<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic The Sourcefire User Agent in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/sourcefire-user-agent/m-p/2683923#M1038211</link>
    <description>&lt;P&gt;The Sourcefire User Agent collects IP-user associations from your AD server.&lt;/P&gt;&lt;P&gt;The LDAP connection allows you to use AD (or LDAP) group membership in your policies.&lt;/P&gt;&lt;P&gt;Defense Center (DC) = old name for FireSIGHT Management Center (FMC). The old DC name is still referenced in much documentation.&lt;/P&gt;&lt;P&gt;FirePOWER = general brand name for the Sourcefire technology as implemented in Cisco's product line.&lt;/P&gt;&lt;P&gt;A sensor generally refers to a dedicated appliance (or VM) running only the FirePOWER NGIPS/NGFW technology.&lt;/P&gt;&lt;P&gt;ASA with FirePOWER services refers to a software module (module type = "sfr") running in addition to the base ASA software on an ASA platform. (On the 5585-X this is a dedicated hardware module.)&lt;/P&gt;</description>
    <pubDate>Tue, 07 Jul 2015 15:36:42 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2015-07-07T15:36:42Z</dc:date>
    <item>
      <title>Sourcefire User Agent</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-user-agent/m-p/2683922#M1038202</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is role of Sourcefire User Agent on Active Directory,(is it required?)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When we connect Sourcefire defense center to AD, we need to create LDAP Connection &amp;nbsp;what exactly Ldap does in this Scenario&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Confusion between Defense center vs firepower vs firesight vs sensor vs ASA with firepower servcies?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:43:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-user-agent/m-p/2683922#M1038202</guid>
      <dc:creator>shubhamkulkarni39</dc:creator>
      <dc:date>2019-03-12T12:43:10Z</dc:date>
    </item>
    <item>
      <title>The Sourcefire User Agent</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-user-agent/m-p/2683923#M1038211</link>
      <description>&lt;P&gt;The Sourcefire User Agent collects IP-user associations from your AD server.&lt;/P&gt;&lt;P&gt;The LDAP connection allows you to use AD (or LDAP) group membership in your policies.&lt;/P&gt;&lt;P&gt;Defense Center (DC) = old name for FireSIGHT Management Center (FMC). The old DC name is still referenced in much documentation.&lt;/P&gt;&lt;P&gt;FirePOWER = general brand name for the Sourcefire technology as implemented in Cisco's product line.&lt;/P&gt;&lt;P&gt;A sensor generally refers to a dedicated appliance (or VM) running only the FirePOWER NGIPS/NGFW technology.&lt;/P&gt;&lt;P&gt;ASA with FirePOWER services refers to a software module (module type = "sfr") running in addition to the base ASA software on an ASA platform. (On the 5585-X this is a dedicated hardware module.)&lt;/P&gt;</description>
      <pubDate>Tue, 07 Jul 2015 15:36:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-user-agent/m-p/2683923#M1038211</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-07-07T15:36:42Z</dc:date>
    </item>
    <item>
      <title>Hi marvin,Thanks,I am facing</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-user-agent/m-p/2683924#M1038218</link>
      <description>&lt;P&gt;Hi marvin,&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;I am facing major&amp;nbsp;issue in Sourcefire User agent, we want to integrate AD with Sourcefire,&lt;/P&gt;&lt;P&gt;We added Ldap Connection in Sourcefire, that successfully added,&lt;/P&gt;&lt;P&gt;we tried to install User agent on AD, but there was requirement for .net framework and sql, we installed and run User agent,&amp;nbsp;&lt;/P&gt;&lt;P&gt;now User agent is installed, but when we try to connect with AD, fill all parameters Server IP, Domain, User name , Password, but there was continues error showing there was a error connecting to server, please check user name password and permission (1),&lt;/P&gt;&lt;P&gt;we have done DCOM, WMI, RPC seetings in AD, but still problem exists,&lt;/P&gt;&lt;P&gt;Exact error is:&amp;nbsp;Authentication Error connecting to AD IP address&lt;BR /&gt;System.UnauthorizedAccessException: Access is denied. (Exception from HRESULT: 0x80070005 (E_ACCESSDENIED))&lt;BR /&gt;&amp;nbsp; &amp;nbsp;at System.Management.ThreadDispatch.Start()&lt;BR /&gt;&amp;nbsp; &amp;nbsp;at System.Management.ManagementScope.Initialize()&lt;BR /&gt;&amp;nbsp; &amp;nbsp;at Tools.Troubleshooter.testADServerConnection()Unable to determine AD Server's OS. - 1&lt;/P&gt;&lt;P&gt;Can you help me for the same!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Jul 2015 17:34:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-user-agent/m-p/2683924#M1038218</guid>
      <dc:creator>shubhamkulkarni39</dc:creator>
      <dc:date>2015-07-08T17:34:19Z</dc:date>
    </item>
    <item>
      <title>If you are installing it on a</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-user-agent/m-p/2683925#M1038232</link>
      <description>&lt;P&gt;If you are installing it on a DC you need to reference the local DC as "localhost" in the Servername/Address field.&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2015 18:26:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-user-agent/m-p/2683925#M1038232</guid>
      <dc:creator>nrunge1</dc:creator>
      <dc:date>2015-07-15T18:26:31Z</dc:date>
    </item>
    <item>
      <title>We have done that,Actually we</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-user-agent/m-p/2683926#M1038238</link>
      <description>&lt;P&gt;We have done that,&lt;/P&gt;&lt;P&gt;Actually we are installing user agent on machine,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2015 05:11:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-user-agent/m-p/2683926#M1038238</guid>
      <dc:creator>shubhamkulkarni39</dc:creator>
      <dc:date>2015-07-16T05:11:31Z</dc:date>
    </item>
    <item>
      <title>I had zero luck using a</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-user-agent/m-p/2683927#M1038245</link>
      <description>&lt;P&gt;I had zero luck using a remote host. It seems that there is a better success rate using the Domain Controllers themselves. However if you are forced to use a remote host for some reason.&lt;/P&gt;&lt;P&gt;Try following the following article. You may have done DCOM and WMI but you may also need a group policy so that your service account can manage auditing and security logs.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118637-configure-firesight-00.html&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Beyond that open up a case with TAC and hope for the best. The agent is complete garbage though.&amp;nbsp;&lt;/P&gt;&lt;P&gt;It hasn't been updated since 2013 according to the Cisco website. This is what Cisco does. They stop development on acquisitions while they develop something better. Current customers get worked over while sales keeps the features on for brochure compliance.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2015 14:13:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-user-agent/m-p/2683927#M1038245</guid>
      <dc:creator>nrunge1</dc:creator>
      <dc:date>2015-07-16T14:13:49Z</dc:date>
    </item>
    <item>
      <title>we have done group policy</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-user-agent/m-p/2683928#M1038249</link>
      <description>&lt;P&gt;we have done group policy stuff,&lt;/P&gt;&lt;P&gt;I forgot to tell you that&amp;nbsp;we are facing issue in WMI,&lt;/P&gt;&lt;P&gt;Win32_Processor: WMI: Access denied&lt;/P&gt;&lt;P&gt;Win32_WMISetting: Successful&lt;/P&gt;&lt;P&gt;Security information: Successful&lt;/P&gt;&lt;P&gt;Win32_OperatingSystem: WMI: Access denied,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This is the reason we are facing issue in Sourcefire user agent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 05:11:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-user-agent/m-p/2683928#M1038249</guid>
      <dc:creator>shubhamkulkarni39</dc:creator>
      <dc:date>2015-07-17T05:11:54Z</dc:date>
    </item>
    <item>
      <title>At this point I would open up</title>
      <link>https://community.cisco.com/t5/network-security/sourcefire-user-agent/m-p/2683929#M1038252</link>
      <description>&lt;P&gt;At this point I would open up a case with TAC. I opened one two days ago with a similar issue and we were able to resolve it this morning.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 17 Jul 2015 15:56:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/sourcefire-user-agent/m-p/2683929#M1038252</guid>
      <dc:creator>nrunge1</dc:creator>
      <dc:date>2015-07-17T15:56:40Z</dc:date>
    </item>
  </channel>
</rss>

