<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Access Control Policy Blocking Sites targeting Active Directory Us in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4632791#M1090971</link>
    <description>&lt;P&gt;I suspect the issue is that you are using passive authentication, and the FTD is having issues authenticating the user with this method.&amp;nbsp; If you use active authentication with captive portal are you able to match the access rule?&lt;/P&gt;
&lt;P&gt;Refer to this link if you want to continue to use passive authentication:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/control_users_with_ts_agent.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/control_users_with_ts_agent.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 16 Jun 2022 04:59:08 GMT</pubDate>
    <dc:creator>Marius Gunnerud</dc:creator>
    <dc:date>2022-06-16T04:59:08Z</dc:date>
    <item>
      <title>Access Control Policy Blocking Sites targeting Active Directory Users</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4616955#M1090400</link>
      <description>&lt;P&gt;Hi Everyone,&lt;/P&gt;&lt;P&gt;I got into this roadblock while implementing a blocking to specific websites like facebook, youtube and adult sites and i want to block only certain group of people by targeting their active directory users login.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have already created Realms and imported users and groups from AD and it was running pretty smooth, even my RAVPN is getting authentication from it is running pretty well and i also created an Identity policy as the Access Control Policy requires me for it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, i made a test block under ACP for any users any source and any destination with the specific urls and it worked well but when i tried to add specific users under USERS tab in my Policy all users can access the blocked URL's which is not what i expect i even added a single AD group or a single AD user it still can access those blocked url's,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am using FTD7.0.1.1 and FMC 7.0.1.1 with ASA5508X&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is a look on my ACP.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ACP.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/151945i61368E3DF6567EB0/image-size/large?v=v2&amp;amp;px=999" role="button" title="ACP.jpg" alt="ACP.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ACP2.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/151944i09DE91A30B892FD7/image-size/large?v=v2&amp;amp;px=999" role="button" title="ACP2.jpg" alt="ACP2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2022 05:18:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4616955#M1090400</guid>
      <dc:creator>Herald Sison</dc:creator>
      <dc:date>2022-05-25T05:18:53Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4617856#M1090417</link>
      <description>&lt;P&gt;You need to check the connection logs and see how the users are matched.&amp;nbsp; I suspect they are showing up as Unknown.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2022 21:51:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4617856#M1090417</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-05-25T21:51:41Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4617962#M1090428</link>
      <description>&lt;P&gt;Hi Sir, i think you are right it says unkown. how to fix this issue sir?&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-05-26 100904.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/152035i6591BCB0E42AA3A3/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2022-05-26 100904.jpg" alt="Screenshot 2022-05-26 100904.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 May 2022 02:11:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4617962#M1090428</guid>
      <dc:creator>Herald Sison</dc:creator>
      <dc:date>2022-05-26T02:11:01Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4619461#M1090459</link>
      <description>&lt;P&gt;You might want to try to download the User Database manually.&amp;nbsp; System &amp;gt; Integration &amp;gt; Realms and edit the realm go to User Download and then click Download Now.&amp;nbsp; This should be configured to download automatically&amp;nbsp; on a schedule but might be worth a try.&lt;/P&gt;
&lt;P&gt;Also, you could have a look at the following link where the blogger has experience a similar issue.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://finkotek.com/firepower-management-center-initiator-user-is-unknown/" target="_blank"&gt;https://finkotek.com/firepower-management-center-initiator-user-is-unknown/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 20:55:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4619461#M1090459</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-05-27T20:55:20Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4619568#M1090462</link>
      <description>&lt;P&gt;Thanks sir but in my case i am using FMC7.0.1.1 and i cannot find any download button.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.jpg" style="width: 868px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/152208iD4359C00D8075237/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.jpg" alt="2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and i read the blog and he mentioned about AD agent? i have not installed or configured any AD agent, where can i get that one? is that a software that needs to be installed in the AD? just like in sonicwall SSO AGENT?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also i found some blogs that when using an AD user agent you need to setup from System &amp;gt; INtegration &amp;gt; Identity Soures &amp;gt; User Agent (button) but in my FMC there is no button for User Agent.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;see below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.jpg" style="width: 865px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/152209i0B4C05851A963629/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.jpg" alt="1.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 28 May 2022 04:20:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4619568#M1090462</guid>
      <dc:creator>Herald Sison</dc:creator>
      <dc:date>2022-05-28T04:20:50Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4624215#M1090605</link>
      <description>&lt;P&gt;Anyone? Is there a solution for this?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Jun 2022 16:20:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4624215#M1090605</guid>
      <dc:creator>Herald Sison</dc:creator>
      <dc:date>2022-06-03T16:20:13Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4624688#M1090625</link>
      <description>&lt;P&gt;What is the domain that the "Unknown" user is associated with?&amp;nbsp; is it mydomain.local or domain1.mydomain.local.&lt;/P&gt;
&lt;P&gt;Did you re-sync the user database.&amp;nbsp; you can do this by clicking on Load Groups under Groups and User Sync tab you posted the screenshot of earlier.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Jun 2022 12:06:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4624688#M1090625</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-06-04T12:06:58Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4625382#M1090668</link>
      <description>&lt;P&gt;Hi Sir,&lt;/P&gt;&lt;P&gt;the primary active directory serve is TT-ADDS01.XYZ.local and the domain is XYZ.LOCAL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i have synced the users a lot of times already&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.jpg" style="width: 679px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/152941i5DE3F351C026EF33/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.jpg" alt="1.jpg" /&gt;&lt;/span&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.jpg" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/152942i62D2F7798BA02581/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.jpg" alt="2.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Jun 2022 04:36:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4625382#M1090668</guid>
      <dc:creator>Herald Sison</dc:creator>
      <dc:date>2022-06-06T04:36:46Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4629385#M1090822</link>
      <description>&lt;P&gt;Hi Sir,&lt;/P&gt;&lt;P&gt;update: i have installed and configured ISE-PIC virtual and integrated to AD and FMC but still the url blocking is still not working for active directory users.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please help!&lt;/P&gt;</description>
      <pubDate>Fri, 10 Jun 2022 07:14:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4629385#M1090822</guid>
      <dc:creator>Herald Sison</dc:creator>
      <dc:date>2022-06-10T07:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4630387#M1090851</link>
      <description>&lt;P&gt;I am assuming the the users you are trying to block with this rule are in one of the two user groups you have defined in the rule?&lt;/P&gt;</description>
      <pubDate>Sun, 12 Jun 2022 18:54:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4630387#M1090851</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-06-12T18:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4630473#M1090854</link>
      <description>&lt;P&gt;yes its part of one of the groups. i even tried to test block 1 user but still blocking is not working.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;one more thing i bumped in to his bug just today. does this bug preventing the blocking to work correctly?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-06-13 101758.jpg" style="width: 306px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/153571i1A73024C7A5FFEB8/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2022-06-13 101758.jpg" alt="Screenshot 2022-06-13 101758.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 02:18:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4630473#M1090854</guid>
      <dc:creator>Herald Sison</dc:creator>
      <dc:date>2022-06-13T02:18:46Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4630482#M1090856</link>
      <description>&lt;P&gt;Are you able to try to specify a specific user instead of the group? does the rule work then?&lt;/P&gt;
&lt;P&gt;The error is very generic but doesn't necessarily mean that it is a bug&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Jun 2022 03:57:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4630482#M1090856</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-06-13T03:57:31Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4631365#M1090917</link>
      <description>&lt;P&gt;&lt;SPAN&gt;i tried adding single user but still the url blocking does not work. i even tried adding multiple individual users but still does not work. the only option that works for me is to block per ip address but in our current office setup this is not a doable option since most of the people from the production, they constantly changes cubicle positions and use different computers daily.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;and 1 more thing, by looking at the connection events i see a lot of "Not Found" for Initiator User.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2022-06-14 162553.jpg" style="width: 896px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/153766i672722139B8196BE/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2022-06-14 162553.jpg" alt="Screenshot 2022-06-14 162553.jpg" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jun 2022 08:26:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4631365#M1090917</guid>
      <dc:creator>Herald Sison</dc:creator>
      <dc:date>2022-06-14T08:26:29Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4632791#M1090971</link>
      <description>&lt;P&gt;I suspect the issue is that you are using passive authentication, and the FTD is having issues authenticating the user with this method.&amp;nbsp; If you use active authentication with captive portal are you able to match the access rule?&lt;/P&gt;
&lt;P&gt;Refer to this link if you want to continue to use passive authentication:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/control_users_with_ts_agent.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/70/configuration/guide/fpmc-config-guide-v70/control_users_with_ts_agent.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 04:59:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4632791#M1090971</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-06-16T04:59:08Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4633330#M1090998</link>
      <description>&lt;P&gt;does that mean the ISE-PIC is not useful anymore? i have tried enablind active authenticatio in my identity policy but some mobile devices gets a "no internet notifications" from their network adapter but still they can connect to the internet and if a blocked site was hit it will redirect to the firewalls inside interface https page.&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jun 2022 16:45:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4633330#M1090998</guid>
      <dc:creator>Herald Sison</dc:creator>
      <dc:date>2022-06-16T16:45:59Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4634544#M1091050</link>
      <description>&lt;P&gt;You need to decide how you want to authenticate your users, if that is via ISE-PIC or directly with the AD.&amp;nbsp; This is a design choice you need to make and based on that choice you will know if you need the ISE in the network.&lt;/P&gt;
&lt;P&gt;As for traffic not hitting your rule, which are you using to authenticate users now? AD or ISE?&lt;/P&gt;</description>
      <pubDate>Sun, 19 Jun 2022 22:12:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4634544#M1091050</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-06-19T22:12:19Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4634580#M1091057</link>
      <description>&lt;P&gt;in the documentation and even in the youtube tutorials, setting up ISE-PIC needs AD realms so i think both AD and ISE-PIC works together.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i also read some exchange conversation online that we need to run this command (user_map_query.pl -i 172.20.7.100) on both FMC and FTD to check if mapping is present. Upon running the command it shows that FMC is mapping the user correctly but not on the FTD and the possible workaround is syncing the database from FMC to FTD and requires a snort restart.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the problem is i dont know what is the command to do this workaround and is it safe to do this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;see results below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in FMC:&lt;/P&gt;&lt;P&gt;WARNING: This script was not tested on this major version (7.0.1)! The results may be unexpected.&lt;/P&gt;&lt;P&gt;Current Time: 06/16/2022 06:19:51 UTC&lt;/P&gt;&lt;P&gt;Getting information on IP Address(es)...&lt;/P&gt;&lt;P&gt;___&lt;/P&gt;&lt;P&gt;IP #1: 172.20.7.100&lt;/P&gt;&lt;P&gt;---&lt;/P&gt;&lt;P&gt;==============================&lt;/P&gt;&lt;P&gt;|&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Database&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;|&lt;/P&gt;&lt;P&gt;==============================&lt;/P&gt;&lt;P&gt;##) Username (ID)&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;1) hsison (1294)&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;for_policy: 1&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &lt;/SPAN&gt;Last Seen: Unknown&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;in FTD:&lt;/P&gt;&lt;P&gt;WARNING: This script was not tested on this major version (7.0.1)! The results may be unexpected.&lt;/P&gt;&lt;P&gt;Current Time: 06/16/2022 06:23:18 UTC&lt;/P&gt;&lt;P&gt;Getting information on IP Address(es)...&lt;/P&gt;&lt;P&gt;ERROR: Unable to find IP address '172.20.7.100' in the database!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Jun 2022 03:47:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4634580#M1091057</guid>
      <dc:creator>Herald Sison</dc:creator>
      <dc:date>2022-06-20T03:47:54Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4636147#M1091148</link>
      <description>&lt;P&gt;I think you have misunderstood the setup.&amp;nbsp; You integrate AD with ISE and then use ISE as and identity source in FMC.&lt;/P&gt;
&lt;P&gt;With regard to mapping the users on the FTD that requires SNORT restart.&amp;nbsp; Any time the SNORT process restarts there will be network outage until the process is back online.&amp;nbsp; So this should be done in a planned service window&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 20:11:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4636147#M1091148</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-06-21T20:11:08Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4636667#M1091170</link>
      <description>&lt;P&gt;Hi sir, you are right.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;May i know how to map users in FTD? Is there a command or documentation for that? I can perform that during the weekend since that is the only time i can perform reboots.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 14:51:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4636667#M1091170</guid>
      <dc:creator>Herald Sison</dc:creator>
      <dc:date>2022-06-22T14:51:55Z</dc:date>
    </item>
    <item>
      <title>Re: Access Control Policy Blocking Sites targeting Active Directory Us</title>
      <link>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4639095#M1091299</link>
      <description>&lt;P&gt;Here is a document on integrating FMC with ISE&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/products/collateral/security/firepower-ngfw/guide-c07-742017.html" target="_blank"&gt;https://www.cisco.com/c/en/us/products/collateral/security/firepower-ngfw/guide-c07-742017.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;for other documents on FMC integrations you can go to the following link.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216120-ise-security-ecosystem-integration-guide.html#anc34" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/identity-services-engine/216120-ise-security-ecosystem-integration-guide.html#anc34&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 26 Jun 2022 21:15:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/access-control-policy-blocking-sites-targeting-active-directory/m-p/4639095#M1091299</guid>
      <dc:creator>Marius Gunnerud</dc:creator>
      <dc:date>2022-06-26T21:15:16Z</dc:date>
    </item>
  </channel>
</rss>

