<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Identity Provider to FMC - Scaling Question in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/identity-provider-to-fmc-scaling-question/m-p/3420346#M511734</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a Firepower customer looking for identity integration within Firepower management center. We have been exploring the identity integration with pxGrid but the scale is bringing up questions on deployment options.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The customer has around 250(!) domain controllers, which means around 25 AD-Agents. Do we have any examples on this scale ?&lt;/LI&gt;&lt;LI&gt;Would another option like SPAN or Logs might be a better approach ?&lt;OL&gt;&lt;LI&gt;There is an existing Qradar deployment with WMI integration to AD. Can that data be utilized by pxGrid and then fed into FMC ? Just checking, if this has been seen at any other customer.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Open to other ideas..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Naman&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 08 Mar 2018 03:25:23 GMT</pubDate>
    <dc:creator>mulatif</dc:creator>
    <dc:date>2018-03-08T03:25:23Z</dc:date>
    <item>
      <title>Identity Provider to FMC - Scaling Question</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-provider-to-fmc-scaling-question/m-p/3420346#M511734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I have a Firepower customer looking for identity integration within Firepower management center. We have been exploring the identity integration with pxGrid but the scale is bringing up questions on deployment options.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;The customer has around 250(!) domain controllers, which means around 25 AD-Agents. Do we have any examples on this scale ?&lt;/LI&gt;&lt;LI&gt;Would another option like SPAN or Logs might be a better approach ?&lt;OL&gt;&lt;LI&gt;There is an existing Qradar deployment with WMI integration to AD. Can that data be utilized by pxGrid and then fed into FMC ? Just checking, if this has been seen at any other customer.&lt;/LI&gt;&lt;/OL&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Open to other ideas..&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Naman&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2018 03:25:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-provider-to-fmc-scaling-question/m-p/3420346#M511734</guid>
      <dc:creator>mulatif</dc:creator>
      <dc:date>2018-03-08T03:25:23Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Provider to FMC - Scaling Question</title>
      <link>https://community.cisco.com/t5/network-access-control/identity-provider-to-fmc-scaling-question/m-p/3420347#M511735</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Max limit per ISE / ISE-PIC instance is 100 DCs today.&amp;nbsp; If require monitoring of more DCs, then deploy multiple ISE/PIC instances.&amp;nbsp; See &lt;A href="https://community.cisco.com/docs/DOC-68347"&gt;ISE Performance &amp;amp;amp; Scale&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remember, it is only needed to get identity for DCs that authenticate users and where need to apply policy based on the users logging into that DC.&amp;nbsp; Although not officially QA tested, we have tested internally the use of log event forwarding which could be used to forward logs from multiple DCs to a single DC for collection. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If the Qradar deployment generates logs for each event, then Syslog could be used to parse user/IP mappings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Craig&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 08 Mar 2018 04:46:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/identity-provider-to-fmc-scaling-question/m-p/3420347#M511735</guid>
      <dc:creator>Craig Hyps</dc:creator>
      <dc:date>2018-03-08T04:46:15Z</dc:date>
    </item>
  </channel>
</rss>

