<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD External Authentication in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/4858781#M1101787</link>
    <description>&lt;P&gt;Please use this post of mine as a reference guide and see if it helps:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bluenetsec.com/fmc-external-authentication-with-radius/" target="_blank"&gt;https://bluenetsec.com/fmc-external-authentication-with-radius/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 20 Jun 2023 14:00:50 GMT</pubDate>
    <dc:creator>Aref Alsouqi</dc:creator>
    <dc:date>2023-06-20T14:00:50Z</dc:date>
    <item>
      <title>FTD External Authentication</title>
      <link>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/3044711#M145323</link>
      <description>&lt;P&gt;I cannot find a way to get external authentication methods to work for the management interface of a Firepower Threat Defense system.&amp;nbsp; In an FMC Platform Settings policy for device type "Firepower" there is an option to enable external authentication generally and for the shell specifically.&amp;nbsp; However, there is no corresponding option in the policy settings for a device type "Threat Defense".&amp;nbsp; In the manual (Firepower Management Center Configuration Guide, Version 6.2), I found this stated:&lt;/P&gt;
&lt;P&gt;• SSH local users can only be configured at the CLI using the configure user add command. By default,&lt;BR /&gt;there is an admin user for which you configured the password during initial setup.&lt;/P&gt;
&lt;P&gt;Does this mean that externally authenticated users cannot use an FTD CLI, or am I missing something?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:09:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/3044711#M145323</guid>
      <dc:creator>Isaiah</dc:creator>
      <dc:date>2019-03-12T09:09:05Z</dc:date>
    </item>
    <item>
      <title>As far as I know, that</title>
      <link>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/3044712#M145326</link>
      <description>&lt;P&gt;As far as I know, that feature is not currently available on the FTD devices.&lt;/P&gt;
&lt;P&gt;I've heard talk of adding it but no committed time frame or release at this point.&lt;/P&gt;</description>
      <pubDate>Thu, 30 Mar 2017 07:47:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/3044712#M145326</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-03-30T07:47:58Z</dc:date>
    </item>
    <item>
      <title>Re: FTD External Authentication</title>
      <link>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/3403577#M145328</link>
      <description>&lt;P&gt;supposedly 6.2.3 code fixed this and it even says "only available for 6.2.3 devices" in the platform external configuration tab&lt;/P&gt;</description>
      <pubDate>Thu, 21 Jun 2018 19:14:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/3403577#M145328</guid>
      <dc:creator>toddlammle</dc:creator>
      <dc:date>2018-06-21T19:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: FTD External Authentication</title>
      <link>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/3684000#M145329</link>
      <description>&lt;P&gt;Is this now available?&amp;nbsp; I'm running 6.2.3.3 on a 2110 and trying to get external (ldap) authentication work for cli access to&amp;nbsp;the ftd which is managed via fmc.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 11:08:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/3684000#M145329</guid>
      <dc:creator>tmoore</dc:creator>
      <dc:date>2018-08-08T11:08:40Z</dc:date>
    </item>
    <item>
      <title>Re: FTD External Authentication</title>
      <link>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/3684003#M145332</link>
      <description>Hi, Yes, you can use LDAP(s) authentication on the CLI of FTD 6.2.3.3&lt;BR /&gt;HTH</description>
      <pubDate>Wed, 08 Aug 2018 11:11:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/3684003#M145332</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2018-08-08T11:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: FTD External Authentication</title>
      <link>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/3684037#M145333</link>
      <description>&lt;P&gt;I can't seem to get this working.&amp;nbsp; I setup and tested the External Auth Server under Platform Settings &amp;gt; Platform Policy &amp;gt; External Authentication &amp;gt; Manage External Authentication Server, which is using LDAP as Auth Method and Encryption is SSL set under Advanced Options.&amp;nbsp; Testing with my account is successful.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After the external auth server is setup, back under Platform Settings &amp;gt; Platform Policy &amp;gt; External Authentication &amp;gt; you are suppose to hit refesh button and I guess you are suppose to see the external auth server object you just created listed but I don't, still show not records to display.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The document states "&lt;SPAN style="color: rgb(0, 0, 0); text-transform: none; text-indent: 0px; letter-spacing: normal; font-family: Arial; font-size: 12px; font-style: normal; font-weight: 400; word-spacing: 0px; float: none; display: inline !important; white-space: normal; orphans: 2; widows: 2; background-color: rgb(255, 255, 255); font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;"&gt;For LDAP when you specify SSL or TLS encryption, you must upload a certificate for the connection; otherwise, the server will not be listed on this tab." &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The document states&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="text-align: left; color: rgb(0, 0, 0); text-transform: none; text-indent: 0px; letter-spacing: normal; font-family: Arial; font-size: 12px; font-style: normal; font-weight: 400; word-spacing: 0px; float: none; display: inline !important; white-space: normal; orphans: 2; widows: 2; background-color: rgb(255, 255, 255); font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;"&gt;"&lt;SPAN style="color: rgb(0, 0, 0); text-transform: none; text-indent: 0px; letter-spacing: normal; font-family: Arial; font-size: 12px; font-style: normal; font-weight: 400; word-spacing: 0px; float: none; display: inline !important; white-space: normal; orphans: 2; widows: 2; background-color: rgb(255, 255, 255); font-variant-ligatures: normal; font-variant-caps: normal; -webkit-text-stroke-width: 0px; text-decoration-style: initial; text-decoration-color: initial;"&gt;For LDAP when you specify SSL or TLS encryption, you must upload a certificate for the connection; otherwise, the server will not be listed on this tab.&lt;/SPAN&gt;"&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not sure where this certificate needs to uploaded for the FTD device.&amp;nbsp; I have a cert uploaded for the FMC for HTTPS access.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What do I need to do to get this working?&lt;/P&gt;
&lt;P&gt;Thanks!&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Aug 2018 12:07:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/3684037#M145333</guid>
      <dc:creator>tmoore</dc:creator>
      <dc:date>2018-08-08T12:07:10Z</dc:date>
    </item>
    <item>
      <title>Re: FTD External Authentication</title>
      <link>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/3742582#M145336</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2018-11-08_23-23-15.png" style="width: 997px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/22662i74B0FDA48618CAC5/image-size/large?v=v2&amp;amp;px=999" role="button" title="2018-11-08_23-23-15.png" alt="2018-11-08_23-23-15.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the&amp;nbsp;&lt;SPAN&gt;External Authentication Object page, go to&amp;nbsp;Show Advanced Options and you will find the above button to upload the LDAPS CA certificate.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 08 Nov 2018 23:34:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/3742582#M145336</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2018-11-08T23:34:24Z</dc:date>
    </item>
    <item>
      <title>Re: FTD External Authentication</title>
      <link>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/4857996#M1101770</link>
      <description>&lt;P&gt;I actually dont think i've ever got it to work in multiple deployments, ive set it up exactly as you have above, i however get the server listed, its enabled but when i try SSH into the device i get "permission denied".&lt;/P&gt;&lt;P&gt;FTD logs:&lt;/P&gt;&lt;P&gt;2023-06-20T03:45:59.154931+00:00 &amp;lt;hostname&amp;gt;.dcp.local : Jun 20 03:45:59 UTC: %FTD-sys-5-199017: sshd[38665]: Invalid user &amp;lt;user-name&amp;gt; from &amp;lt;mgmt_host_ip&amp;gt; port 37758#012&lt;BR /&gt;2023-06-20T03:46:02.835086+00:00 &amp;lt;hostname&amp;gt;.dcp.local : Jun 20 03:46:02 UTC: %FTD-sys-5-199017: sshd[38665]: pam_tally(sshd:auth): pam_get_uid; no such user#012&lt;BR /&gt;2023-06-20T03:46:02.835367+00:00 &amp;lt;hostname&amp;gt;.dcp.local : Jun 20 03:46:02 UTC: %FTD-sys-5-199017: sshd[38665]: pam_unix(sshd:auth): check pass; user unknown#012&lt;BR /&gt;2023-06-20T03:46:02.835470+00:00 &amp;lt;hostname&amp;gt;.dcp.local : Jun 20 03:46:02 UTC: %FTD-sys-5-199017: sshd[38665]: pam_unix(sshd:auth): authentication failure; logname= uid=0 euid=0 tty=ssh ruser= rhost=&amp;lt;mgmt_host_ip&amp;gt; #012&lt;BR /&gt;2023-06-20T03:46:02.843674+00:00 &amp;lt;hostname&amp;gt;.dcp.local : Jun 20 03:46:02 UTC: %FTD-sys-5-199017: sshd[38665]: pam_ldap: error trying to bind as user "uid=&amp;lt;user-name&amp;gt;,cn=users,cn=accounts,dc=dcp,dc=local" (Invalid credentials)#012&lt;BR /&gt;2023-06-20T03:46:05.089077+00:00 &amp;lt;hostname&amp;gt;.dcp.local : Jun 20 03:46:05 UTC: %FTD-sys-5-199017: sshd[38665]: Failed password for invalid user &amp;lt;user-name&amp;gt; from &amp;lt;mgmt_host_ip&amp;gt; port 37758 ssh2#012&lt;/P&gt;&lt;P&gt;i can log in to the FMC, membership group is the same for FTD and FMC. not sure what im missing here.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 04:21:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/4857996#M1101770</guid>
      <dc:creator>WillDudeGuy</dc:creator>
      <dc:date>2023-06-20T04:21:01Z</dc:date>
    </item>
    <item>
      <title>Re: FTD External Authentication</title>
      <link>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/4858781#M1101787</link>
      <description>&lt;P&gt;Please use this post of mine as a reference guide and see if it helps:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://bluenetsec.com/fmc-external-authentication-with-radius/" target="_blank"&gt;https://bluenetsec.com/fmc-external-authentication-with-radius/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Jun 2023 14:00:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/4858781#M1101787</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-20T14:00:50Z</dc:date>
    </item>
    <item>
      <title>Re: FTD External Authentication</title>
      <link>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/4859134#M1101801</link>
      <description>&lt;P&gt;Hi Aref,&lt;/P&gt;&lt;P&gt;Whilst I appreciate you trying to assist me, the reference guide you've linked doesn't in any way replicate the environment we have and also doesn't touch on the main issue of not being able to authenticate to the FTDs&lt;/P&gt;&lt;P&gt;Will&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 06:10:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/4859134#M1101801</guid>
      <dc:creator>WillDudeGuy</dc:creator>
      <dc:date>2023-06-21T06:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: FTD External Authentication</title>
      <link>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/4859277#M1101815</link>
      <description>&lt;P&gt;Hi Will, apologies if I am missing anything. If you are getting the permission denies when you are trying to SSH into the FTDs, then that potentially would be due to incorrect settings in the external authentication object. In the link I shared it is showing how the FTD CLI would need to be configured to allow some of the admins to log into the FTDs CLI. Could you please share the configs you applied and elaborate a little bit more about the issues you are experiencing with these accesses?&lt;/P&gt;</description>
      <pubDate>Wed, 21 Jun 2023 09:53:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-external-authentication/m-p/4859277#M1101815</guid>
      <dc:creator>Aref Alsouqi</dc:creator>
      <dc:date>2023-06-21T09:53:28Z</dc:date>
    </item>
  </channel>
</rss>

