<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrating TEAP users from FMC-User Agent to Cisco ISE in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/migrating-teap-users-from-fmc-user-agent-to-cisco-ise/m-p/5341313#M598674</link>
    <description>&lt;P&gt;Hi Nikhil&lt;/P&gt;
&lt;P&gt;Have you been able to get it run?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have been on the same setup Saj mentioned: 802.1x with Device Cert und passiveID Agent for user. But this was never realy successful since the passiveID Agent was too slow for roaming clients and the User ID was lost to often to have a strong realiable solution. So I deciced to go for TEAP with Device and User Certs using ISE for WiFi, LAN and Remote Access.&lt;/P&gt;
&lt;P&gt;Unfortunatly with that, it looks like FMC/FTD is no more able to find the correct User anymore, since the Username displayed on FMC is always in the format: "user@domain.com,MACHINEID". This cannot be mapped with the corresponding AD-group configured in the Realm. So I wonder waht is the correct way to use User Certs for ID Based FW using TEAP as 802.1x...&lt;/P&gt;</description>
    <pubDate>Thu, 23 Oct 2025 06:30:41 GMT</pubDate>
    <dc:creator>mstraessle</dc:creator>
    <dc:date>2025-10-23T06:30:41Z</dc:date>
    <item>
      <title>Migrating TEAP users from FMC-User Agent to Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/migrating-teap-users-from-fmc-user-agent-to-cisco-ise/m-p/4655058#M576293</link>
      <description>&lt;P&gt;Hello Everyone,&lt;/P&gt;
&lt;P&gt;As Cisco has announced EOL for FMC-User Agent functionality for versions 6.6 and above. We are trying to migrate to Cisco ISE to capture user logon information. While reviewing the document:&amp;nbsp;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/630/configuration/guide/fpmc-config-guide-v63/control_users_with_ise_ise_pic.html#:~:text=To%20implement%20user%20control%20using%20ISE%20or%20ISE-PIC,the%20Firepower%20Management%20Center%20s%20will%20be%20dropped." target="_blank" rel="noopener"&gt;Firepower Management Center Configuration Guide, Version 6.3 - Control Users with ISE/ISE-PIC [Cisco Secure Firewall Management Center] - Cisco&lt;/A&gt;&lt;/P&gt;
&lt;DIV id="tinyMceEditorNikhilJadhav_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;there is a note which states that:&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"The Firepower System does not parse IEEE 802.1x machine authentication but it&amp;nbsp;does&amp;nbsp;parse 802.1x user authentication. If you are using 802.1x with ISE, you must include user authentication. 802.1x machine authentication will not provide a user identity to the FMC that can be used in policy."&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;Currently we are using TEAP method of authentication which uses User and Machine identity in a single tunnel to authenticate the users. Will the User-Agent migration to Cisco ISE work for our current scenario as in the above statement, the FMC only parses 802.1x user authentication and ignores machine authentication?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2022 19:19:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/migrating-teap-users-from-fmc-user-agent-to-cisco-ise/m-p/4655058#M576293</guid>
      <dc:creator>Nikhil Jadhav</dc:creator>
      <dc:date>2022-07-21T19:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating TEAP users from FMC-User Agent to Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/migrating-teap-users-from-fmc-user-agent-to-cisco-ise/m-p/4669472#M576701</link>
      <description>&lt;P&gt;Hopefully it will work but hard to know exactly how the FMC parser works without testing it.&lt;/P&gt;
&lt;P&gt;Did you ever find out?&lt;/P&gt;</description>
      <pubDate>Mon, 15 Aug 2022 23:32:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/migrating-teap-users-from-fmc-user-agent-to-cisco-ise/m-p/4669472#M576701</guid>
      <dc:creator>thomas</dc:creator>
      <dc:date>2022-08-15T23:32:48Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating TEAP users from FMC-User Agent to Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/migrating-teap-users-from-fmc-user-agent-to-cisco-ise/m-p/4767266#M579576</link>
      <description>&lt;P&gt;Hi Nikhil,&lt;/P&gt;&lt;P&gt;Just wondering whether machine auth is working in your setup.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Brief info on my setup:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Windows desktops authenticate using the device auth cert to ISE&lt;/LI&gt;&lt;LI&gt;Passive ID using to get the User to IP mappings from AD&lt;/LI&gt;&lt;LI&gt;The same information is passed to FMC through the PxGrid&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In the FMC, we can see the User to IP mapping for clients with Device Auth. However, an identity-based policy not working for users with device auth.&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;why can FMC not execute an identity-based rule when the User to IP mapping details are available?&lt;/LI&gt;&lt;LI&gt;Is there any way to check the user to ip mapping information in the FMC?&lt;/LI&gt;&lt;LI&gt;What is the logic FMC use to decide which log to be considered? is it the latest log win?&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;Users with PEAP auth do work fine with the identity-based rules. So, it confirms that PxGrid is working fine.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Feb 2023 07:47:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/migrating-teap-users-from-fmc-user-agent-to-cisco-ise/m-p/4767266#M579576</guid>
      <dc:creator>~Saj~</dc:creator>
      <dc:date>2023-02-02T07:47:12Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating TEAP users from FMC-User Agent to Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/migrating-teap-users-from-fmc-user-agent-to-cisco-ise/m-p/5341313#M598674</link>
      <description>&lt;P&gt;Hi Nikhil&lt;/P&gt;
&lt;P&gt;Have you been able to get it run?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have been on the same setup Saj mentioned: 802.1x with Device Cert und passiveID Agent for user. But this was never realy successful since the passiveID Agent was too slow for roaming clients and the User ID was lost to often to have a strong realiable solution. So I deciced to go for TEAP with Device and User Certs using ISE for WiFi, LAN and Remote Access.&lt;/P&gt;
&lt;P&gt;Unfortunatly with that, it looks like FMC/FTD is no more able to find the correct User anymore, since the Username displayed on FMC is always in the format: "user@domain.com,MACHINEID". This cannot be mapped with the corresponding AD-group configured in the Realm. So I wonder waht is the correct way to use User Certs for ID Based FW using TEAP as 802.1x...&lt;/P&gt;</description>
      <pubDate>Thu, 23 Oct 2025 06:30:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/migrating-teap-users-from-fmc-user-agent-to-cisco-ise/m-p/5341313#M598674</guid>
      <dc:creator>mstraessle</dc:creator>
      <dc:date>2025-10-23T06:30:41Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating TEAP users from FMC-User Agent to Cisco ISE</title>
      <link>https://community.cisco.com/t5/network-access-control/migrating-teap-users-from-fmc-user-agent-to-cisco-ise/m-p/5341321#M598675</link>
      <description>&lt;P&gt;Hey all am jumping in here because this exact scenario is on my radar too: migrating users from FMC User Agent to Cisco ISE (TEAP users specifically).&lt;/P&gt;&lt;P&gt;Couple of things that are bothering me:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;When migrating does the user experience change (certificates, login prompts, etc.)?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Are there any gotchas around existing devices (laptops, phones) that were already set up with FMC User Agent?&lt;/P&gt;&lt;/LI&gt;&lt;LI&gt;&lt;P&gt;Also in your experience how much downtime or service hiccup should we expect during the switch-over?&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Would love to hear from someone who’s done this live what surprised you, what you wished you’d done differently.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Thu, 23 Oct 2025 06:47:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/migrating-teap-users-from-fmc-user-agent-to-cisco-ise/m-p/5341321#M598675</guid>
      <dc:creator>Chloeharper</dc:creator>
      <dc:date>2025-10-23T06:47:25Z</dc:date>
    </item>
  </channel>
</rss>

