<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic hi,

did you solve this? in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ad-firesight-integration/m-p/2786419#M1033415</link>
    <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;did you solve this?&lt;/P&gt;</description>
    <pubDate>Fri, 24 Mar 2017 21:51:40 GMT</pubDate>
    <dc:creator>Jose Carlos Sm de Lima</dc:creator>
    <dc:date>2017-03-24T21:51:40Z</dc:date>
    <item>
      <title>AD &amp; FireSIGHT Integration</title>
      <link>https://community.cisco.com/t5/network-security/ad-firesight-integration/m-p/2786414#M1033407</link>
      <description>&lt;P&gt;Hello all&lt;BR /&gt;in my company we have ASA 5545 with firepower module on&lt;BR /&gt;we made integration between the AD and the firesight. also we have clearpass and we integrate the AD with the AD to force raduice to all users from domain&lt;BR /&gt;the case now any user login from a device joined the domain events recorded everything by the username, but if come from other device not joined&lt;BR /&gt;the domain but go throw the radius and the radius authenticate from AD , why i dont see his name , i only get his IP&lt;/P&gt;
&lt;P&gt;where is the problem in my case&lt;/P&gt;
&lt;P&gt;should i look more at clearpass config , or it related to AD or to the firesight ?&lt;/P&gt;
&lt;P&gt;help ASAP&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:48:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ad-firesight-integration/m-p/2786414#M1033407</guid>
      <dc:creator>MuhammadEisa</dc:creator>
      <dc:date>2019-03-12T12:48:32Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/ad-firesight-integration/m-p/2786415#M1033409</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I dont think it will be Firesight , but to confirm you can first check the AD event logs and search for&amp;nbsp; that username ,check if you see the LOGON event corresponding to it. If yes then you can check the User agent logs and check the same. If User agent polls the username then User agent will foward the same thing to the Firesight Manager.&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Aastha Bhardwaj&lt;/P&gt;
&lt;P&gt;Rate&amp;nbsp; if that helps!!!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Nov 2015 18:15:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ad-firesight-integration/m-p/2786415#M1033409</guid>
      <dc:creator>Aastha Bhardwaj</dc:creator>
      <dc:date>2015-11-04T18:15:35Z</dc:date>
    </item>
    <item>
      <title>after checking the log file i</title>
      <link>https://community.cisco.com/t5/network-security/ad-firesight-integration/m-p/2786416#M1033411</link>
      <description>&lt;P&gt;after checking the log file i found&lt;/P&gt;
&lt;P&gt;Checking x.x.x.x for user momo @x Failed. Does admin have permission to see all processes on x.x.x.x&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;this log for non domain labtop, but auth by the clearpass radius&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- logoff memo@x (x.x.x.x)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Checking x.x.x.x for user memo@x. Found &lt;/P&gt;
&lt;P&gt;this log for&amp;nbsp; joined domain device&lt;/P&gt;
&lt;P&gt;so now is the problem related to the user i use to auth with the domain on asa&lt;BR /&gt;or it related to the domain it self that it cant resolve the non domain devices&lt;BR /&gt;it can resolve the joined domain perfect , so&lt;BR /&gt;is someone face this problem before ?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Nov 2015 09:17:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ad-firesight-integration/m-p/2786416#M1033411</guid>
      <dc:creator>MuhammadEisa</dc:creator>
      <dc:date>2015-11-07T09:17:51Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/ad-firesight-integration/m-p/2786417#M1033413</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I would recommend you to open up a case with Cisco TAC because we would need to check a few things before jumping on some conclusion.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Aastha Bhardwaj&lt;/P&gt;
&lt;P&gt;Rate if that helps!!!&lt;/P&gt;</description>
      <pubDate>Mon, 09 Nov 2015 22:02:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ad-firesight-integration/m-p/2786417#M1033413</guid>
      <dc:creator>Aastha Bhardwaj</dc:creator>
      <dc:date>2015-11-09T22:02:19Z</dc:date>
    </item>
    <item>
      <title>i will check and update here</title>
      <link>https://community.cisco.com/t5/network-security/ad-firesight-integration/m-p/2786418#M1033414</link>
      <description>&lt;P&gt;i will check and update here&lt;/P&gt;</description>
      <pubDate>Tue, 10 Nov 2015 13:42:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ad-firesight-integration/m-p/2786418#M1033414</guid>
      <dc:creator>MuhammadEisa</dc:creator>
      <dc:date>2015-11-10T13:42:09Z</dc:date>
    </item>
    <item>
      <title>hi,

did you solve this?</title>
      <link>https://community.cisco.com/t5/network-security/ad-firesight-integration/m-p/2786419#M1033415</link>
      <description>&lt;P&gt;hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;did you solve this?&lt;/P&gt;</description>
      <pubDate>Fri, 24 Mar 2017 21:51:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ad-firesight-integration/m-p/2786419#M1033415</guid>
      <dc:creator>Jose Carlos Sm de Lima</dc:creator>
      <dc:date>2017-03-24T21:51:40Z</dc:date>
    </item>
  </channel>
</rss>

