<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FTD and User identity based rules _CDA in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/ftd-and-user-identity-based-rules-cda/m-p/3866370#M132503</link>
    <description>Thank you for your input.&lt;BR /&gt;I will check with my vendor for required quote and see if that reduces our OPEX.</description>
    <pubDate>Sun, 02 Jun 2019 08:15:56 GMT</pubDate>
    <dc:creator>NDP</dc:creator>
    <dc:date>2019-06-02T08:15:56Z</dc:date>
    <item>
      <title>FTD and User identity based rules _CDA</title>
      <link>https://community.cisco.com/t5/network-security/ftd-and-user-identity-based-rules-cda/m-p/3866138#M132501</link>
      <description>&lt;P&gt;Need advise /guidance on CDA integration with FTD&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have FTD devices as Internet perimeter Firewalls. As the enterprise network is for Service based company, We expect ramp-up and ramp-down of many projects every week and month. due to this dynamic change in head count, there is always requirement to edit firewall rules or create new rules to meet businness requirements.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;LAN network is not 802.1x based. We would like to go with user identity firewall rules instead of IP based rules on these NGFS -FTD boxes. so, We can add DLs as source group in Firewall rules and DL can be managed by project teams only.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;was going through couple of Cisco URLs and understood that Context Directory agent can fetch data from MS Active directory and help FTD to perform IP-User mapping.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;could someone advise me if this was successful integration. if Yes, I need help on pricing as well for CDA. so, We can explore if that reduces OPEX as well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you in advance&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jun 2019 10:17:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-and-user-identity-based-rules-cda/m-p/3866138#M132501</guid>
      <dc:creator>NDP</dc:creator>
      <dc:date>2019-06-01T10:17:22Z</dc:date>
    </item>
    <item>
      <title>Re: FTD and User identity based rules _CDA</title>
      <link>https://community.cisco.com/t5/network-security/ftd-and-user-identity-based-rules-cda/m-p/3866196#M132502</link>
      <description>&lt;P&gt;There are two parts to the answer to your question.&lt;/P&gt;
&lt;P&gt;1. You need to pull groups and group membership from AD. You do that via direct integration from Firepower Management Center.&lt;/P&gt;
&lt;P&gt;2. You need to map IP addresses to users. We do that via an identity source. External identity sources include:&lt;/P&gt;
&lt;P&gt;CDA is an old and no longer supported product. It is/was free.&lt;/P&gt;
&lt;P&gt;Cisco Firepower User Agent would be a current alternative. It is also free.&lt;/P&gt;
&lt;P&gt;The best and most supportable alternative would be to use ISE PIC (Passive Identity Collector). It is a licensed and paid product. Part number&amp;nbsp;R-ISE-PIC-VM-K9= is the VM&amp;lt;-based version and costs US$1250 (list price, not including maintenance).&lt;/P&gt;</description>
      <pubDate>Sat, 01 Jun 2019 14:43:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-and-user-identity-based-rules-cda/m-p/3866196#M132502</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-06-01T14:43:58Z</dc:date>
    </item>
    <item>
      <title>Re: FTD and User identity based rules _CDA</title>
      <link>https://community.cisco.com/t5/network-security/ftd-and-user-identity-based-rules-cda/m-p/3866370#M132503</link>
      <description>Thank you for your input.&lt;BR /&gt;I will check with my vendor for required quote and see if that reduces our OPEX.</description>
      <pubDate>Sun, 02 Jun 2019 08:15:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/ftd-and-user-identity-based-rules-cda/m-p/3866370#M132503</guid>
      <dc:creator>NDP</dc:creator>
      <dc:date>2019-06-02T08:15:56Z</dc:date>
    </item>
  </channel>
</rss>

