<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic FirePower1010 Identity Source unknown error in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4172500#M1075085</link>
    <description>&lt;P&gt;&lt;FONT&gt;I am trying to add an identity source and fill in all the fields. But the test failed:&lt;BR /&gt;"Cannot connect to realm for Identity policies. Message returned: The connection test failed with an unknown error."&lt;BR /&gt;Domain controller is available from FirePower, telnet on 389 port is successfully.&lt;BR /&gt;Software is&amp;nbsp; 6.6.0.1-7.&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;What can be wrong?&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 23 Oct 2020 11:00:22 GMT</pubDate>
    <dc:creator>ratemaki</dc:creator>
    <dc:date>2020-10-23T11:00:22Z</dc:date>
    <item>
      <title>FirePower1010 Identity Source unknown error</title>
      <link>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4172500#M1075085</link>
      <description>&lt;P&gt;&lt;FONT&gt;I am trying to add an identity source and fill in all the fields. But the test failed:&lt;BR /&gt;"Cannot connect to realm for Identity policies. Message returned: The connection test failed with an unknown error."&lt;BR /&gt;Domain controller is available from FirePower, telnet on 389 port is successfully.&lt;BR /&gt;Software is&amp;nbsp; 6.6.0.1-7.&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;What can be wrong?&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 11:00:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4172500#M1075085</guid>
      <dc:creator>ratemaki</dc:creator>
      <dc:date>2020-10-23T11:00:22Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower1010 Identity Source unknown error</title>
      <link>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4172724#M1075100</link>
      <description>Are you able to resolve the domain name from firepower? Also, are you&lt;BR /&gt;adding it to firepower as domain controller or ldap server. If ldap server&lt;BR /&gt;then test is expected to fail. Try it as domain controller.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;***** please  remember to rate useful posts&lt;BR /&gt;</description>
      <pubDate>Fri, 23 Oct 2020 17:36:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4172724#M1075100</guid>
      <dc:creator>Mohammed al Baqari</dc:creator>
      <dc:date>2020-10-23T17:36:02Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower1010 Identity Source unknown error</title>
      <link>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4172731#M1075101</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;I have been trying to do the same but ive read that identity policies uses the Management port. So if you still want to manage the FDM then you need a switch between the DC &amp;amp; MGMT.&lt;/P&gt;&lt;P&gt;Firepower MGMT -&amp;gt; Switch -&amp;gt; DC. But config the switch so you can access the FPR MGMT from another port on the switch. Also, setting a Data Interface for "Management Only" doesnt work either. (Didnt for me).&lt;/P&gt;&lt;P&gt;Though in my situation above wasnt a option so I let this go. &lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 17:39:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4172731#M1075101</guid>
      <dc:creator>S3C</dc:creator>
      <dc:date>2020-10-23T17:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower1010 Identity Source unknown error</title>
      <link>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4172735#M1075102</link>
      <description>&lt;P&gt;Yes, domain name resolves from firepower.&lt;/P&gt;&lt;P&gt;And I added it as domain controller. I can add it only as AD but not as LDAP.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 17:58:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4172735#M1075102</guid>
      <dc:creator>ratemaki</dc:creator>
      <dc:date>2020-10-23T17:58:59Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower1010 Identity Source unknown error</title>
      <link>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4172747#M1075104</link>
      <description>&lt;P&gt;Domain controller is able from&amp;nbsp;Management Interface firepower.&lt;/P&gt;&lt;P&gt;There is not ip adress on the&amp;nbsp;diagnostic interface but it is up and mode is routed.&lt;/P&gt;&lt;P&gt;I use Device manager to configure firepower and this menu doesn't exist: "&lt;SPAN&gt;Firepower MGMT -&amp;gt; Switch -&amp;gt; DC.&lt;/SPAN&gt;"&lt;/P&gt;</description>
      <pubDate>Fri, 23 Oct 2020 18:05:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4172747#M1075104</guid>
      <dc:creator>ratemaki</dc:creator>
      <dc:date>2020-10-23T18:05:56Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower1010 Identity Source unknown error</title>
      <link>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4173205#M1075131</link>
      <description>&lt;P&gt;Did you test the policy? or you just tried the configuration test? I've seen a few times the test failing but actually the connectivity between the AD the and device is working.&lt;/P&gt;</description>
      <pubDate>Sun, 25 Oct 2020 12:38:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4173205#M1075131</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2020-10-25T12:38:07Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower1010 Identity Source unknown error</title>
      <link>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4173569#M1075184</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/284594"&gt;@Aref Alsouqi&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;&lt;P&gt;Did you test the policy? or you just tried the configuration test? I've seen a few times the test failing but actually the connectivity between the AD the and device is working.&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yes, I tried to add the group of domain users in policy but there was just only "name_of_Identity\all users".&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 10:28:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4173569#M1075184</guid>
      <dc:creator>ratemaki</dc:creator>
      <dc:date>2020-10-26T10:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower1010 Identity Source unknown error</title>
      <link>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4173895#M1075216</link>
      <description>&lt;P&gt;Never tried the all users before, I would try to specify the groups, and try again.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2020 18:32:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4173895#M1075216</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2020-10-26T18:32:40Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower1010 Identity Source unknown error</title>
      <link>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4174211#M1075234</link>
      <description>&lt;P&gt;I created the policy in access control: Source Zone - Inside zone, Destination Zone - Outside Zone, Users - "name_of_Identity\test_group_users".&lt;BR /&gt;But there are no hits in this policy.&lt;/P&gt;&lt;P&gt;And reason is added users in policy. Without users the policy is working.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Oct 2020 09:59:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4174211#M1075234</guid>
      <dc:creator>ratemaki</dc:creator>
      <dc:date>2020-10-27T09:59:24Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower1010 Identity Source unknown error</title>
      <link>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4175367#M1075289</link>
      <description>&lt;P&gt;How did you configure the identity policy on the FTD? the FTD needs to build up the user to IP addresses mapping before the user based policy can work.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Oct 2020 19:29:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4175367#M1075289</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2020-10-28T19:29:33Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower1010 Identity Source unknown error</title>
      <link>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4175772#M1075304</link>
      <description>&lt;P&gt;The identity policy settings are in attachment sreen.&amp;nbsp;AD Identity Source is&amp;nbsp;Identity Realm (AD)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How can I mapping users to IPs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Actually, I need to use access control rule and implement it by group of domain users and see the activity domain users in log also.&lt;/P&gt;&lt;P&gt;But could be I do something wrong.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 12:46:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4175772#M1075304</guid>
      <dc:creator>ratemaki</dc:creator>
      <dc:date>2020-10-29T12:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: FirePower1010 Identity Source unknown error</title>
      <link>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4176187#M1075333</link>
      <description>&lt;P&gt;As far as I know there would not be a manual way to build up the users to IP mapping. That is something the Firepower builds up by using the identity policy and identity sources such as ISE or AnyConnect for passive authentication. In your case, I see you configured AnyConnect with passive authentication. If there is no AnyConnect users activity to allow the Firepower to build up the mapping database, the access control policy using the AD realm would not work. That's because the Firepower would not have the user to IP mapping created, so it won't be able to match or imply any security rule on the realm users.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 23:36:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower1010-identity-source-unknown-error/m-p/4176187#M1075333</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2020-10-29T23:36:21Z</dc:date>
    </item>
  </channel>
</rss>

