<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic How security event is shared between DC's in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/how-security-event-is-shared-between-dc-s/m-p/4641989#M575842</link>
    <description>&lt;P class="line" style="white-space: pre-wrap;"&gt;I have only one operational DC from where user Agent are getting userid/ip mapping info. Even though there are 1 other DC added at User agent but other 1 are part of Test Site.&lt;/P&gt;
&lt;DIV class="header-content"&gt;
&lt;P class="line" style="white-space: pre-wrap;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P class="line" style="white-space: pre-wrap;"&gt;How to confirm which dc actually providing user id and ip mapping to the user agent.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="line" style="white-space: pre-wrap;"&gt;Refer to below doc and based on my current scenario, if technically user agent connecting to one dc which is not listed in user agent while knowing DC's do not share the security events ?&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cisco reference quote&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="line" style="white-space: pre-wrap;"&gt;**&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firesight/user-agent/24/config-guide/Firepower-User-Agent-Configuration-Guide-v2-4/ConfigAgent.html#88746" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/firesight/user-agent/24/config-guide/Firepower-User-Agent-Configuration-Guide-v2-4/ConfigAgent.html#88746&lt;/A&gt;&lt;/P&gt;
&lt;P class="line" style="white-space: pre-wrap;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="line" style="white-space: pre-wrap;"&gt;If your Active Directory system has multiple domain controllers, enter the host name or IP address of the domain controller with which you want the user agent to communicate. (Active Directory domain controllers don’t share their security logs so you must have a separate user agent connection to each controller.) In a distributed or heavily trafficked system, you can optionally install more than one user agent as discussed in Deploy Multiple User Agents.**&lt;/P&gt;
&lt;P class="line" style="white-space: pre-wrap;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 30 Jun 2022 19:00:33 GMT</pubDate>
    <dc:creator>MSJ1</dc:creator>
    <dc:date>2022-06-30T19:00:33Z</dc:date>
    <item>
      <title>How security event is shared between DC's</title>
      <link>https://community.cisco.com/t5/network-access-control/how-security-event-is-shared-between-dc-s/m-p/4641989#M575842</link>
      <description>&lt;P class="line" style="white-space: pre-wrap;"&gt;I have only one operational DC from where user Agent are getting userid/ip mapping info. Even though there are 1 other DC added at User agent but other 1 are part of Test Site.&lt;/P&gt;
&lt;DIV class="header-content"&gt;
&lt;P class="line" style="white-space: pre-wrap;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P class="line" style="white-space: pre-wrap;"&gt;How to confirm which dc actually providing user id and ip mapping to the user agent.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P class="line" style="white-space: pre-wrap;"&gt;Refer to below doc and based on my current scenario, if technically user agent connecting to one dc which is not listed in user agent while knowing DC's do not share the security events ?&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Cisco reference quote&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="line" style="white-space: pre-wrap;"&gt;**&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firesight/user-agent/24/config-guide/Firepower-User-Agent-Configuration-Guide-v2-4/ConfigAgent.html#88746" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/security/firesight/user-agent/24/config-guide/Firepower-User-Agent-Configuration-Guide-v2-4/ConfigAgent.html#88746&lt;/A&gt;&lt;/P&gt;
&lt;P class="line" style="white-space: pre-wrap;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P class="line" style="white-space: pre-wrap;"&gt;If your Active Directory system has multiple domain controllers, enter the host name or IP address of the domain controller with which you want the user agent to communicate. (Active Directory domain controllers don’t share their security logs so you must have a separate user agent connection to each controller.) In a distributed or heavily trafficked system, you can optionally install more than one user agent as discussed in Deploy Multiple User Agents.**&lt;/P&gt;
&lt;P class="line" style="white-space: pre-wrap;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;/DIV&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 19:00:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-security-event-is-shared-between-dc-s/m-p/4641989#M575842</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2022-06-30T19:00:33Z</dc:date>
    </item>
    <item>
      <title>Re: How security event is shared between DC's</title>
      <link>https://community.cisco.com/t5/network-access-control/how-security-event-is-shared-between-dc-s/m-p/4642068#M575847</link>
      <description>&lt;P&gt;This appears to be more of a Firepower question than one related to ISE/NAC. I would suggest moving/posting your question to the &lt;A href="https://community.cisco.com/t5/network-security/bd-p/discussions-network-security" target="_blank" rel="noopener"&gt;Network Security&lt;/A&gt; community section.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 22:46:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-security-event-is-shared-between-dc-s/m-p/4642068#M575847</guid>
      <dc:creator>Greg Gibbs</dc:creator>
      <dc:date>2022-06-30T22:46:57Z</dc:date>
    </item>
    <item>
      <title>Re: How security event is shared between DC's</title>
      <link>https://community.cisco.com/t5/network-access-control/how-security-event-is-shared-between-dc-s/m-p/4643383#M575902</link>
      <description>&lt;P&gt;ok did that.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Jul 2022 12:26:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/how-security-event-is-shared-between-dc-s/m-p/4643383#M575902</guid>
      <dc:creator>MSJ1</dc:creator>
      <dc:date>2022-07-04T12:26:13Z</dc:date>
    </item>
  </channel>
</rss>

