<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Difference between &amp;quot;user-identity domain&amp;quot; &amp;amp; &amp;quot;user-identity default-domain&amp;quot; in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/difference-between-quot-user-identity-domain-quot-amp-quot-user/m-p/4042149#M1067497</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; When you define a "user-identity-domain" you link it to a pre-defined AAA LDAP servers, and this feature is used for user-group mapping polling:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa-server FIRST_DOMAIN protocol ldap&lt;/P&gt;&lt;P&gt;aaa-server (INSIDE) FIRST_DOMAIN host 10.10.10.10&lt;/P&gt;&lt;P&gt;&amp;nbsp; ldap-base-dn dc=colocvium,dc=com&lt;/P&gt;&lt;P&gt;&amp;nbsp;!&lt;/P&gt;&lt;P&gt;aaa-server SECOND_DOMAIN protocol ldap&lt;/P&gt;&lt;P&gt;aaa-server (INSIDE) SECOND_DOMAIN host 20.20.20.20&lt;/P&gt;&lt;P&gt;&amp;nbsp;ldap-base-dn dc=cisco,dc=com&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&amp;nbsp; When you configure the identity-based rules in your ACL, if you fail/forget to specify also the domain name for the user, it will pick up the configured domain from "user-identity default-domain", which by default is LOCAL (meaning the LOCAL user database); this is the scope of this command. If you want to change it from the default of "LOCAL" to something custom, it needs to be one of the domain previously configured via the aaa-server protocol ldap commands, otherwise it gives an error, which makes sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 07 Mar 2020 12:12:52 GMT</pubDate>
    <dc:creator>Cristian Matei</dc:creator>
    <dc:date>2020-03-07T12:12:52Z</dc:date>
    <item>
      <title>Difference between "user-identity domain" &amp; "user-identity default-domain"</title>
      <link>https://community.cisco.com/t5/network-security/difference-between-quot-user-identity-domain-quot-amp-quot-user/m-p/4042073#M1067486</link>
      <description>&lt;P&gt;Hi Experts,&lt;/P&gt;&lt;P&gt;ASA configuration guide lists both "user-identity domain" and "user-identity default-domain" in relations to a single identity-firewall configuration, often with same "nickname" and "NETBIOS_name" respectively, (IMO) without clarifying the specifics of each commands.&lt;/P&gt;&lt;P&gt;What does each command do, and are they independent of each other?&lt;/P&gt;&lt;P&gt;R's, Alex&lt;/P&gt;</description>
      <pubDate>Sat, 07 Mar 2020 04:46:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/difference-between-quot-user-identity-domain-quot-amp-quot-user/m-p/4042073#M1067486</guid>
      <dc:creator>AlexFer</dc:creator>
      <dc:date>2020-03-07T04:46:08Z</dc:date>
    </item>
    <item>
      <title>Re: Difference between "user-identity domain" &amp; "user-identity default-domain"</title>
      <link>https://community.cisco.com/t5/network-security/difference-between-quot-user-identity-domain-quot-amp-quot-user/m-p/4042149#M1067497</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; When you define a "user-identity-domain" you link it to a pre-defined AAA LDAP servers, and this feature is used for user-group mapping polling:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;aaa-server FIRST_DOMAIN protocol ldap&lt;/P&gt;&lt;P&gt;aaa-server (INSIDE) FIRST_DOMAIN host 10.10.10.10&lt;/P&gt;&lt;P&gt;&amp;nbsp; ldap-base-dn dc=colocvium,dc=com&lt;/P&gt;&lt;P&gt;&amp;nbsp;!&lt;/P&gt;&lt;P&gt;aaa-server SECOND_DOMAIN protocol ldap&lt;/P&gt;&lt;P&gt;aaa-server (INSIDE) SECOND_DOMAIN host 20.20.20.20&lt;/P&gt;&lt;P&gt;&amp;nbsp;ldap-base-dn dc=cisco,dc=com&lt;/P&gt;&lt;P&gt;!&lt;/P&gt;&lt;P&gt;&amp;nbsp; When you configure the identity-based rules in your ACL, if you fail/forget to specify also the domain name for the user, it will pick up the configured domain from "user-identity default-domain", which by default is LOCAL (meaning the LOCAL user database); this is the scope of this command. If you want to change it from the default of "LOCAL" to something custom, it needs to be one of the domain previously configured via the aaa-server protocol ldap commands, otherwise it gives an error, which makes sense.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Cristian Matei.&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Mar 2020 12:12:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/difference-between-quot-user-identity-domain-quot-amp-quot-user/m-p/4042149#M1067497</guid>
      <dc:creator>Cristian Matei</dc:creator>
      <dc:date>2020-03-07T12:12:52Z</dc:date>
    </item>
  </channel>
</rss>

