<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Thanks Kaisero, I need to in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042594#M145363</link>
    <description>&lt;P&gt;Thanks Kaisero, &lt;BR /&gt;&lt;BR /&gt;I need to find an additional information to show to my customers, maybe you can help: &lt;BR /&gt;- Where do I&amp;nbsp;find, in public documentation, that ASA with FirePOWER&amp;nbsp;is only a NGFW/UTM&amp;nbsp;IF you have Active Directory in English or IF you buy Cisco additional softwares?&lt;/P&gt;</description>
    <pubDate>Mon, 05 Jun 2017 14:26:49 GMT</pubDate>
    <dc:creator />
    <dc:date>2017-06-05T14:26:49Z</dc:date>
    <item>
      <title>Cisco ASA With Firepower Services integration with Active Directry Issue</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042587#M145346</link>
      <description>&lt;P&gt;Greetings,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;We are having the following problem with our implementation of the Cisco Firepower integration with Active Directory and need Cisco’s help for this issue.&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;Our customer is based in LATAM and using an Active Directory (AD) that is in Spanish. The Firepower is not able to integrate with the AD because of the BUG &lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuv61861/?reffering_site=dumpcr" target="_blank"&gt;&lt;SPAN style="font-family: 'Courier New';"&gt;CSCuv61861&lt;/SPAN&gt;&lt;/A&gt;. The TAC’s first suggestion was to follow the Bug workaround of changing the AD to English, which is not viable for the end customer.&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;I going to start by quoting the Cisco’s TAC conclusion:&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;&lt;SPAN style="font-family: 'Courier New'; color: black;"&gt;“It appears that you are being impacted by bug &lt;/SPAN&gt;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuv61861/?reffering_site=dumpcr" target="_blank"&gt;&lt;SPAN style="font-family: 'Courier New';"&gt;CSCuv61861&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style="font-family: 'Courier New'; color: black;"&gt;. In a nutshell, the issue is that the AD User Agent does not support languages other than English. That is something that development is working on, but might take some time to resolve. For now, my recommendation is that you forward tracking number "CSCuv61861" to your Sales person who should be able to solicit the latest updates on the matter from the Cisco Business Unit”&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;Our problem is that the TAC wants to close the case without giving a solution to the end customer when in reality this case should be raised to a development team in order to fix the Bug. According to the TAC, some development team is working this case, but the case should be kept open and escalated so that the End Customer can be sure that Cisco is working on it and not just trusting on the TAC’s word.&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;We have tried to escalate the case commercially but not even our account manager receives an update internally from Cisco.&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;The delicate situation here is that one of the most important reasons for the customer to migrate their ULR filtering and application control to Cisco firewpower is the integration with the AD, and in Latin America, probably most of the ADs are in Spanish. What can we tell our future customers now about this solution when it is not able to integrate with their AD.&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;I need Cisco’s help in order to escalate this case and not closing it as the TAC’s wants. Is it possible to have some orientation from Cisco in this forum?&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;&lt;/P&gt;
&lt;P style="text-align: justify;"&gt;Thanks a lot in advanced&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 09:08:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042587#M145346</guid>
      <dc:creator>cpradoscarvajal</dc:creator>
      <dc:date>2019-03-12T09:08:52Z</dc:date>
    </item>
    <item>
      <title>I understand your frustration</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042588#M145347</link>
      <description>&lt;P&gt;I understand your frustration but I dont think this issue will be resolved any time soon. This feature limitation is very old and still not fixed. I would recommend contacting your cisco account manager once again and tell him that this is very important to you and is basically a deal breaker for your customer(s). Normally there shouldn't be any issue to get an update from the &amp;nbsp;BU on issues like that, if you don't receive any information I would think that the problem is you first point of contact.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;As for a possible workaround I would suggest using ISE with PassiveID. You can gather identity information with ISE and forward it via pxGRID to Firepower Management Center.&amp;nbsp;ISE will directly join the AD and read the security log via WMI to receive the ip:user mappings. If deploying an additional VM for identity integration is an option this would be the way to go.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Let me know if that helps or if you need any additional information.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Mar 2017 20:43:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042588#M145347</guid>
      <dc:creator>Oliver Kaiser</dc:creator>
      <dc:date>2017-03-29T20:43:02Z</dc:date>
    </item>
    <item>
      <title>Hi Kaisero,</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042589#M145348</link>
      <description>&lt;P&gt;Hi Kaisero,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks for your respond.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is unfortunate that Cisco is not taking care of this issue. I work in LATAM and there are many customers specially medium customers that need this solution, but selling another box is just too expensive for them.&lt;/P&gt;
&lt;P&gt;In my opinion there is great potential in this product, but the language limitation creates a problem when selling the solution.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Christian Prados&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2017 16:54:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042589#M145348</guid>
      <dc:creator>cpradoscarvajal</dc:creator>
      <dc:date>2017-04-06T16:54:20Z</dc:date>
    </item>
    <item>
      <title>Thanks a lot Christian for</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042590#M145349</link>
      <description>&lt;P&gt;Thanks a lot Christian for the detailed contribution, did you get any&amp;nbsp;solution?&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This is a critical issue, only english supported is unacceptable. Me and other partners had the same issue about a year ago in Portuguese.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can't believe&amp;nbsp;we still have this problem around, of course it IS a deal breaker. And a suitable treatment in problems like this one may be the reason&amp;nbsp;some players are getting security market&amp;nbsp;chunk while others are losing. And I believe this is one of Cisco's main security projects (correct me if I am wrong).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;The "solution" =&amp;gt; Change Active Directory's Language - I'd rather not comment.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;And I got no hope in my case with same issue from&amp;nbsp;Cisco Partner Helpline as well..&lt;/P&gt;</description>
      <pubDate>Mon, 29 May 2017 15:28:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042590#M145349</guid>
      <dc:creator />
      <dc:date>2017-05-29T15:28:32Z</dc:date>
    </item>
    <item>
      <title>it seems like ISE-PIC will be</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042591#M145350</link>
      <description>&lt;P&gt;it seems like ISE-PIC will be the way forward. The agent hasnt been updated in ages and I dont think the language requirements will be changed (atleast I am not aware of it).&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2017 09:32:10 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042591#M145350</guid>
      <dc:creator>Oliver Kaiser</dc:creator>
      <dc:date>2017-05-31T09:32:10Z</dc:date>
    </item>
    <item>
      <title>This is a bad, in  my world</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042592#M145352</link>
      <description>&lt;P&gt;This is a bad, in &amp;nbsp;my world It's never too late to evolve for those&amp;nbsp;who wants it.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So we sell a NGFW / UTM solution that cannot integrate with users database. Or, the customer has to buy another solution to make it work.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2017 14:05:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042592#M145352</guid>
      <dc:creator />
      <dc:date>2017-06-05T14:05:28Z</dc:date>
    </item>
    <item>
      <title>So what is the SKU for</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042593#M145354</link>
      <description>&lt;P&gt;&lt;/P&gt;
&lt;P&gt;So what is the SKU for ordering ISE-PIC? People are having a hard time finding it as you can see here:&lt;/P&gt;
&lt;P&gt;https://communities.cisco.com/thread/79188?start=0&amp;amp;tstart=0&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2017 14:08:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042593#M145354</guid>
      <dc:creator />
      <dc:date>2017-06-05T14:08:02Z</dc:date>
    </item>
    <item>
      <title>Thanks Kaisero, I need to</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042594#M145363</link>
      <description>&lt;P&gt;Thanks Kaisero, &lt;BR /&gt;&lt;BR /&gt;I need to find an additional information to show to my customers, maybe you can help: &lt;BR /&gt;- Where do I&amp;nbsp;find, in public documentation, that ASA with FirePOWER&amp;nbsp;is only a NGFW/UTM&amp;nbsp;IF you have Active Directory in English or IF you buy Cisco additional softwares?&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2017 14:26:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042594#M145363</guid>
      <dc:creator />
      <dc:date>2017-06-05T14:26:49Z</dc:date>
    </item>
    <item>
      <title>IMO they should add support</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042595#M145367</link>
      <description>&lt;P&gt;IMO they should add support for other lanugages but then again I think every windows server should be installed in english due to other issues as well... If you are looking for the SKU its R-ISE-PIC-VM-K9= with ~ 1360$ list price.&lt;/P&gt;</description>
      <pubDate>Mon, 05 Jun 2017 14:47:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042595#M145367</guid>
      <dc:creator>Oliver Kaiser</dc:creator>
      <dc:date>2017-06-05T14:47:57Z</dc:date>
    </item>
    <item>
      <title>Hi Paulo, unfortunately</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042596#M145371</link>
      <description>&lt;P&gt;Hi Paulo, unfortunately according to the TAC we will have to wait. There is no news about an upgrade for the agent that integrates with the AD in other languages other than english.&lt;/P&gt;
&lt;P&gt;I tried speaking with the representative in Venezuela and there is no much knowledge about this issue. Their only suggestion is to follow the TAC advise.&lt;/P&gt;
&lt;P&gt;I still have a case open for this with the TAC (95573352), but the TAC is not able to do anything else.&lt;/P&gt;
&lt;P&gt;After doing some research of the solution, I found out that this problem comes from when the solution was only sourcefire, and they only worked with english and japanese by that time.&lt;/P&gt;
&lt;P&gt;We tried to do active authentication, but the problem is that active authentication has limitations.&lt;/P&gt;
&lt;P&gt;In Venezuela only few customers have the Active Directory in english. The thing is that many customer need to migrate to the new Firepower not only to replace an old ASA but also to replace URL filtering solutions like Microsoft TMG that are EOL. We might lost lots of opportunities.&lt;/P&gt;
&lt;P&gt;Now I know that we are not facing this issue alone.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;Christian&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2017 17:21:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042596#M145371</guid>
      <dc:creator>cpradoscarvajal</dc:creator>
      <dc:date>2017-06-15T17:21:03Z</dc:date>
    </item>
    <item>
      <title>Thanks for your feedback, it</title>
      <link>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042597#M145374</link>
      <description>&lt;P&gt;Thanks for your feedback, it's really sad the way&amp;nbsp;that Cisco is conducting this issue.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I've contacted local Cisco AMs and other roles related to the customer facing the problem, nobody even voted this issue up.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It makes me feel seriously&amp;nbsp;worried.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Jun 2017 17:40:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/cisco-asa-with-firepower-services-integration-with-active/m-p/3042597#M145374</guid>
      <dc:creator />
      <dc:date>2017-06-15T17:40:56Z</dc:date>
    </item>
  </channel>
</rss>

