<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic users not passing to firepower in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753416#M1012793</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;We are using&amp;nbsp;Configure Cisco Firepower User Agent for Active Directory installed on a domain controller, both sections are green which seems to indicate it should pass the details back to the firepower.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have some rules on the firepower and I have added some users to the rules (it find the users) but as soon as I do this they cant access the specified content.&amp;nbsp; The rule works if I remove the users.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When looking in the logs, there is no reference to the username at all.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As the initial client request contains only the IP I believe that the firepower should then lookup that IP and match the username via the agent on the domain controller.&amp;nbsp; Is there anyway I can test this ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 14:07:31 GMT</pubDate>
    <dc:creator>systemtek</dc:creator>
    <dc:date>2019-03-12T14:07:31Z</dc:date>
    <item>
      <title>users not passing to firepower</title>
      <link>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753416#M1012793</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;
&lt;P&gt;We are using&amp;nbsp;Configure Cisco Firepower User Agent for Active Directory installed on a domain controller, both sections are green which seems to indicate it should pass the details back to the firepower.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have some rules on the firepower and I have added some users to the rules (it find the users) but as soon as I do this they cant access the specified content.&amp;nbsp; The rule works if I remove the users.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When looking in the logs, there is no reference to the username at all.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As the initial client request contains only the IP I believe that the firepower should then lookup that IP and match the username via the agent on the domain controller.&amp;nbsp; Is there anyway I can test this ?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 14:07:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753416#M1012793</guid>
      <dc:creator>systemtek</dc:creator>
      <dc:date>2019-03-12T14:07:31Z</dc:date>
    </item>
    <item>
      <title>Re: users not passing to firepower</title>
      <link>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753424#M1012794</link>
      <description>Hi,&lt;BR /&gt;Create a test rule with the user you want to allow or block as first rule in ACP and try if its working as per the AD-Username. Before testing logoff the machine and login again to get the correct IP details.&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;Abheesh</description>
      <pubDate>Tue, 27 Nov 2018 10:48:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753424#M1012794</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2018-11-27T10:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: users not passing to firepower</title>
      <link>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753436#M1012795</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Thanks for the reply, essentially that is what I have done.&amp;nbsp; I have the correct IP in the logs, but no usernames appear in the logs.&amp;nbsp; It just shows as BLOCK in logs but no username details as soon as I remove the username from the rule, it works.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 11:06:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753436#M1012795</guid>
      <dc:creator>systemtek</dc:creator>
      <dc:date>2018-11-27T11:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: users not passing to firepower</title>
      <link>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753439#M1012796</link>
      <description>click the TABLE VIEW of CONNECTION EVENTS to see the detailed view.&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;Abheesh</description>
      <pubDate>Tue, 27 Nov 2018 11:08:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753439#M1012796</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2018-11-27T11:08:29Z</dc:date>
    </item>
    <item>
      <title>Re: users not passing to firepower</title>
      <link>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753442#M1012797</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Thanks, but "Initiator User" shows as "Unknown"&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 11:10:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753442#M1012797</guid>
      <dc:creator>systemtek</dc:creator>
      <dc:date>2018-11-27T11:10:53Z</dc:date>
    </item>
    <item>
      <title>Re: users not passing to firepower</title>
      <link>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753443#M1012798</link>
      <description>&lt;P&gt;which version you are running and can you share a screenshot.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 11:12:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753443#M1012798</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2018-11-27T11:12:26Z</dc:date>
    </item>
    <item>
      <title>Re: users not passing to firepower</title>
      <link>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753449#M1012799</link>
      <description>Hi,&lt;BR /&gt;Are you created an identity policy with passive authentication and bind to ACP right..?&lt;BR /&gt;For the user details Check Analysis &amp;gt; Users &amp;gt; User Activity.&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;Abheesh</description>
      <pubDate>Tue, 27 Nov 2018 11:25:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753449#M1012799</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2018-11-27T11:25:27Z</dc:date>
    </item>
    <item>
      <title>Re: users not passing to firepower</title>
      <link>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753454#M1012800</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;I already checked in&amp;nbsp;&lt;SPAN&gt;Analysis &amp;gt; Users &amp;gt; User Activity and this does not show my test users activity.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Attached image from logs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="example-firepower-unknown user.JPG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/24837i577964B6B49C4B3C/image-size/large?v=v2&amp;amp;px=999" role="button" title="example-firepower-unknown user.JPG" alt="example-firepower-unknown user.JPG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 11:37:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753454#M1012800</guid>
      <dc:creator>systemtek</dc:creator>
      <dc:date>2018-11-27T11:37:35Z</dc:date>
    </item>
    <item>
      <title>Re: users not passing to firepower</title>
      <link>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753458#M1012801</link>
      <description>Almost same issue reported by other user, please have a look.&lt;BR /&gt;&lt;A href="https://community.cisco.com/t5/firepower/fmc-6-2-2-unknown-users/m-p/3353429/highlight/true#M1322" target="_blank"&gt;https://community.cisco.com/t5/firepower/fmc-6-2-2-unknown-users/m-p/3353429/highlight/true#M1322&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;HTH&lt;BR /&gt;Abheesh</description>
      <pubDate>Tue, 27 Nov 2018 11:41:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753458#M1012801</guid>
      <dc:creator>Abheesh Kumar</dc:creator>
      <dc:date>2018-11-27T11:41:50Z</dc:date>
    </item>
    <item>
      <title>Re: users not passing to firepower</title>
      <link>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753472#M1012802</link>
      <description>&lt;P&gt;Thanks for that link&amp;nbsp;&lt;SPAN class=""&gt;&lt;A id="link_13" class="lia-link-navigation lia-page-link lia-user-name-link" href="https://community.cisco.com/t5/user/viewprofilepage/user-id/625392" target="_self"&gt;Abheesh Kumar&lt;/A&gt;&amp;nbsp;I will need to spend some time today and tomorrow looking at that, I have found a few other similar posts so will take a look and see what is found.&amp;nbsp; In the mean time if anyone has any other suggestions&amp;nbsp; please let me know.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Nov 2018 12:04:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-not-passing-to-firepower/m-p/3753472#M1012802</guid>
      <dc:creator>systemtek</dc:creator>
      <dc:date>2018-11-27T12:04:14Z</dc:date>
    </item>
  </channel>
</rss>

