<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FireSIGHT User Agent in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firesight-user-agent/m-p/3061249#M1029104</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Need some advise on FireSIGHT User Agent. I have a FireSIGHT Management Center managing a number of ASA with Firepower service and integrate with global AD.&lt;/P&gt;
&lt;P&gt;1. How many FireSIGHT&amp;nbsp;User Agent shall I deploy?&lt;/P&gt;
&lt;P&gt;2. FireSIGHT reports get the information from AD Event Viewer database?&lt;/P&gt;
&lt;P&gt;3. With different DHCP servers in each location, will this affect the report, network control? Example sites shall not have overlapping IP networks, etc.&lt;/P&gt;
&lt;P&gt;Or it is okay to have overlapping IP networks since firewall rules/filtering etc.&amp;nbsp;are implemented in individual ASA.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;Meng&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 13:24:35 GMT</pubDate>
    <dc:creator>chee-meng_hong</dc:creator>
    <dc:date>2019-03-12T13:24:35Z</dc:date>
    <item>
      <title>FireSIGHT User Agent</title>
      <link>https://community.cisco.com/t5/network-security/firesight-user-agent/m-p/3061249#M1029104</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Need some advise on FireSIGHT User Agent. I have a FireSIGHT Management Center managing a number of ASA with Firepower service and integrate with global AD.&lt;/P&gt;
&lt;P&gt;1. How many FireSIGHT&amp;nbsp;User Agent shall I deploy?&lt;/P&gt;
&lt;P&gt;2. FireSIGHT reports get the information from AD Event Viewer database?&lt;/P&gt;
&lt;P&gt;3. With different DHCP servers in each location, will this affect the report, network control? Example sites shall not have overlapping IP networks, etc.&lt;/P&gt;
&lt;P&gt;Or it is okay to have overlapping IP networks since firewall rules/filtering etc.&amp;nbsp;are implemented in individual ASA.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thank you&lt;/P&gt;
&lt;P&gt;Meng&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:24:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-user-agent/m-p/3061249#M1029104</guid>
      <dc:creator>chee-meng_hong</dc:creator>
      <dc:date>2019-03-12T13:24:35Z</dc:date>
    </item>
    <item>
      <title>Overlapping subnets will be a</title>
      <link>https://community.cisco.com/t5/network-security/firesight-user-agent/m-p/3061250#M1029109</link>
      <description>&lt;P&gt;Overlapping subnets will be a problem since the User Agents all report back to FMC. The FMC would not know that address a is user a for one ASA but user b for a different ASA.&lt;/P&gt;
&lt;P&gt;Generally the rule of thumb is that you need a user agent querying at least every domain controller that processes user logons. (It queries the Event Logs via WMI.)&lt;/P&gt;
&lt;P&gt;A given agent can query up to 5 servers. Reference:&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firesight/user-agent/23/config-guide/Firepower-User-Agent-Configuration-Guide-v2-3/Intro.html#50942&lt;/P&gt;
&lt;P&gt;...so plan your deployment accordingly.&lt;/P&gt;</description>
      <pubDate>Fri, 26 May 2017 08:42:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-user-agent/m-p/3061250#M1029109</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-05-26T08:42:20Z</dc:date>
    </item>
  </channel>
</rss>

