<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firepower User Agent not reporting user logins in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-user-agent-not-reporting-user-logins/m-p/2982026#M1009968</link>
    <description>&lt;P&gt;I've been fighting this issue for a couple days now, and not sure exactly what's going on. Here's a quick run down:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Windows Server 2012 R2 (Domain Controller, running FP User Agent 2.3 local)&lt;/LI&gt;
&lt;LI&gt;Firepower Management Center 6.0.1.2&lt;/LI&gt;
&lt;LI&gt;ASA 5506-X w/ Firepower Services 6.0.0.1&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Domain controller/UA are on the same subnet as the management center, windows firewall is turned off. When I add my Active Directory server in, it connects successfully and turns green, however "Last Real-Time Report" never populates. When I add Firepower management center in, it also turns green. Though "Last Reported" also never populates. I've seen numerous successful audits for login in the windows security log on the domain controller, however the management center never shows any user activity or any users learned. I've tried running through the configuration guide several times for the UA, tried using even a domain admin account, nothing. Any advice is welcome.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 13:09:11 GMT</pubDate>
    <dc:creator>Jon Major</dc:creator>
    <dc:date>2019-03-12T13:09:11Z</dc:date>
    <item>
      <title>Firepower User Agent not reporting user logins</title>
      <link>https://community.cisco.com/t5/network-security/firepower-user-agent-not-reporting-user-logins/m-p/2982026#M1009968</link>
      <description>&lt;P&gt;I've been fighting this issue for a couple days now, and not sure exactly what's going on. Here's a quick run down:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Windows Server 2012 R2 (Domain Controller, running FP User Agent 2.3 local)&lt;/LI&gt;
&lt;LI&gt;Firepower Management Center 6.0.1.2&lt;/LI&gt;
&lt;LI&gt;ASA 5506-X w/ Firepower Services 6.0.0.1&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Domain controller/UA are on the same subnet as the management center, windows firewall is turned off. When I add my Active Directory server in, it connects successfully and turns green, however "Last Real-Time Report" never populates. When I add Firepower management center in, it also turns green. Though "Last Reported" also never populates. I've seen numerous successful audits for login in the windows security log on the domain controller, however the management center never shows any user activity or any users learned. I've tried running through the configuration guide several times for the UA, tried using even a domain admin account, nothing. Any advice is welcome.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:09:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-user-agent-not-reporting-user-logins/m-p/2982026#M1009968</guid>
      <dc:creator>Jon Major</dc:creator>
      <dc:date>2019-03-12T13:09:11Z</dc:date>
    </item>
    <item>
      <title>Have you configured a Realm</title>
      <link>https://community.cisco.com/t5/network-security/firepower-user-agent-not-reporting-user-logins/m-p/2982027#M1009969</link>
      <description>&lt;P&gt;Have you configured a Realm on FMC? You have to configure a Realm and Sync your Users/Groups.&lt;/P&gt;
&lt;P&gt;Please let us&amp;nbsp;know your settings on FMC to further troubleshoot this. In case the configuration is correct you can run the ADI (user identity) process on FMC in debug mode to gather more data on the issue and see if the agent reports data.&lt;/P&gt;</description>
      <pubDate>Sat, 08 Oct 2016 19:40:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-user-agent-not-reporting-user-logins/m-p/2982027#M1009969</guid>
      <dc:creator>Oliver Kaiser</dc:creator>
      <dc:date>2016-10-08T19:40:35Z</dc:date>
    </item>
    <item>
      <title>Realm was/is configured, and</title>
      <link>https://community.cisco.com/t5/network-security/firepower-user-agent-not-reporting-user-logins/m-p/2982028#M1009970</link>
      <description>&lt;P&gt;Realm was/is configured, and user download working.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 09 Oct 2016 15:35:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-user-agent-not-reporting-user-logins/m-p/2982028#M1009970</guid>
      <dc:creator>Jon Major</dc:creator>
      <dc:date>2016-10-09T15:35:06Z</dc:date>
    </item>
    <item>
      <title>Ok, lets try to gather some</title>
      <link>https://community.cisco.com/t5/network-security/firepower-user-agent-not-reporting-user-logins/m-p/2982029#M1009971</link>
      <description>&lt;P&gt;Ok, lets try to gather some data on the issue and run the ADI process in debug mode. You need to disable the process and run it with a debug flag. Since you need to restart the process all user-identity related features wont work as long as the service is down.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;1.&amp;nbsp;Change to root on FMC&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;&lt;STRONG&gt;sudo su -&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;2. Check if adi process is running&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;&lt;STRONG&gt;ps ax | grep adi&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;3. Disable adi process (if you only kill it, it will be automatically restarted, always use pmtool)&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;&lt;STRONG&gt;/usr/local/sf/bin/pmtool DisableByID adi&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;4. Check if adi process is not running anymore&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;STRONG&gt;&lt;EM&gt;ps ax | grep adi&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;5. Start adi process with debug flag and pipe output to tmp dir&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;&lt;STRONG&gt;nohup /usr/local/sf/bin/adi --debug &amp;gt; /var/tmp/adi-debug.log 2&amp;gt;&amp;amp;1 &amp;amp;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;6. Generate logon/logoff events that should be published from AD to FMC and make sure User Agent is still connected to FMC.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;When your tests are done kill the process again and enable it using pmtool&lt;/P&gt;
&lt;P&gt;1. Find PID&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;STRONG&gt;&lt;EM&gt;ps ax | grep adi&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;2. Kill ADI process&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;&lt;STRONG&gt;kill -9 &amp;lt;PID&amp;gt;&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;3. Enable adi using pmtool&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;EM&gt;&lt;STRONG&gt;pmtool EnableById adi&lt;/STRONG&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;4. Make sure adi is running again&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;STRONG&gt;&lt;EM&gt;ps ax | grep adi&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="padding-left: 30px;"&gt;&lt;/P&gt;
&lt;P&gt;If you need help analyzing the log output&amp;nbsp;or got questions about the procedure let me know.&lt;/P&gt;</description>
      <pubDate>Sun, 09 Oct 2016 15:46:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-user-agent-not-reporting-user-logins/m-p/2982029#M1009971</guid>
      <dc:creator>Oliver Kaiser</dc:creator>
      <dc:date>2016-10-09T15:46:34Z</dc:date>
    </item>
    <item>
      <title>Re: Ok, lets try to gather some</title>
      <link>https://community.cisco.com/t5/network-security/firepower-user-agent-not-reporting-user-logins/m-p/3356261#M1009972</link>
      <description>&lt;P&gt;I gathered the info but it wasn't immediately clear what might be wrong.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Mar 2018 22:51:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-user-agent-not-reporting-user-logins/m-p/3356261#M1009972</guid>
      <dc:creator>HHRJB91360</dc:creator>
      <dc:date>2018-03-27T22:51:59Z</dc:date>
    </item>
  </channel>
</rss>

