<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Discovery Users within Firepower in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4094603#M1070584</link>
    <description>&lt;P&gt;Does the identity policy need to be configured on an ACP as well?&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 29 May 2020 19:05:36 GMT</pubDate>
    <dc:creator>Scott_22</dc:creator>
    <dc:date>2020-05-29T19:05:36Z</dc:date>
    <item>
      <title>Discovery Users within Firepower</title>
      <link>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4094469#M1070570</link>
      <description>&lt;P&gt;I'm am attempting to discover users within our infrastructure through a network discovery policy, but the FMC doesn't seem to discover anyone. I have a network discovery policy configured to detect users, hosts, and applications. Do I also need an identity policy mapped to a realm? Can the users be discovered via pxGrid with ISE?&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 15:54:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4094469#M1070570</guid>
      <dc:creator>Scott_22</dc:creator>
      <dc:date>2020-05-29T15:54:46Z</dc:date>
    </item>
    <item>
      <title>Re: Discovery Users within Firepower</title>
      <link>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4094544#M1070578</link>
      <description>&lt;P&gt;Dear Scott,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For getting the user details on Cisco FMC , you need to integrate your FMC with AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please follow the below steps&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;++Configure user discovery on your network discovery policy for RFC1918&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;++Integrate FMC with AD using realm&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;++Download the user details from AD to FMC under Realm user download section&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;++Configure identity policy with passive authentication.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;once this is successful, you should be able to see the user group details on ACP rule on user tab.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For user to IP mapping , you can use useragent. Please note user agent support is only till 6.6.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For user-agent integration, you can refer the below link.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/200329-Configure-Active-Directory-Integration-w.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/asa-firepower-services/200329-Configure-Active-Directory-Integration-w.html&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please rate if this is helpful to you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Regards&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Shine Sudheesh&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 17:34:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4094544#M1070578</guid>
      <dc:creator>ShineSudheesh</dc:creator>
      <dc:date>2020-05-29T17:34:05Z</dc:date>
    </item>
    <item>
      <title>Re: Discovery Users within Firepower</title>
      <link>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4094603#M1070584</link>
      <description>&lt;P&gt;Does the identity policy need to be configured on an ACP as well?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 19:05:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4094603#M1070584</guid>
      <dc:creator>Scott_22</dc:creator>
      <dc:date>2020-05-29T19:05:36Z</dc:date>
    </item>
    <item>
      <title>Re: Discovery Users within Firepower</title>
      <link>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4094634#M1070588</link>
      <description>No really, you do the AD integration, and then on the ACP what you do is to pull the users/groups to build your Policy.</description>
      <pubDate>Fri, 29 May 2020 20:05:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4094634#M1070588</guid>
      <dc:creator>Maykol Rojas</dc:creator>
      <dc:date>2020-05-29T20:05:27Z</dc:date>
    </item>
    <item>
      <title>Re: Discovery Users within Firepower</title>
      <link>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4094636#M1070589</link>
      <description>&lt;P&gt;Yes .You need to associate the identity policy with an access control policy to allow or block selected users from accessing specified resources.&lt;/P&gt;</description>
      <pubDate>Fri, 29 May 2020 20:11:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4094636#M1070589</guid>
      <dc:creator>sreejith_r</dc:creator>
      <dc:date>2020-05-29T20:11:15Z</dc:date>
    </item>
    <item>
      <title>Re: Discovery Users within Firepower</title>
      <link>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4095178#M1070616</link>
      <description>&lt;P&gt;My questions is solely focused on network discovery. To discover users, does the Identity policy need to be applied anywhere? I know the realm obviously needs to be applied to the Identity Policy, but want to confirm that is all that is needed. End goal is to view users and their account names within analysis.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 31 May 2020 21:04:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4095178#M1070616</guid>
      <dc:creator>Scott_22</dc:creator>
      <dc:date>2020-05-31T21:04:47Z</dc:date>
    </item>
    <item>
      <title>Re: Discovery Users within Firepower</title>
      <link>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4095235#M1070622</link>
      <description>&lt;P&gt;Passive user discovery will only tell you a small part of the story that can be gleaned from observing information transiting the device in clear text.&lt;/P&gt;
&lt;P&gt;For best results use ISE via pxGrid. Of course that assumes users are being required to authenticate via network access control that ISE is enforcing and that ISE is linked to your identity source (typically AD).&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2020 03:46:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4095235#M1070622</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-06-01T03:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: Discovery Users within Firepower</title>
      <link>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4095478#M1070633</link>
      <description>&lt;P&gt;Assuming users are authenticating via ISE and pxGrid is configured, what are the steps to discover users? If pxGrid is configured are users automatically synced with the FMC?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2020 13:16:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4095478#M1070633</guid>
      <dc:creator>Scott_22</dc:creator>
      <dc:date>2020-06-01T13:16:39Z</dc:date>
    </item>
    <item>
      <title>Re: Discovery Users within Firepower</title>
      <link>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4095508#M1070637</link>
      <description>&lt;P&gt;The FMC is a subscriber to the session information coming from ISE via pxGrid. So - yes, the synchronization happens automatically for users' ISE authentication info (username and IP address) to be communicated to FMC&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2020 14:21:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4095508#M1070637</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2020-06-01T14:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: Discovery Users within Firepower</title>
      <link>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4095528#M1070640</link>
      <description>&lt;P&gt;Okay, so an ACE is not needed in the ACP to simply discover information about a users session? Based on this document, it mentions the following:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;SPAN&gt;The FMC may download all the users and IP address bindings to its heart’s content, but none of the data that is downloaded will be used in the policy until there is a realm configured to determine which groups and users to use in the firewall policies.....&lt;/SPAN&gt;&lt;SPAN&gt;The realm is now fully configured for rule creation, along with the pxGrid integration for learning what IP addresses belong to which users and devices. Now you are ready to add identity information to the access policy rules in the FMC."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So the 2nd step of adding the identity policy to an ACP is not required for discovery only?&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://www.ciscopress.com/articles/article.asp?p=2963461&amp;amp;seqNum=2" target="_blank"&gt;https://www.ciscopress.com/articles/article.asp?p=2963461&amp;amp;seqNum=2&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2020 14:49:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/discovery-users-within-firepower/m-p/4095528#M1070640</guid>
      <dc:creator>Scott_22</dc:creator>
      <dc:date>2020-06-01T14:49:55Z</dc:date>
    </item>
  </channel>
</rss>

