<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ASA with domain users in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3222547#M1016129</link>
    <description>&lt;P&gt;sure will rate and uptill now I have rated for your replies,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;my question was if I don't include groups in the user download page&amp;nbsp; Firesight will&amp;nbsp;display me all the groups when configuring the access policies, so I don't have to include or exclude , this is an extra feature by FS &amp;nbsp;that precisely&amp;nbsp;displays &amp;nbsp;only those group while configuring access policies&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sun, 26 Nov 2017 05:07:02 GMT</pubDate>
    <dc:creator>adamgibs7</dc:creator>
    <dc:date>2017-11-26T05:07:02Z</dc:date>
    <item>
      <title>ASA with domain users</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3221387#M1016115</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have implemented firepower with fire sight system, my problem is when a guest connect his laptop he get the IP address and he able to connect to the internet, I want the single sign on with source fire&amp;nbsp;for domain users and if&amp;nbsp;the user&amp;nbsp;is not a domain user then&amp;nbsp;the &amp;nbsp;prompt should appear for username and password.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is achievable in fortinet &amp;nbsp;How I can achieve this with ASA.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 14:49:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3221387#M1016115</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2020-02-21T14:49:14Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with domain users</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3221538#M1016116</link>
      <description>&lt;P&gt;If you are managing your ASA Firepower service module with Firepower Management Center you can setup realm integration with your AD and require all non-AD users to use captive portal. The same is not possible using only ASDM-based management.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'm not sure where a guest user account would be defined in your scenario though.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Nov 2017 10:44:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3221538#M1016116</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-11-23T10:44:18Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with domain users</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3222340#M1016120</link>
      <description>&lt;P&gt;Dear Marvin,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Can you route me to the documentation for the captive portal, as mentioned above in your reply.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 25 Nov 2017 07:52:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3222340#M1016120</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2017-11-25T07:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with domain users</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3222410#M1016122</link>
      <description>&lt;P&gt;Cisco has a Configuration Example document on just this integration. Please see the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/200329-Configure-Active-Directory-Integration-w.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/200329-Configure-Active-Directory-Integration-w.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Additional details can be found in the FMC Configuration Guide here:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/user_identity_sources.html#concept_6E7BBA97DD5D4883AA55185B6FEEE9BA" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/620/configuration/guide/fpmc-config-guide-v62/user_identity_sources.html#concept_6E7BBA97DD5D4883AA55185B6FEEE9BA&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 25 Nov 2017 14:18:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3222410#M1016122</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-11-25T14:18:32Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with domain users</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3222498#M1016123</link>
      <description>&lt;P&gt;Dear Marvin,&lt;/P&gt;
&lt;P&gt;Thanks for the reply and the link provided I will configure and if I get stuck anywhere I will post the error,&amp;nbsp;according to the link provided I &amp;nbsp;have a small query below,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please find the attached screenshot, I am running 6.0, none of the groups are selected in the user Download page but still the user name's &amp;nbsp;are seen in the connection events, file events, malware events,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Do we have to select the groups in the user download page or by default&amp;nbsp;all are included as I can see user groups when I create a policy.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 25 Nov 2017 23:21:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3222498#M1016123</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2017-11-25T23:21:54Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with domain users</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3222536#M1016126</link>
      <description>&lt;P&gt;You're welcome - please rate if it helped.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Re the groups, select them from the downloads page. That is where the user mapping to group is derived from.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Identification of end user identity is via one of the identity sources - User Agent, ISE, captive portal etc.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Association of that user identity to a group is via the selections you have available on the screenshot you shared.&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 02:56:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3222536#M1016126</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-11-26T02:56:23Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with domain users</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3222547#M1016129</link>
      <description>&lt;P&gt;sure will rate and uptill now I have rated for your replies,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;my question was if I don't include groups in the user download page&amp;nbsp; Firesight will&amp;nbsp;display me all the groups when configuring the access policies, so I don't have to include or exclude , this is an extra feature by FS &amp;nbsp;that precisely&amp;nbsp;displays &amp;nbsp;only those group while configuring access policies&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 05:07:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3222547#M1016129</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2017-11-26T05:07:02Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with domain users</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3222591#M1016130</link>
      <description>&lt;P&gt;If you do not specify any groups to include, the system retrieves user data for all the groups that match the parameters you provided. For performance reasons, Cisco recommends that you explicitly include only the groups that represent the users you want to use in access control.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In my lab, I have specified only Domain Users and Domain Admins in my Realm configuration (screenshot #1 below). Thus, when configuring an ACP I only have those groups and their members to choose among when configuring a rule (screenshot #2).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="FMC User and Group download setting.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/3968i250E7E1CF6ED4826/image-size/large?v=v2&amp;amp;px=999" role="button" title="FMC User and Group download setting.PNG" alt="FMC User and Group download setting.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ACP Rule with Users.PNG" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/3967i8C977E585B9E5509/image-size/large?v=v2&amp;amp;px=999" role="button" title="ACP Rule with Users.PNG" alt="ACP Rule with Users.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Nov 2017 12:09:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3222591#M1016130</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-11-26T12:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: ASA with domain users</title>
      <link>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3223307#M1016132</link>
      <description>thanks</description>
      <pubDate>Mon, 27 Nov 2017 18:59:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/asa-with-domain-users/m-p/3223307#M1016132</guid>
      <dc:creator>adamgibs7</dc:creator>
      <dc:date>2017-11-27T18:59:44Z</dc:date>
    </item>
  </channel>
</rss>

