<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Beleive I have solved this in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firesight-not-up-to-date-with-ad/m-p/2761101#M18585</link>
    <description>&lt;P&gt;Beleive I have solved this myself.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;the indicator of this issue that i should have noticed was that only two of my six DC's were logging a last report time. &amp;nbsp;I understand now that this means only two of my six DC's were actually reporting logon/logoff data which is why there were sync issues.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;i fixed this by upgrading the AD agent to version 2.3, dumping the old configuration and adding back the DC's. &amp;nbsp;note, you can only have five DC's per agent including the localhost.then i addressed the reporting issue by creating a GPO that enabled auditing of logon/logoff events and applied that to the Domain controllers. &amp;nbsp;finally i used a domain admin service account for the querying. &amp;nbsp;after doing all of this all of my DC's are reporting now, ad my user events list has gotten much longer.&lt;/P&gt;</description>
    <pubDate>Thu, 19 Nov 2015 14:44:51 GMT</pubDate>
    <dc:creator>inlandprinting</dc:creator>
    <dc:date>2015-11-19T14:44:51Z</dc:date>
    <item>
      <title>Firesight not up to date with AD</title>
      <link>https://community.cisco.com/t5/network-security/firesight-not-up-to-date-with-ad/m-p/2761100#M18584</link>
      <description>&lt;P&gt;i've noticed that every few weeks we'll have an incident where a user is recognized by firesight incorrectly and as such that users access control policy gets messed up. &amp;nbsp;for example office user inherits production users IP address. &amp;nbsp;source fire still see the production user and blocks the office user from all internet access. &amp;nbsp;Had anyone seen this problem before and know of a way to rectify. &amp;nbsp;&lt;/P&gt;&lt;P&gt;we have tried removing the host entry and the user entry but the block remains when we do this. &amp;nbsp;I'm assuming if we let it sit long eough it'd time out but that's not a great option when people can't use the internet. &amp;nbsp;hopeing for some resolution on this. &amp;nbsp;seems to me this probably happens when a machine loses power and as such the AD agent does not recognize a logout event. &amp;nbsp;then the login event from the user also does not seem to be recognized. &amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance for any help or insight.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Oct 2015 20:29:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-not-up-to-date-with-ad/m-p/2761100#M18584</guid>
      <dc:creator>inlandprinting</dc:creator>
      <dc:date>2015-10-26T20:29:17Z</dc:date>
    </item>
    <item>
      <title>Beleive I have solved this</title>
      <link>https://community.cisco.com/t5/network-security/firesight-not-up-to-date-with-ad/m-p/2761101#M18585</link>
      <description>&lt;P&gt;Beleive I have solved this myself.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;the indicator of this issue that i should have noticed was that only two of my six DC's were logging a last report time. &amp;nbsp;I understand now that this means only two of my six DC's were actually reporting logon/logoff data which is why there were sync issues.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;i fixed this by upgrading the AD agent to version 2.3, dumping the old configuration and adding back the DC's. &amp;nbsp;note, you can only have five DC's per agent including the localhost.then i addressed the reporting issue by creating a GPO that enabled auditing of logon/logoff events and applied that to the Domain controllers. &amp;nbsp;finally i used a domain admin service account for the querying. &amp;nbsp;after doing all of this all of my DC's are reporting now, ad my user events list has gotten much longer.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Nov 2015 14:44:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-not-up-to-date-with-ad/m-p/2761101#M18585</guid>
      <dc:creator>inlandprinting</dc:creator>
      <dc:date>2015-11-19T14:44:51Z</dc:date>
    </item>
  </channel>
</rss>

