<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Local admin and user account on cisco FTD disabled in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695225#M1093710</link>
    <description>&lt;P&gt;It is not using ldap or radius.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I observed that both account became enabled suddenly afterwards.&lt;/P&gt;&lt;P&gt;Am thinking this is just a setup mechanism on ftd to prevent unauthorized access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you think?&lt;/P&gt;</description>
    <pubDate>Wed, 28 Sep 2022 08:42:24 GMT</pubDate>
    <dc:creator>systems100</dc:creator>
    <dc:date>2022-09-28T08:42:24Z</dc:date>
    <item>
      <title>Local admin and user account on cisco FTD disabled</title>
      <link>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695221#M1093708</link>
      <description>&lt;P&gt;Dears,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kindly assist, i noticed that local admin and user account i created was disabled, though i had not used those two accounts for a while i use one other account to access the FTD via cli.&lt;/P&gt;&lt;P&gt;Please what do you think could cause this?.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 08:30:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695221#M1093708</guid>
      <dc:creator>systems100</dc:creator>
      <dc:date>2022-09-28T08:30:42Z</dc:date>
    </item>
    <item>
      <title>Re: Local admin and user account on cisco FTD disabled</title>
      <link>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695223#M1093709</link>
      <description>&lt;P&gt;Normally admin account can not be disable. unless you forget the password? Is your FTD is using the LDAP/Radius authentication?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 08:34:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695223#M1093709</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-09-28T08:34:28Z</dc:date>
    </item>
    <item>
      <title>Re: Local admin and user account on cisco FTD disabled</title>
      <link>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695225#M1093710</link>
      <description>&lt;P&gt;It is not using ldap or radius.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I observed that both account became enabled suddenly afterwards.&lt;/P&gt;&lt;P&gt;Am thinking this is just a setup mechanism on ftd to prevent unauthorized access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What do you think?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 08:42:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695225#M1093710</guid>
      <dc:creator>systems100</dc:creator>
      <dc:date>2022-09-28T08:42:24Z</dc:date>
    </item>
    <item>
      <title>Re: Local admin and user account on cisco FTD disabled</title>
      <link>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695228#M1093711</link>
      <description>&lt;P&gt;What is the FTD version and what the FXOS version you on? Is your FTD running the FTD code or running the ASA code?&lt;/P&gt;
&lt;P&gt;this should not happened. Not doubting you but could be you put in the wrong password earlier?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Found this on cisco documentation.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Failed Authentication&lt;/SPAN&gt;&lt;SPAN&gt;—The user was prompted to authenticate, but failed to enter a valid&lt;/SPAN&gt;&lt;BR role="presentation" /&gt;&lt;SPAN&gt;&lt;SPAN class="highlight selected appended"&gt;username&lt;/SPAN&gt;/password pair within the maximum number of allowed attempts. &lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 08:53:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695228#M1093711</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-09-28T08:53:28Z</dc:date>
    </item>
    <item>
      <title>Re: Local admin and user account on cisco FTD disabled</title>
      <link>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695230#M1093713</link>
      <description>&lt;P&gt;AFAIK the local admin account is exempted from being locked out, the only exception for this would be if you are using a restrict security standards such as the US DoD. How did you notice those users were in disabled state?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 08:53:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695230#M1093713</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-28T08:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: Local admin and user account on cisco FTD disabled</title>
      <link>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695239#M1093714</link>
      <description>&lt;P&gt;I noticed this by doing "show users" on the cisco FTD in the clish mode.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 09:03:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695239#M1093714</guid>
      <dc:creator>systems100</dc:creator>
      <dc:date>2022-09-28T09:03:38Z</dc:date>
    </item>
    <item>
      <title>Re: Local admin and user account on cisco FTD disabled</title>
      <link>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695249#M1093720</link>
      <description>&lt;P&gt;show users in clish mode will show you all the username are configured in your FTD.&amp;nbsp; (This include the username who have access the FMC) they will also showed in show users in clish.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 09:14:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695249#M1093720</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-09-28T09:14:26Z</dc:date>
    </item>
    <item>
      <title>Re: Local admin and user account on cisco FTD disabled</title>
      <link>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695254#M1093722</link>
      <description>&lt;P&gt;Did you notice if it was showing "Yes" in the lock column while they were disabled?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 09:20:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695254#M1093722</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-28T09:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: Local admin and user account on cisco FTD disabled</title>
      <link>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695266#M1093727</link>
      <description>&lt;P&gt;I just check mine. it showed Lock No. but in your case in first attempt you could not login and suddenly later on it let you in the CLI.&lt;/P&gt;
&lt;P&gt;show user&lt;BR /&gt;Login UID Auth Access Enabled Reset Exp Warn Str Lock Max&lt;BR /&gt;abc 1084 Remote Config Enabled N/A Never N/A Dis No N/A&lt;BR /&gt;xyz 1018 Remote Config Enabled N/A Never N/A Dis No N/A&lt;BR /&gt;admin 101 Local Config Enabled No Never N/A Ena No N/A&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 09:38:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695266#M1093727</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-09-28T09:38:46Z</dc:date>
    </item>
    <item>
      <title>Re: Local admin and user account on cisco FTD disabled</title>
      <link>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695283#M1093731</link>
      <description>&lt;P&gt;It is currently showing no:&lt;/P&gt;&lt;P&gt;Login UID Auth Access Enabled Reset Exp Warn Grace MinL Str Lock Max&lt;BR /&gt;admin 101 Local Config Enabled No Never Disabled Disabled 0 Dis No N/A&lt;BR /&gt;abc 1001 Local Config Enabled Yes Never Disabled Disabled 1 Dis No 5&lt;BR /&gt;dof 1000 Local Config Enabled No Never Disabled Disabled 12 Dis No 5&lt;/P&gt;&lt;P&gt;also do you know a command to set the password policy on the FTD?&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 09:56:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695283#M1093731</guid>
      <dc:creator>systems100</dc:creator>
      <dc:date>2022-09-28T09:56:07Z</dc:date>
    </item>
    <item>
      <title>Re: Local admin and user account on cisco FTD disabled</title>
      <link>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695290#M1093732</link>
      <description>&lt;P&gt;You can use these blow feature. for example to set the minim password length. if you use Managed the FTD from FMC in that case you can look at the FMC Gui.&lt;/P&gt;
&lt;P&gt;how you managed your FTD standalone or via fmc?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;&amp;gt; configure user
  access           Set user access level
  add              Add user
  aging            Set user password aging
  delete           Delete user
  disable          Disable user
  enable           Enable user
  forcereset       Force user password reset
  maxfailedlogins  Set maximum failed logins
  minpasswdlen     Set minimum password length
  password         Set user password
  strengthcheck    Set strength requirement on user password
  unlock           Unlock user account
&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;have a look on tihs document &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/640/hardening/ftd/FTD_Hardening_Guide_v64.html" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/640/hardening/ftd/FTD_Hardening_Guide_v64.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 10:03:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695290#M1093732</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-09-28T10:03:46Z</dc:date>
    </item>
    <item>
      <title>Re: Local admin and user account on cisco FTD disabled</title>
      <link>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695330#M1093735</link>
      <description>&lt;P&gt;Would really be interesting to check the lock column if this should happen again. If you see the disabled users marked as locked out, including the admin account and you are not using any strict security model, then I would raise this with Cisco. I don't think you can configure the password policy on the FTD from the UI, I think you can only use the "configure user ..." command as already mentioned.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 11:38:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695330#M1093735</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-28T11:38:33Z</dc:date>
    </item>
    <item>
      <title>Re: Local admin and user account on cisco FTD disabled</title>
      <link>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695339#M1093741</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/284594"&gt;@Aref Alsouqi&lt;/a&gt; just to confirm i have tested&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;gt; &lt;STRONG&gt;configure user strengthcheck apiuser enable&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;you can check the strengthcheck if the password is strong.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Enables or disables password strength checking, which requires a user to meet specific password criteria when changing their password. When a user’s password expires or if the &lt;SPAN class="ph synph"&gt;&lt;SPAN class="keyword kwd"&gt;configure user forcereset&lt;/SPAN&gt; &lt;/SPAN&gt; command is used, this requirement is automatically enabled the next time the user logs in.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;however you can add,enable and disable&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 11:58:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695339#M1093741</guid>
      <dc:creator>Sheraz.Salim</dc:creator>
      <dc:date>2022-09-28T11:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: Local admin and user account on cisco FTD disabled</title>
      <link>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695379#M1093752</link>
      <description>&lt;P&gt;that is possible from the CLI, but I don't think you have equivalent configuration section on the UI.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 13:04:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/local-admin-and-user-account-on-cisco-ftd-disabled/m-p/4695379#M1093752</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2022-09-28T13:04:33Z</dc:date>
    </item>
  </channel>
</rss>

