<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Identity FW - ACL with AD Group not matching in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/identity-fw-acl-with-ad-group-not-matching/m-p/2303378#M345767</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've made another test. I've changed the group that matches the ACL and it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The differences between groups are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- They're located in different OUs, but both are accessible.&lt;/P&gt;&lt;P&gt;- One has 6 users and the other many more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any kind of restriction on how many users a group can contain so that ASA is able to check it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other group that does not work is a group (Global_FTP) containing 3 different groups, being one of them that other group (FTP_OfficeXX).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help will be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 02 Aug 2013 08:44:31 GMT</pubDate>
    <dc:creator>Igor Rodriguez</dc:creator>
    <dc:date>2013-08-02T08:44:31Z</dc:date>
    <item>
      <title>Identity FW - ACL with AD Group not matching</title>
      <link>https://community.cisco.com/t5/network-security/identity-fw-acl-with-ad-group-not-matching/m-p/2303376#M345764</link>
      <description>&lt;P&gt;Hello all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have set up our Cisco ASA 8.4(4)1 so that it works as an Identity Firewall. Everything is going fine, except the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've made an ACL so that only allowed users access a few FTP servers. The thing is that those users belong to an Active Directory group. Using the AD group, the ACL is not being matched and therefore, is not working.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, if I change that AD group and try only my AD user, it does work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have other ACLs matching AD groups and are working fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So my question is:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Is there any limitation to those AD groups?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; What can I check to know why my user (that belongs to that AD group) is not being allowed while ACL includes AD group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help will be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Igor&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 02:17:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-fw-acl-with-ad-group-not-matching/m-p/2303376#M345764</guid>
      <dc:creator>Igor Rodriguez</dc:creator>
      <dc:date>2019-03-12T02:17:24Z</dc:date>
    </item>
    <item>
      <title>Identity FW - ACL with AD Group not matching</title>
      <link>https://community.cisco.com/t5/network-security/identity-fw-acl-with-ad-group-not-matching/m-p/2303377#M345765</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any idea of how could I try to solve this?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 29 Jul 2013 08:09:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-fw-acl-with-ad-group-not-matching/m-p/2303377#M345765</guid>
      <dc:creator>Igor Rodriguez</dc:creator>
      <dc:date>2013-07-29T08:09:54Z</dc:date>
    </item>
    <item>
      <title>Identity FW - ACL with AD Group not matching</title>
      <link>https://community.cisco.com/t5/network-security/identity-fw-acl-with-ad-group-not-matching/m-p/2303378#M345767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've made another test. I've changed the group that matches the ACL and it works.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The differences between groups are:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- They're located in different OUs, but both are accessible.&lt;/P&gt;&lt;P&gt;- One has 6 users and the other many more.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any kind of restriction on how many users a group can contain so that ASA is able to check it?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Other group that does not work is a group (Global_FTP) containing 3 different groups, being one of them that other group (FTP_OfficeXX).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any help will be appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!!!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Aug 2013 08:44:31 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-fw-acl-with-ad-group-not-matching/m-p/2303378#M345767</guid>
      <dc:creator>Igor Rodriguez</dc:creator>
      <dc:date>2013-08-02T08:44:31Z</dc:date>
    </item>
    <item>
      <title>Identity FW - ACL with AD Group not matching</title>
      <link>https://community.cisco.com/t5/network-security/identity-fw-acl-with-ad-group-not-matching/m-p/2303379#M345769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello again everybody,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was wondering if maybe because of summer vacations this post was missing to some of you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyone has any idea of why ACL does not match when using an old and with more members group?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Best regards,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Igor&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Sep 2013 15:12:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-fw-acl-with-ad-group-not-matching/m-p/2303379#M345769</guid>
      <dc:creator>Igor Rodriguez</dc:creator>
      <dc:date>2013-09-30T15:12:03Z</dc:date>
    </item>
  </channel>
</rss>

