<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic I tried with Access Policy in in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-active-authentication-unable-to-make-it-work/m-p/2877014#M1031026</link>
    <description>&lt;P&gt;I tried with Access Policy in FP . It is same behavior. for some reason it is dropping the packet .&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Apr 2016 15:29:36 GMT</pubDate>
    <dc:creator>gncomms01</dc:creator>
    <dc:date>2016-04-22T15:29:36Z</dc:date>
    <item>
      <title>Firepower Active Authentication unable to make it work</title>
      <link>https://community.cisco.com/t5/network-security/firepower-active-authentication-unable-to-make-it-work/m-p/2877011#M1031023</link>
      <description>&lt;P&gt;I am trying to setup the Active and Passive Authentication with Firepower version 6 ( ASA 5585-SSP-60 )&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I installed the fire power user agent and setup realm in integration.&amp;nbsp; Passive Authentication works. I am seeing two problems,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;1) if user is not in active directory , than trying to use Active Authentication . but on the firewall logs keep getting the packet drops,&amp;nbsp; not getting the authentication window.&amp;nbsp; Captive-portal is setup on the firewall. Any ideas&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;%ASA-4-434002: SFR requested to drop TCP packet from vlan80:10.255.111.10/53061 to identity:10.255.111.253/885&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;2) Passive Authentication , notice that if login with local user account ( not the domain account ) firepower don't identify the user as guest/unknown . Will keep allow the traffic with last known domain user id from&amp;nbsp;that computer. Is this normal behaviour ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:59:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-active-authentication-unable-to-make-it-work/m-p/2877011#M1031023</guid>
      <dc:creator>CSCO12002221</dc:creator>
      <dc:date>2019-03-12T12:59:04Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/firepower-active-authentication-unable-to-make-it-work/m-p/2877012#M1031024</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For the second one it is expected because the user entry is still there . The default timeout is 1440 minutes , if you want you can change that&amp;nbsp; under System &amp;gt; Integration &amp;gt;Realm configuration.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For the first one I am really not quite sure but ideally it should at least prompt for the authentication window. You might need to open up a TAC case so that further analysis can be done in this.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Aastha Bhardwaj&lt;/P&gt;
&lt;P&gt;Rate if that helps!!!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Apr 2016 13:18:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-active-authentication-unable-to-make-it-work/m-p/2877012#M1031024</guid>
      <dc:creator>Aastha Bhardwaj</dc:creator>
      <dc:date>2016-04-21T13:18:26Z</dc:date>
    </item>
    <item>
      <title>In the access policy on the</title>
      <link>https://community.cisco.com/t5/network-security/firepower-active-authentication-unable-to-make-it-work/m-p/2877013#M1031025</link>
      <description>&lt;P&gt;In the access policy on the FP, do you allow traffic to 10.255.111.253/885 ?&lt;/P&gt;
&lt;P&gt;/Per&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2016 08:37:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-active-authentication-unable-to-make-it-work/m-p/2877013#M1031025</guid>
      <dc:creator>Per Tenggren</dc:creator>
      <dc:date>2016-04-22T08:37:59Z</dc:date>
    </item>
    <item>
      <title>I tried with Access Policy in</title>
      <link>https://community.cisco.com/t5/network-security/firepower-active-authentication-unable-to-make-it-work/m-p/2877014#M1031026</link>
      <description>&lt;P&gt;I tried with Access Policy in FP . It is same behavior. for some reason it is dropping the packet .&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2016 15:29:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-active-authentication-unable-to-make-it-work/m-p/2877014#M1031026</guid>
      <dc:creator>gncomms01</dc:creator>
      <dc:date>2016-04-22T15:29:36Z</dc:date>
    </item>
    <item>
      <title>Thanks Aastha. I tried</title>
      <link>https://community.cisco.com/t5/network-security/firepower-active-authentication-unable-to-make-it-work/m-p/2877015#M1031027</link>
      <description>&lt;P&gt;Thanks Aastha. I tried changing the timeout in realm configuration but this effects the Active Directory Users also. I reduce the time to 30 mins or 10 mins and notice that it is keep logging off Active directory user and shows them as unknown . &lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Apr 2016 15:31:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-active-authentication-unable-to-make-it-work/m-p/2877015#M1031027</guid>
      <dc:creator>gncomms01</dc:creator>
      <dc:date>2016-04-22T15:31:47Z</dc:date>
    </item>
  </channel>
</rss>

