"&lt;SPAN style="color: #000000; font-family: -webkit-standard; font-size: medium;"&gt;If the TS Agent monitors the same users as another passive authentication identity source (the User Agent or ISE), the Firepower Management Center prioritizes the TS Agent data. If the TS Agent and a passive identity source report activity by the same IP address, only the TS Agent data is logged to the Firepower Management Center"&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;John&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-email-small" href="mailto:jeppich@cisco.com"&gt;jeppich@cisco.com&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 06 Jul 2018 23:09:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cannot-sent-ts-port-range-to-fmc/m-p/3589286#M496398</guid>
      <dc:creator>jeppich</dc:creator>
      <dc:date>2018-07-06T23:09:55Z</dc:date>
    </item>
    <item>
      <title>Re: ISE cannot sent TS port range to FMC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cannot-sent-ts-port-range-to-fmc/m-p/3589287#M496399</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hi John &amp;amp; Hsing-Tsu,&lt;/P&gt;&lt;P&gt;So in order FMC to have correct User ID, port and IP mapping, &lt;SPAN style="font-size: 10pt;"&gt;TS-Agent directly send to FMC? like this: &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;TS-Agent---&amp;gt;FMC&lt;/P&gt;&lt;P&gt;ISE---(pxgrid)---&amp;gt;FMC &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the way we try to do is :&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;TS-Agent---&amp;gt;ISE ----(pxgrid)---&amp;gt;FMC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We can use TS-Agent to send mapping to ISE, then we should easily send all ID mapping to FMC via pxgrid including regular mapping and TS ports mapping. this more make sense.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: 10pt;"&gt;Will this way work? &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Jul 2018 02:00:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cannot-sent-ts-port-range-to-fmc/m-p/3589287#M496399</guid>
      <dc:creator>csco11552159</dc:creator>
      <dc:date>2018-07-07T02:00:12Z</dc:date>
    </item>
    <item>
      <title>Re: ISE cannot sent TS port range to FMC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cannot-sent-ts-port-range-to-fmc/m-p/3589288#M496400</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately it's not quite there yet.&lt;/P&gt;&lt;P&gt;I would suggest you to use TS-Agent =&amp;gt; FMC for now, while the solution is still being evolved and developed for the other route.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 07 Jul 2018 02:51:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cannot-sent-ts-port-range-to-fmc/m-p/3589288#M496400</guid>
      <dc:creator>hslai</dc:creator>
      <dc:date>2018-07-07T02:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE cannot sent TS port range to FMC</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-cannot-sent-ts-port-range-to-fmc/m-p/3589289#M496401</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thank you.&lt;/P&gt;&lt;P&gt;i will send to FMC for now. hopefully some changes coming soon.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 10 Jul 2018 13:04:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-cannot-sent-ts-port-range-to-fmc/m-p/3589289#M496401</guid>
      <dc:creator>csco11552159</dc:creator>
      <dc:date>2018-07-10T13:04:32Z</dc:date>
    </item>
  </channel>
</rss>

