<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Create a second local admin user on FTD FDM in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/create-a-second-local-admin-user-on-ftd-fdm/m-p/5226946#M1117706</link>
    <description>&lt;P&gt;I am trying to create a second local admin user on a Cisco FTD device.&amp;nbsp; It is a standalone device, running version 7.2.8-25, using FDM.&amp;nbsp; I have no FMC.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have tried creating a second admin user in the cli using&lt;/P&gt;
&lt;P&gt;configure user add jsmith password config&lt;/P&gt;
&lt;P&gt;I have tried creating it in expert mode&lt;/P&gt;
&lt;P&gt;sudo su&lt;/P&gt;
&lt;P&gt;usertool.pl -p 'jsmith password'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The new user does show up in CLI when I run the command 'show user'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; show user&lt;/P&gt;
&lt;P&gt;Login &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;UID &amp;nbsp; Auth Access &amp;nbsp;Enabled Reset &amp;nbsp; Exp &amp;nbsp; &amp;nbsp; Warn &amp;nbsp; &amp;nbsp;Grace MinL Str Lock Max&lt;/P&gt;
&lt;P&gt;admin &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;100 &amp;nbsp;Local Config &amp;nbsp;Enabled &amp;nbsp; &amp;nbsp;No &amp;nbsp;10000 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;7 &amp;nbsp;Disabled &amp;nbsp; &amp;nbsp;8 Ena &amp;nbsp; No N/A&lt;/P&gt;
&lt;P&gt;jsmith&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1000 &amp;nbsp;Local Config &amp;nbsp;Enabled &amp;nbsp; &amp;nbsp;No &amp;nbsp;10000 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;7 &amp;nbsp;Disabled &amp;nbsp; &amp;nbsp;0 Dis &amp;nbsp; No &amp;nbsp; 5&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And it shows up in expert mode when I run 'usertool.pl -d'&lt;/P&gt;
&lt;P&gt;root@FTD01:/home/admin# usertool.pl -d&lt;/P&gt;
&lt;P&gt;%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%&lt;/P&gt;
&lt;P&gt;*********************************************************&lt;/P&gt;
&lt;P&gt;User:jsmith&amp;nbsp; &amp;nbsp; UserID:10 &amp;nbsp; &amp;nbsp; &amp;nbsp; Real Name:none&lt;/P&gt;
&lt;P&gt;Contact:none &amp;nbsp; &amp;nbsp;Email:none&lt;/P&gt;
&lt;P&gt;User is active&lt;/P&gt;
&lt;P&gt;The user is human&lt;/P&gt;
&lt;P&gt;Password strength checking off&lt;/P&gt;
&lt;P&gt;Number of failed login attempts: 0&lt;/P&gt;
&lt;P&gt;Max number of failed login attempts: 5&lt;/P&gt;
&lt;P&gt;Last Login: Thu Jan &amp;nbsp;1 00:00:00 1970&lt;/P&gt;
&lt;P&gt;Last Failed Login: Thu Jan &amp;nbsp;1 00:00:00 1970&lt;/P&gt;
&lt;P&gt;Last Validate: Thu Jan &amp;nbsp;1 00:00:00 1970&lt;/P&gt;
&lt;P&gt;Last Changed Password:&lt;/P&gt;
&lt;P&gt;Hard Expires: ~ 0 days, 0sec&lt;/P&gt;
&lt;P&gt;Soft Expires: ~ 0 days, 0sec&lt;/P&gt;
&lt;P&gt;*********************************************************&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I cannot log into the GUI with this new account. It just says "Unable to authorize access.&amp;nbsp; If you continue to have difficulty accessing this device, please contact the system administrator"&lt;/P&gt;
&lt;P&gt;How do I activate this user for admin GUI access?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 20 Nov 2024 19:07:15 GMT</pubDate>
    <dc:creator>rwills</dc:creator>
    <dc:date>2024-11-20T19:07:15Z</dc:date>
    <item>
      <title>Create a second local admin user on FTD FDM</title>
      <link>https://community.cisco.com/t5/network-security/create-a-second-local-admin-user-on-ftd-fdm/m-p/5226946#M1117706</link>
      <description>&lt;P&gt;I am trying to create a second local admin user on a Cisco FTD device.&amp;nbsp; It is a standalone device, running version 7.2.8-25, using FDM.&amp;nbsp; I have no FMC.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have tried creating a second admin user in the cli using&lt;/P&gt;
&lt;P&gt;configure user add jsmith password config&lt;/P&gt;
&lt;P&gt;I have tried creating it in expert mode&lt;/P&gt;
&lt;P&gt;sudo su&lt;/P&gt;
&lt;P&gt;usertool.pl -p 'jsmith password'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The new user does show up in CLI when I run the command 'show user'&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;gt; show user&lt;/P&gt;
&lt;P&gt;Login &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;UID &amp;nbsp; Auth Access &amp;nbsp;Enabled Reset &amp;nbsp; Exp &amp;nbsp; &amp;nbsp; Warn &amp;nbsp; &amp;nbsp;Grace MinL Str Lock Max&lt;/P&gt;
&lt;P&gt;admin &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;100 &amp;nbsp;Local Config &amp;nbsp;Enabled &amp;nbsp; &amp;nbsp;No &amp;nbsp;10000 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;7 &amp;nbsp;Disabled &amp;nbsp; &amp;nbsp;8 Ena &amp;nbsp; No N/A&lt;/P&gt;
&lt;P&gt;jsmith&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;1000 &amp;nbsp;Local Config &amp;nbsp;Enabled &amp;nbsp; &amp;nbsp;No &amp;nbsp;10000 &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;7 &amp;nbsp;Disabled &amp;nbsp; &amp;nbsp;0 Dis &amp;nbsp; No &amp;nbsp; 5&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And it shows up in expert mode when I run 'usertool.pl -d'&lt;/P&gt;
&lt;P&gt;root@FTD01:/home/admin# usertool.pl -d&lt;/P&gt;
&lt;P&gt;%%%%%%%%%%%%%%%%%%%%%%%%%%%%%%&lt;/P&gt;
&lt;P&gt;*********************************************************&lt;/P&gt;
&lt;P&gt;User:jsmith&amp;nbsp; &amp;nbsp; UserID:10 &amp;nbsp; &amp;nbsp; &amp;nbsp; Real Name:none&lt;/P&gt;
&lt;P&gt;Contact:none &amp;nbsp; &amp;nbsp;Email:none&lt;/P&gt;
&lt;P&gt;User is active&lt;/P&gt;
&lt;P&gt;The user is human&lt;/P&gt;
&lt;P&gt;Password strength checking off&lt;/P&gt;
&lt;P&gt;Number of failed login attempts: 0&lt;/P&gt;
&lt;P&gt;Max number of failed login attempts: 5&lt;/P&gt;
&lt;P&gt;Last Login: Thu Jan &amp;nbsp;1 00:00:00 1970&lt;/P&gt;
&lt;P&gt;Last Failed Login: Thu Jan &amp;nbsp;1 00:00:00 1970&lt;/P&gt;
&lt;P&gt;Last Validate: Thu Jan &amp;nbsp;1 00:00:00 1970&lt;/P&gt;
&lt;P&gt;Last Changed Password:&lt;/P&gt;
&lt;P&gt;Hard Expires: ~ 0 days, 0sec&lt;/P&gt;
&lt;P&gt;Soft Expires: ~ 0 days, 0sec&lt;/P&gt;
&lt;P&gt;*********************************************************&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But I cannot log into the GUI with this new account. It just says "Unable to authorize access.&amp;nbsp; If you continue to have difficulty accessing this device, please contact the system administrator"&lt;/P&gt;
&lt;P&gt;How do I activate this user for admin GUI access?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 19:07:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/create-a-second-local-admin-user-on-ftd-fdm/m-p/5226946#M1117706</guid>
      <dc:creator>rwills</dc:creator>
      <dc:date>2024-11-20T19:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: Create a second local admin user on FTD FDM</title>
      <link>https://community.cisco.com/t5/network-security/create-a-second-local-admin-user-on-ftd-fdm/m-p/5226948#M1117707</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/450292"&gt;@rwills&lt;/a&gt; with FDM as of 7.6 you cannot create additional user accounts for FDM management access. You'd have to use external authentication (i.e. RADIUS)&lt;/P&gt;</description>
      <pubDate>Wed, 20 Nov 2024 19:12:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/create-a-second-local-admin-user-on-ftd-fdm/m-p/5226948#M1117707</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2024-11-20T19:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: Create a second local admin user on FTD FDM</title>
      <link>https://community.cisco.com/t5/network-security/create-a-second-local-admin-user-on-ftd-fdm/m-p/5227034#M1117711</link>
      <description>&lt;P&gt;As Rob mentioned, you can only use the "admin" user when using locally authenticated users to FDM, as of 7.6&lt;/P&gt;
&lt;P&gt;But for reference this is stated in the System Administration -&amp;gt; System Management section of the FDM Config guide:&lt;BR /&gt;"&lt;EM&gt;You can configure an external authentication and authorization source for users to log into&amp;nbsp;&lt;SPAN class="ph"&gt;threat defense&lt;/SPAN&gt;&amp;nbsp;(HTTPS access). You can use an external server in addition to, or instead of, the local user database and the system-defined&amp;nbsp;&lt;STRONG&gt;&lt;SPAN class="ph uicontrol"&gt;admin&lt;/SPAN&gt;&amp;nbsp;&lt;/STRONG&gt;user. &lt;STRONG&gt;Note that you cannot create additional local user accounts for&amp;nbsp;&lt;SPAN class="ph"&gt;device manager&lt;/SPAN&gt;&amp;nbsp;access.&lt;/STRONG&gt;&lt;/EM&gt;"&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/720/fdm/fptd-fdm-config-guide-720/fptd-fdm-mgmt.html#id_73790" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/720/fdm/fptd-fdm-config-guide-720/fptd-fdm-mgmt.html#id_73790&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 00:31:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/create-a-second-local-admin-user-on-ftd-fdm/m-p/5227034#M1117711</guid>
      <dc:creator>Jonatan Jonasson</dc:creator>
      <dc:date>2024-11-21T00:31:13Z</dc:date>
    </item>
    <item>
      <title>Re: Create a second local admin user on FTD FDM</title>
      <link>https://community.cisco.com/t5/network-security/create-a-second-local-admin-user-on-ftd-fdm/m-p/5227515#M1117743</link>
      <description>&lt;P&gt;What is the use-case for FDM?&amp;nbsp; Why not FMC/cdFMC?&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 00:58:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/create-a-second-local-admin-user-on-ftd-fdm/m-p/5227515#M1117743</guid>
      <dc:creator>ahollifield</dc:creator>
      <dc:date>2024-11-22T00:58:45Z</dc:date>
    </item>
    <item>
      <title>Re: Create a second local admin user on FTD FDM</title>
      <link>https://community.cisco.com/t5/network-security/create-a-second-local-admin-user-on-ftd-fdm/m-p/5227899#M1117773</link>
      <description>&lt;P&gt;&lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/199513"&gt;@ahollifield&lt;/a&gt;&amp;nbsp;this topic can be highly religious and probably deserves it's own thread &lt;span class="lia-unicode-emoji" title=":face_with_tongue:"&gt;😛&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Jokes aside, and while I can't speak for OP, there are a number of use cases from costs/logistics/operational and competitive standpoints to use FDM and not FMC.&lt;BR /&gt;Personally I would use FDM in more places if it had close to feature parity with FMC for single-box or single-pair environments.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 23 Nov 2024 00:03:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/create-a-second-local-admin-user-on-ftd-fdm/m-p/5227899#M1117773</guid>
      <dc:creator>Jonatan Jonasson</dc:creator>
      <dc:date>2024-11-23T00:03:02Z</dc:date>
    </item>
  </channel>
</rss>

