<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC Multiple Domain Management and external users in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-multiple-domain-management-and-external-users/m-p/4954790#M1105627</link>
    <description>&lt;P&gt;I found this in the FMC user guide:&lt;/P&gt;
&lt;P&gt;"In a multidomain deployment, external authentication objects are only available in the domain in which they are created"&lt;/P&gt;
&lt;P&gt;so it looks like it suposed to be suported. However, even though I can create an LDAP or Radius authentication object under the subdomain, it's not possible to login when I disable the global authentication object.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;</description>
    <pubDate>Tue, 07 Nov 2023 08:57:38 GMT</pubDate>
    <dc:creator>Chess Norris</dc:creator>
    <dc:date>2023-11-07T08:57:38Z</dc:date>
    <item>
      <title>FMC Multiple Domain Management and external users</title>
      <link>https://community.cisco.com/t5/network-security/fmc-multiple-domain-management-and-external-users/m-p/4951000#M1105443</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;We want to create subdomains in our FMC and add a specific FTD device to each subdomain.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have created two sub domains in the FMC and added one FTD device to each subdomain.&lt;/P&gt;
&lt;P&gt;It works when I create local users and assign them to a specific subdomai. Then the user can only edit the device that belong to the same subdomain as the user.&lt;/P&gt;
&lt;P&gt;However, when I log in as an external user, that user will always have access to the global domain. It doesn't matter if I edit the user and only assign the subdomain. As soon as the external user login, he have access to both the subdomain and the global domain.&lt;/P&gt;
&lt;P&gt;Is there away to map the external users to a specific subdomain or is it only possible with local users?&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;</description>
      <pubDate>Mon, 30 Oct 2023 17:37:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-multiple-domain-management-and-external-users/m-p/4951000#M1105443</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2023-10-30T17:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Multiple Domain Management and external users</title>
      <link>https://community.cisco.com/t5/network-security/fmc-multiple-domain-management-and-external-users/m-p/4954790#M1105627</link>
      <description>&lt;P&gt;I found this in the FMC user guide:&lt;/P&gt;
&lt;P&gt;"In a multidomain deployment, external authentication objects are only available in the domain in which they are created"&lt;/P&gt;
&lt;P&gt;so it looks like it suposed to be suported. However, even though I can create an LDAP or Radius authentication object under the subdomain, it's not possible to login when I disable the global authentication object.&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;</description>
      <pubDate>Tue, 07 Nov 2023 08:57:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-multiple-domain-management-and-external-users/m-p/4954790#M1105627</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2023-11-07T08:57:38Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Multiple Domain Management and external users</title>
      <link>https://community.cisco.com/t5/network-security/fmc-multiple-domain-management-and-external-users/m-p/5088857#M1112086</link>
      <description>&lt;P&gt;Hi, did you make it work? I have the exact requirement and cannot find a guide.&lt;/P&gt;</description>
      <pubDate>Fri, 03 May 2024 14:35:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-multiple-domain-management-and-external-users/m-p/5088857#M1112086</guid>
      <dc:creator>jlgf</dc:creator>
      <dc:date>2024-05-03T14:35:18Z</dc:date>
    </item>
    <item>
      <title>Re: FMC Multiple Domain Management and external users</title>
      <link>https://community.cisco.com/t5/network-security/fmc-multiple-domain-management-and-external-users/m-p/5089675#M1112106</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;No unfortunately I had to give up the idea of using multiple domains and instead use a separate FMC.&lt;/P&gt;
&lt;P&gt;There was a big issue with a IPSec tunnel that we needed to break before we could configuring multiple domains and we had a FTD on the other end of the VPN tunnel, managed by the FMC and we couldn’t break that tunnel.&lt;/P&gt;
&lt;P&gt;Multiple domains it's a great idea, but it should probably be implemented before you start managing FTD's.&lt;/P&gt;
&lt;P&gt;/Chess&lt;/P&gt;</description>
      <pubDate>Sat, 04 May 2024 13:14:59 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-multiple-domain-management-and-external-users/m-p/5089675#M1112106</guid>
      <dc:creator>Chess Norris</dc:creator>
      <dc:date>2024-05-04T13:14:59Z</dc:date>
    </item>
  </channel>
</rss>

