<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Have you deployed the in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911970#M1031294</link>
    <description>&lt;P&gt;Have you deployed the Sourcefire User Agent and is it successfully discovering user-IP mapping and is that information reflected in your "Users" tab of the FirePOWER Manager?&lt;/P&gt;</description>
    <pubDate>Sat, 16 Apr 2016 13:07:06 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2016-04-16T13:07:06Z</dc:date>
    <item>
      <title>Users in access control policies</title>
      <link>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911965#M1031272</link>
      <description>&lt;P&gt;Dears&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;when i select users while creating a new policies I get the attached error.&lt;/P&gt;
&lt;P&gt;i have some queries for the access control policies&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rule 1: action: block , ,zone: inside to outside,,&amp;nbsp; source :any destination: any url : high risk url&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;Result&lt;/SPAN&gt; will be block for all users for high risk url&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rule 2:&amp;nbsp; action allow,, zone: inside to outside, source : any destination: any ,, user : ADMINS url : all-allow ,,, application filter: allow all&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;Result&lt;/SPAN&gt;:&amp;nbsp; will be user Admin will be allowed all url but block bittorent application&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Rule 3:&amp;nbsp; action allow,, zone: inside to outside, source : any destination: any ,, user : USER-ALL url : specific url category application filter: bittorrent block&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;Result:&lt;/SPAN&gt;&amp;nbsp; will be user&amp;nbsp; will be restricted to specific url and bittorent will be block&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:58:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911965#M1031272</guid>
      <dc:creator>clark white</dc:creator>
      <dc:date>2019-03-12T12:58:22Z</dc:date>
    </item>
    <item>
      <title>So do you have an identity</title>
      <link>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911966#M1031278</link>
      <description>&lt;P&gt;So do you have an identity policy?&lt;/P&gt;
&lt;P&gt;Have you linked to your domain and are you getting user identity mapping via Sourcefire User Agent or ISE?&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 01:49:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911966#M1031278</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-04-13T01:49:57Z</dc:date>
    </item>
    <item>
      <title>Dear Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911967#M1031281</link>
      <description>&lt;P&gt;Dear Marvin,&lt;/P&gt;
&lt;P&gt;can you help me for access policies whether my thinking are correct???&amp;nbsp; for identity policies i will come to you what is my exact query.&lt;/P&gt;
&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 13 Apr 2016 17:08:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911967#M1031281</guid>
      <dc:creator>clark white</dc:creator>
      <dc:date>2016-04-13T17:08:39Z</dc:date>
    </item>
    <item>
      <title>Clark,</title>
      <link>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911968#M1031287</link>
      <description>&lt;P&gt;Clark,&lt;/P&gt;
&lt;P&gt;The logic you present for your access control policy seems good.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Apr 2016 01:05:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911968#M1031287</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-04-14T01:05:42Z</dc:date>
    </item>
    <item>
      <title>Dear Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911969#M1031288</link>
      <description>&lt;P&gt;Dear Marvin,&lt;/P&gt;
&lt;P&gt;I have created a identity policy with a rule in which I have a passive authentication&amp;nbsp;and a realm which I configured but still I get&amp;nbsp;the same&amp;nbsp;" exclamation mark on the user while creating&amp;nbsp;the access policies,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;For&amp;nbsp; below access control policies the internet was very slow for every webpage when I disable URL filtering allowing to all the browsing was fast,&lt;/P&gt;
&lt;P&gt;Rule 1: action: block , ,zone: inside to outside,,&amp;nbsp; source :any destination: any url : high risk url&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;Result&lt;/SPAN&gt; will be block for all users for high risk url&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sat, 16 Apr 2016 11:54:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911969#M1031288</guid>
      <dc:creator>clark white</dc:creator>
      <dc:date>2016-04-16T11:54:08Z</dc:date>
    </item>
    <item>
      <title>Have you deployed the</title>
      <link>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911970#M1031294</link>
      <description>&lt;P&gt;Have you deployed the Sourcefire User Agent and is it successfully discovering user-IP mapping and is that information reflected in your "Users" tab of the FirePOWER Manager?&lt;/P&gt;</description>
      <pubDate>Sat, 16 Apr 2016 13:07:06 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911970#M1031294</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-04-16T13:07:06Z</dc:date>
    </item>
    <item>
      <title>Dear Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911971#M1031298</link>
      <description>&lt;P&gt;Dear Marvin,&lt;/P&gt;
&lt;P&gt;the realm issue solved by changing the Base DN path once I changed the path the users were able to download.&lt;/P&gt;
&lt;P&gt;But for the Access Control policies, can u give a base idea how the access control policies are build ?? I want to keep Intrusion policy as a default becz I am controlling everything from firewall ijust wanted a malware, application, url , security intelligence, file filtering to be configured.&lt;/P&gt;
&lt;P&gt;Please correct me if I am wrong. Rule 3 will never match ,,, users will not match this rule becz this rule has to be splitted by 2 different rules&amp;nbsp;application filter rule for all user &amp;nbsp;and url filter separate rule for all user.&lt;/P&gt;
&lt;P&gt;Rule 3:&amp;nbsp; action allow,, zone: inside to outside, source : any destination: any ,, user : USER-ALL url : specific url category application filter: bittorrent block&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="color: #ff0000;"&gt;Result:&lt;/SPAN&gt;&amp;nbsp; no match and traffic will be send to default intrusion policy rule.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2016 19:14:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911971#M1031298</guid>
      <dc:creator>clark white</dc:creator>
      <dc:date>2016-04-18T19:14:53Z</dc:date>
    </item>
    <item>
      <title>I din't really think of them</title>
      <link>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911972#M1031304</link>
      <description>&lt;P&gt;I din't really think of them as a whole set.&lt;/P&gt;
&lt;P&gt;You're right - you need to order them most specific to least specific and consider that the first match will end the rule processing.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Apr 2016 19:51:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911972#M1031304</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2016-04-18T19:51:43Z</dc:date>
    </item>
    <item>
      <title>Dear Marvin,</title>
      <link>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911973#M1031309</link>
      <description>&lt;P&gt;Dear Marvin,&lt;/P&gt;
&lt;P&gt;I am confuse little to create access policies,below are my thought to create a policies by order ,so please correct me if i am doing wrong.&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;zone: inside to outside&amp;nbsp; users: all ,,application: bittorrent&amp;nbsp; block:all&lt;/LI&gt;
&lt;LI&gt;zone: inside to outside&amp;nbsp; users: HOD ,,application: all&amp;nbsp; allow :all&lt;/LI&gt;
&lt;LI&gt;zone: inside to outside&amp;nbsp; users: managers &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; permit: all&lt;/LI&gt;
&lt;LI&gt;zone: inside to outside&amp;nbsp; users: head of dep&amp;nbsp;&amp;nbsp;&amp;nbsp; permit : youtube and other good website.&lt;/LI&gt;
&lt;LI&gt;zone: inside to outside&amp;nbsp; users: all ,,application: instant mesagging,etc etc&amp;nbsp; block:all&lt;/LI&gt;
&lt;LI&gt;zone: inside to outside&amp;nbsp; users: all &amp;nbsp;&amp;nbsp; block : pornography,abortion,gambling&lt;/LI&gt;
&lt;LI&gt;zone: inside to outside&amp;nbsp; users: all&amp;nbsp;&amp;nbsp;&amp;nbsp; permit: categories ( which are not blocked in rule 4)&lt;/LI&gt;
&lt;LI&gt;zone: inside to other zones&amp;nbsp; Network: source&amp;nbsp; Internal Network &amp;nbsp; destination other private networks for other companies on firewall users: any&amp;nbsp; port: any &amp;nbsp; block: permit&lt;/LI&gt;
&lt;LI&gt;zone: inside to outside&amp;nbsp; Network: Internal Network&amp;nbsp; users: non corporate users&amp;nbsp;&amp;nbsp; port: any &amp;nbsp; block: all&lt;/LI&gt;
&lt;LI&gt;Default action: Intrusion policy.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Apr 2016 04:20:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/users-in-access-control-policies/m-p/2911973#M1031309</guid>
      <dc:creator>clark white</dc:creator>
      <dc:date>2016-04-25T04:20:12Z</dc:date>
    </item>
  </channel>
</rss>

