<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello Avram, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925744#M1030031</link>
    <description>&lt;P&gt;Hello Avram,&lt;/P&gt;
&lt;P&gt;As I told you in some of the previous replies for your Useragent&amp;nbsp;queries&amp;nbsp; last week , user based access control policies can be created&amp;nbsp;only by installing the Firepower Useragent. Once the user agent is installed properly you can create the AC policy based on specific users. Navigate to Policies &amp;gt; Access Control &amp;gt; Rules &amp;gt; Users - Under users you should be able to search for the users that you fetched from the AD. If you are not able to fetch the users , that means the user agent installation or communication is not proper.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rate if the post helps you.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jul 2016 04:24:40 GMT</pubDate>
    <dc:creator>Jetsy Mathew</dc:creator>
    <dc:date>2016-07-14T04:24:40Z</dc:date>
    <item>
      <title>Network Users Discovery.</title>
      <link>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925742#M1030026</link>
      <description>&lt;P&gt;&lt;SPAN class="translation-chunk" data-align="0:12"&gt;Hello! It's me again.&lt;/SPAN&gt;&lt;SPAN class="translation-chunk" data-align="12:20"&gt;Read&lt;/SPAN&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class="translation-chunk" data-align="21:37"&gt;all the documentation&lt;/SPAN&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class="translation-chunk" data-align="38:40"&gt;but&lt;/SPAN&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class="translation-chunk" data-align="41:56"&gt;have not found the answer. Problem with Network Discovery with users.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="translation-chunk" data-align="41:56"&gt;I have created:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="translation-chunk" data-align="41:56"&gt;1.Policy - Network Discovery - Network - Here I added networks, zone and actions (discover user host application)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="translation-chunk" data-align="41:56"&gt;&lt;SPAN&gt;2.Policy - Network Discovery -&amp;nbsp;Users - Here add all protocols&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="translation-chunk" data-align="41:56"&gt;&lt;SPAN&gt;Then created:&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="translation-chunk" data-align="41:56"&gt;&lt;SPAN&gt;3.Policy - access control - with some rules (use discovery only by default)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="translation-chunk" data-align="41:56"&gt;&lt;SPAN&gt;How I understand for first time that all. But the system can not find users (It is find only users that use FTP)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="translation-chunk" data-align="41:56"&gt;&lt;SPAN&gt;May be it is need to use NetFlow Devices?&amp;nbsp;What am I doing wrong? Thank you!&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:04:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925742#M1030026</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2019-03-12T13:04:23Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925743#M1030029</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;Network discovery does discover hosts and applications but this cannot be used in access control policy for user based rules.&lt;/P&gt;
&lt;P&gt;Network discovery's primary usage is for IPS policies firesight recommendation and awareness about the user data in firesifght.&lt;/P&gt;
&lt;P&gt;For access control policies, Firepower needs to have user-ip mapping based on which it can apply the rules.&lt;/P&gt;
&lt;P&gt;You would need user agent which can get the user IP mapping and then this whole config on firepower which will work along with that.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/200329-Configure-Active-Directory-Integration-w.html&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118131-technote-sourcefire-00.html&lt;/P&gt;
&lt;P&gt;The above articles will help.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rate if helps.&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 03:11:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925743#M1030029</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2016-07-14T03:11:27Z</dc:date>
    </item>
    <item>
      <title>Hello Avram,</title>
      <link>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925744#M1030031</link>
      <description>&lt;P&gt;Hello Avram,&lt;/P&gt;
&lt;P&gt;As I told you in some of the previous replies for your Useragent&amp;nbsp;queries&amp;nbsp; last week , user based access control policies can be created&amp;nbsp;only by installing the Firepower Useragent. Once the user agent is installed properly you can create the AC policy based on specific users. Navigate to Policies &amp;gt; Access Control &amp;gt; Rules &amp;gt; Users - Under users you should be able to search for the users that you fetched from the AD. If you are not able to fetch the users , that means the user agent installation or communication is not proper.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Rate if the post helps you.&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 04:24:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925744#M1030031</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2016-07-14T04:24:40Z</dc:date>
    </item>
    <item>
      <title>THANK YOU! Sorry for my</title>
      <link>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925745#M1030033</link>
      <description>&lt;P&gt;THANK YOU!&amp;nbsp;&lt;SPAN class="translation-chunk" data-align="0:11"&gt;Sorry for&lt;/SPAN&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;SPAN class="translation-chunk" data-align="12:24"&gt;my stupidity!&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Here:Navigate to Policies &amp;gt; Access Control &amp;gt; Rules &amp;gt; Users I see users and groups that I added in Users - LDAP Connections .&amp;nbsp;&lt;SPAN&gt;This means that all must work. I will check! Thak you for your time.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 06:04:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925745#M1030033</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2016-07-14T06:04:48Z</dc:date>
    </item>
    <item>
      <title>I think i found my problem!</title>
      <link>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925746#M1030035</link>
      <description>&lt;P&gt;I think i found my problem! It is problem with access to DC. I try to install agent to another computer (not domain) and have error &amp;nbsp;- unable to read security log on DC. Trying to solve! P.S. &lt;SPAN&gt;very strange - I have not this error if I try to add&amp;nbsp;&lt;/SPAN&gt;&amp;nbsp;AD in agent that installed on DC.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 10:21:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925746#M1030035</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2016-07-14T10:21:01Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925747#M1030038</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Use this to verify the permission.&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118637-configure-firesight-00.html&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118159-troubleshoot-firesite-00.html&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Hope it helps&lt;/P&gt;
&lt;P&gt;Yogesh&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jul 2016 15:02:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925747#M1030038</guid>
      <dc:creator>yogdhanu</dc:creator>
      <dc:date>2016-07-14T15:02:33Z</dc:date>
    </item>
    <item>
      <title>O GODS) I find mistake)</title>
      <link>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925748#M1030040</link>
      <description>&lt;P&gt;O GODS) I find mistake) Problems were with politics on domain.&lt;/P&gt;
&lt;P&gt;Enable Audit Logoff. &amp;nbsp;Enable Audit Logon. A now I see users. Woooo!!! Error&amp;nbsp;&amp;nbsp;An error occured while fetching encryption bytes from 'C:\UserAgentEncryptionBytes.bin': Specified key is not a valid size for this algorithm.." is left. But &amp;nbsp;see users! YHANK YOU!&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 08:53:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925748#M1030040</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2016-07-15T08:53:56Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925749#M1030042</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Please check that the file UserAgentEncryptionBytes.bin file is present and has a size greater than 0.&lt;/P&gt;
&lt;P&gt;Delete &lt;SPAN&gt;UserAgentEncryptionBytes.bin&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Enable the Cisco User Agent Service to run as a different user:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Please follow the steps :-&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Open the Service console&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Start &amp;gt; Run &amp;gt; services.msc (or through Administrative Tools)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Right Click and Choose Properties for Cisco Firpower User Agent&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Select Log On tab&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Specify a known account with proper rights to run the service&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;SPAN&gt;http://www.cisco.com/c/en/us/support/docs/security&lt;WBR /&gt;/firesight-management-center/118637-configure-fire&lt;WBR /&gt;sight-00.html&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;IMG src="https://cisco.i.lithium.com/t5/image/serverpage/image-id/108093iD406A815F4217A34/image-size/original?v=v2&amp;amp;px=-1" border="0" alt="Screen Shot 2015-09-24 at 10.01.44 AM.png" title="Screen Shot 2015-09-24 at 10.01.44 AM.png" /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Appl and Start the Service&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Verify the&amp;nbsp;&lt;SPAN&gt;C:\UserAgentEncryptionBytes.bin is recreated and has a size greater than 0&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Rate if the post helps you&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Jetsy&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 09:09:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925749#M1030042</guid>
      <dc:creator>Jetsy Mathew</dc:creator>
      <dc:date>2016-07-15T09:09:33Z</dc:date>
    </item>
    <item>
      <title>O! I already try to do this</title>
      <link>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925750#M1030044</link>
      <description>&lt;P&gt;O! I already try to do this.And i did not help me. Yes. size of this file 0 bytes.&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 11:39:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925750#M1030044</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2016-07-15T11:39:51Z</dc:date>
    </item>
    <item>
      <title>I dont use the agent, and I</title>
      <link>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925751#M1030045</link>
      <description>&lt;P&gt;I dont use the agent, and I can manage get user information, by using the LDAP authentication module. &amp;nbsp;Making sure you capture in the Org all the parameters. &amp;nbsp;Haven's said that, using the User Agent at the Domain controller is the prefer way. &amp;nbsp;You need to work with the Windows Admin, and check all the policies, and logging, ports, etc. &amp;nbsp;Happy troubleshooting&lt;/P&gt;</description>
      <pubDate>Fri, 15 Jul 2016 17:59:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925751#M1030045</guid>
      <dc:creator>Ed Padilla Jr</dc:creator>
      <dc:date>2016-07-15T17:59:11Z</dc:date>
    </item>
    <item>
      <title>HEllo friends! Thank you for</title>
      <link>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925752#M1030046</link>
      <description>&lt;P&gt;HEllo friends! Thank you for your&amp;nbsp;advices! I not use agent! How I understant it needed only if I want use &amp;nbsp;&lt;SPAN&gt;access policy in firepower. I do not need it! I see all my users and theirs activity.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jul 2016 06:31:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925752#M1030046</guid>
      <dc:creator>n.avramenko87</dc:creator>
      <dc:date>2016-07-21T06:31:29Z</dc:date>
    </item>
    <item>
      <title>Congratulations!</title>
      <link>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925753#M1030047</link>
      <description>&lt;P&gt;Congratulations!&lt;/P&gt;</description>
      <pubDate>Mon, 25 Jul 2016 15:19:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/network-users-discovery/m-p/2925753#M1030047</guid>
      <dc:creator>Ed Padilla Jr</dc:creator>
      <dc:date>2016-07-25T15:19:22Z</dc:date>
    </item>
  </channel>
</rss>

