<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC External Authentication Failing in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-external-authentication-failing/m-p/4066733#M1069212</link>
    <description>&lt;P&gt;So i figured out the first issue and I'm now able to successfully test using ldap after changing the base dn to , but if i try to use ldaps it fails.&amp;nbsp; I have the cert from the server exported as a base 64 file and when i try to browse and upload it is takes the setting but if I save it the settings save but the cert disappears when you go back in.&amp;nbsp; Is there a requirement that I'm missing in order to get LDAPS for the external authentication?&lt;/P&gt;</description>
    <pubDate>Wed, 15 Apr 2020 20:39:27 GMT</pubDate>
    <dc:creator>mumbles202</dc:creator>
    <dc:date>2020-04-15T20:39:27Z</dc:date>
    <item>
      <title>FMC External Authentication Failing</title>
      <link>https://community.cisco.com/t5/network-security/fmc-external-authentication-failing/m-p/4066632#M1069211</link>
      <description>&lt;P&gt;I'm trying to setup external authentication for a 6.5 FMC but running into some issues.&amp;nbsp; Currently the FMC has LDAP authentication setup for AnyConnect connectivity, and if i try to Fetch DNs or Fetch Attrib those both return values, but when I try to test a user that I know is in the group by domain\user1 or just entering user1 it fails.&amp;nbsp; Active Directory is 2016.&amp;nbsp; I'm currently using the following settings:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Base Dn - dc=domain,dc=local&lt;/P&gt;&lt;P&gt;UI Access Attribute - sAMAccountName&lt;BR /&gt;Shell Access Attribute - sAMAccountName&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Administrator - CN=ftdaccess,OU=Security Groups,DC=domain,DC=local&lt;BR /&gt;Group Member Attribute - memberOf (I also tried just member w/ the same results)&lt;BR /&gt;Shell Access Filter - Same as Base Filter is checked&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I expand the test results i do see the following:&lt;/P&gt;&lt;P&gt;The server query size limit was exceeded. Use the Base Filter to reduce the number of records retrieved.&lt;BR /&gt;See Test Output for details.&lt;BR /&gt;Error&lt;BR /&gt;Test Failed: The search for your test user using your current parameters failed; please verify your authentication settings and test user credentials.&lt;BR /&gt;External Authentication Object&lt;BR /&gt;Authentication Method&lt;BR /&gt;CAC Use for CAC authentication and authorization&lt;BR /&gt;Name&lt;BR /&gt;LDAP&lt;BR /&gt;Description&lt;BR /&gt;LDAP Authentication FMC&lt;BR /&gt;Server Type&lt;BR /&gt;Primary Server&lt;BR /&gt;Host Name/IP Address&lt;BR /&gt;172.16.20.25&lt;BR /&gt;ex. IP or hostname&lt;BR /&gt;Port&lt;BR /&gt;389&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The test user in question is a member of 2 groups (Domain Users and&amp;nbsp;ftdaccess).&amp;nbsp; Should I set the base DN to a path that mirrors the OU that members of the group should be limited to?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 18:12:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-external-authentication-failing/m-p/4066632#M1069211</guid>
      <dc:creator>mumbles202</dc:creator>
      <dc:date>2020-04-15T18:12:35Z</dc:date>
    </item>
    <item>
      <title>Re: FMC External Authentication Failing</title>
      <link>https://community.cisco.com/t5/network-security/fmc-external-authentication-failing/m-p/4066733#M1069212</link>
      <description>&lt;P&gt;So i figured out the first issue and I'm now able to successfully test using ldap after changing the base dn to , but if i try to use ldaps it fails.&amp;nbsp; I have the cert from the server exported as a base 64 file and when i try to browse and upload it is takes the setting but if I save it the settings save but the cert disappears when you go back in.&amp;nbsp; Is there a requirement that I'm missing in order to get LDAPS for the external authentication?&lt;/P&gt;</description>
      <pubDate>Wed, 15 Apr 2020 20:39:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-external-authentication-failing/m-p/4066733#M1069212</guid>
      <dc:creator>mumbles202</dc:creator>
      <dc:date>2020-04-15T20:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: FMC External Authentication Failing</title>
      <link>https://community.cisco.com/t5/network-security/fmc-external-authentication-failing/m-p/4904601#M1103418</link>
      <description>&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firepower-ngfw/215538-configure-firepower-management-center-an.pdf" target="_blank"&gt;Configure Firepower Management Center and FTD with LDAP for External Authentication (cisco.com)&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Aug 2023 14:14:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-external-authentication-failing/m-p/4904601#M1103418</guid>
      <dc:creator>williams_t82</dc:creator>
      <dc:date>2023-08-14T14:14:00Z</dc:date>
    </item>
  </channel>
</rss>

