<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Based Firewall doesn't work using Citrix Published  in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980617#M401537</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tarik!&lt;/P&gt;&lt;P&gt;I got some output out of the &lt;EM&gt;c:\IBF\radiusServer\runtime\logs\localStore&lt;/EM&gt;. Interesting is the "&lt;STRONG&gt;5400 NOTICE Failed-Attempt&lt;/STRONG&gt;" entry. But I can't find the "FailureReason" as described in &lt;A href="http://www.cisco.com/en/US/docs/security/ibf/setup_guide/ibf10_log_msgs.html"&gt;http://www.cisco.com/en/US/docs/security/ibf/setup_guide/ibf10_log_msgs.html&lt;/A&gt;: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2012-08-03 13:52:37.498 +01:00 0057180965 11003 DEBUG RADIUS: Returned RADIUS Access-Reject, IBFVersion=ibf-1.0 (win32), ConfigVersionId=9, Device IP Address=192.168.11.1, Device Port=1025, DestinationIPAddress=0.0.0.0, DestinationPort=1645, RadiusPacketType=AccessRequest, RadiusIdentifier=35, User-Name=192.168.52.97, NAS-IP-Address=192.168.11.1, cisco-av-pair=entity-attr:request=*, cisco-av-pair=entity-attr:entity-id:ip=192.168.52.97, cisco-av-pair=entity-attr:cntl:notify=true, IbfSessionID=s00752/132508682/7488750, SelectedAccessService=Network Access, Response={RadiusPacketType=AccessReject; },&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2012-08-03 13:52:37.498 +01:00 0057180966 &lt;STRONG&gt;5400 NOTICE Failed-Attempt&lt;/STRONG&gt;: IBF request failed, IBFVersion=ibf-1.0 (win32), ConfigVersionId=9, Device IP Address=192.168.11.1, Device Port=1025, DestinationIPAddress=0.0.0.0, DestinationPort=1645, RadiusPacketType=AccessRequest, UserName=192.168.52.97, Protocol=Radius, RequestLatency=3, NetworkDeviceName=fwa1, User-Name=192.168.52.97, NAS-IP-Address=192.168.11.1, cisco-av-pair=entity-attr:request=*, cisco-av-pair=entity-attr:entity-id:ip=192.168.52.97, cisco-av-pair=entity-attr:cntl:notify=true, IbfSessionID=s00752/132508682/7488750, SelectedAccessService=Network Access, Step=11001 , Step=11017 , Step=15012 , Step=12864 , Step=12866 , Step=11003 , Response={RadiusPacketType=AccessReject; },&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2012-08-03 13:52:37.500 +01:00 0057180967 11001 DEBUG RADIUS: Received RADIUS Access-Request, IBFVersion=ibf-1.0 (win32), ConfigVersionId=9, Device IP Address=192.168.11.1, Device Port=1025, DestinationIPAddress=0.0.0.0, DestinationPort=1645, IbfSessionID=s00752/132508682/7488751, &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2012-08-03 13:52:37.500 +01:00 0057180968 11017 DEBUG RADIUS: RADIUS created a new session, IBFVersion=ibf-1.0 (win32), ConfigVersionId=9, Device IP Address=192.168.11.1, Device Port=1025, DestinationIPAddress=0.0.0.0, DestinationPort=1645, IbfSessionID=s00752/132508682/7488751, &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2012-08-03 13:52:37.501 +01:00 0057180969 15012 DEBUG Policy: Selected Access Service, IBFVersion=ibf-1.0 (win32), ConfigVersionId=9, Device IP Address=192.168.11.1, UserName=10.25.170.248, Protocol=Radius, Time And Date=1343994757, PolicyType=ServiceSelectionPolicy, IbfSessionID=s00752/132508682/7488751, SelectedAccessService=Network Access, &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Have a nice Weekend! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Walter&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 03 Aug 2012 12:49:42 GMT</pubDate>
    <dc:creator>WALTER GROSSENBACHER</dc:creator>
    <dc:date>2012-08-03T12:49:42Z</dc:date>
    <item>
      <title>Identity Based Firewall doesn't work using Citrix Published Desktop environment</title>
      <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980602#M401522</link>
      <description>&lt;P&gt;Hi!&lt;/P&gt;&lt;P&gt;We are using the newest release of AD Agent (1.0.0.32.1, built 598). The ASA Firewalls 5520 are having the software release 8.4(3)8 installed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem:&lt;/P&gt;&lt;P&gt;When somebody tries to connect thru the Identity based firewalls from a citrix published desktop environment (PDI) the connection is not possible. Checking the ip-of-user mapping on the firewalls (show user-identity ip-of-user USERNAME) mostly doesn't show the mapping of the USERNAME and the PDI the user is logged in. The user-of-ip mapping of the PDIs IP-address shows mostly other users, which then are used to authenticate the acces thru the firewalls.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What is interesting, that on the AD Agent using "adacfg.exe cache list | find /i "USERNAME"" i can't see the PDIs IP-address neither because it is mapped to another user.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Questions:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is Citrix Published Desktop environment supported to connect thru Identity based Firewalls?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anybody knows how AD Agent, Domain Controllers and Firewalls are working together?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the firewalls with "show user-identity ad-agent we see, the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authentication Port: udp/1645&lt;/P&gt;&lt;P&gt;Accounting Port: udp/1646&lt;/P&gt;&lt;P&gt;ASA Listening Port: udp/3799&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why Cisco does use 1645 and 1646 and not 1812 and 1813?&lt;/P&gt;&lt;P&gt;The Listening Port is used for what purpose?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Remark: we tried the AD Agent modes full- download and on-demand with the same effect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for your replies&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Walter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 23:35:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980602#M401522</guid>
      <dc:creator>WALTER GROSSENBACHER</dc:creator>
      <dc:date>2019-03-11T23:35:26Z</dc:date>
    </item>
    <item>
      <title>Identity Based Firewall doesn't work using Citrix Published Desk</title>
      <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980603#M401523</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Is Citrix Published Desktop environment supported to connect thru Identity based Firewalls? I dont think that is a problem we need to see if they are a member of the domain or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are these desktop environments joined to the domain or are you using local accounts to access these desktops? Also does it work fine with laptops?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anybody knows how AD Agent, Domain Controllers and Firewalls are working together?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;ADagent is supposed to monitor the login events on the domain controller in order to build the user to ip mapping the firewalls connect to the adagent using radius. (&lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/access_idfw.html#wp1287981"&gt;http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/access_idfw.html#wp1287981&lt;/A&gt;&lt;SPAN&gt;)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On the firewalls with "show user-identity ad-agent we see, the following:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Authentication Port: udp/1645 - this is the legacy port for radius still in use today&lt;/P&gt;&lt;P&gt;Accounting Port: udp/1646 - same as above but for accounting&lt;/P&gt;&lt;P&gt;ASA Listening Port: udp/3799 - this is typically used for CoA change of authorization, but I am not sure if the ad agent can dynamically terminate sessions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why Cisco does use 1645 and 1646 and not 1812 and 1813? My assumption is that these are the ports that the are used when in adagent mode, both of these ports shouldnt be a problem to use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Listening Port is used for what purpose? That is a good question but we will someone else to confirm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 28 Jul 2012 07:46:07 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980603#M401523</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-28T07:46:07Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Based Firewall doesn't work using Citrix Published</title>
      <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980604#M401524</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are these desktop environments joined to the domain or are you using local accounts to access these desktops? Also does it work fine with laptops?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;The desktop environments are joined to the domain. Working with laptops and/or workstation works fine.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ADagent is supposed to monitor the login events on the domain controller in order to build the user to ip mapping the firewalls connect to the adagent using radius. (http://www.cisco.com/en/US/docs/security/asa/asa84/configuration/guide/access_idfw.html#wp1287981)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE level="1"&gt;&lt;P&gt;Thanks for this. It explains everything except the listening port.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Why Cisco does use 1645 and 1646 and not 1812 and 1813? My assumption is that these are the ports that the are used when in adagent mode, both of these ports shouldnt be a problem to use.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;This is my oppinion as well &lt;SPAN __jive_emoticon_name="happy"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The Listening Port is used for what purpose? That is a good question but we will someone else to confirm.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;gt;This would be great!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;New question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For the LDAP communication between AD Agent and the DCs is it better to use LDAPS (TCP Port 636) or LDAP (TCP Port 389)? ( is one of these protocols recommended?)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More informations about the problem we have with the public desktops:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As we have only one user-of-ip mapping of each IP-Address on the AD Agent and there are more users using the same IP-Address we mostly see the last user that logged in on the affected IP-Address (public desktop environment). I think that is the problem we have. What do you think?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Walter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 05:50:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980604#M401524</guid>
      <dc:creator>WALTER GROSSENBACHER</dc:creator>
      <dc:date>2012-07-30T05:50:05Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Based Firewall doesn't work using Citrix Published</title>
      <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980605#M401525</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Walter,&lt;/P&gt;&lt;P&gt;New question:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For&amp;nbsp; the LDAP communication between AD Agent and the DCs is it better to use&amp;nbsp; LDAPS (TCP Port 636) or LDAP (TCP Port 389)? ( is one of these&amp;nbsp; protocols recommended?) &lt;STRONG&gt;This is entirely up to you, ldaps provide more security since the the ldap search is performed over ssl.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;More informations about the problem we have with the public desktops:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As&amp;nbsp; we have only one user-of-ip mapping of each IP-Address on the AD Agent&amp;nbsp; and there are more users using the same IP-Address we mostly see the&amp;nbsp; last user that logged in on the affected IP-Address (public desktop&amp;nbsp; environment). I think that is the problem we have. What do you think? &lt;STRONG&gt;After a little bit of reasearch it seems as if the security logs are not replicated amongst all DCs in the domain. I wonder if the client is logging on through one domain controllers then logging off on a different domain controller. When you first configured the adagent, did you run an nslookup from both the member server and the client machine to see if you added all the domain controllers in the adagent configuration? If so, does this adagent have access to all the domain controllers?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 06:49:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980605#M401525</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-30T06:49:11Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Based Firewall doesn't work using Citrix Published</title>
      <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980606#M401526</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There are no Firewalls between the AD-Agent and the DCs. We checked the names using nslookup. Everything ok. I asked our AD responsibles to doublecheck the firewall settings and the logs on the DCs and on the AD Agent. As soon i get an answer I will let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What I saw on the firewalls is, that just one (the first) DC is communicating with the firewalls. Is this normal?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;fw-1# show aaa-server protocol ldap&lt;/P&gt;&lt;P&gt;Server Group:    AD-ALL&lt;/P&gt;&lt;P&gt;Server Protocol: ldap&lt;/P&gt;&lt;P&gt;Server Address:  192.168.229.30&lt;/P&gt;&lt;P&gt;Server port:     0&lt;/P&gt;&lt;P&gt;Server status:   ACTIVE, Last transaction at unknown&lt;/P&gt;&lt;P&gt;Number of pending requests              0&lt;/P&gt;&lt;P&gt;Average round trip time                 0ms&lt;/P&gt;&lt;P&gt;Number of authentication requests       114&lt;/P&gt;&lt;P&gt;Number of authorization requests        0&lt;/P&gt;&lt;P&gt;Number of accounting requests           0&lt;/P&gt;&lt;P&gt;Number of retransmissions               0&lt;/P&gt;&lt;P&gt;Number of accepts                       114&lt;/P&gt;&lt;P&gt;Number of rejects                       0&lt;/P&gt;&lt;P&gt;Number of challenges                    0&lt;/P&gt;&lt;P&gt;Number of malformed responses           0&lt;/P&gt;&lt;P&gt;Number of bad authenticators            0&lt;/P&gt;&lt;P&gt;Number of timeouts                      0&lt;/P&gt;&lt;P&gt;Number of unrecognized responses        0&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Server Group:    AD-ALL&lt;/P&gt;&lt;P&gt;Server Protocol: ldap&lt;/P&gt;&lt;P&gt;Server Address:  192.168.229.31&lt;/P&gt;&lt;P&gt;Server port:     0&lt;/P&gt;&lt;P&gt;Server status:   ACTIVE, Last transaction at unknown&lt;/P&gt;&lt;P&gt;Number of pending requests              0&lt;/P&gt;&lt;P&gt;Average round trip time                 0ms&lt;/P&gt;&lt;P&gt;Number of authentication requests       0&lt;/P&gt;&lt;P&gt;Number of authorization requests        0&lt;/P&gt;&lt;P&gt;Number of accounting requests           0&lt;/P&gt;&lt;P&gt;Number of retransmissions               0&lt;/P&gt;&lt;P&gt;Number of accepts                       0&lt;/P&gt;&lt;P&gt;Number of rejects                       0&lt;/P&gt;&lt;P&gt;Number of challenges                    0&lt;/P&gt;&lt;P&gt;Number of malformed responses           0&lt;/P&gt;&lt;P&gt;Number of bad authenticators            0&lt;/P&gt;&lt;P&gt;Number of timeouts                      0&lt;/P&gt;&lt;P&gt;Number of unrecognized responses        0&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Server Group:    AD-ALL&lt;/P&gt;&lt;P&gt;Server Protocol: ldap&lt;/P&gt;&lt;P&gt;Server Address:  192.168.229.39&lt;/P&gt;&lt;P&gt;Server port:     0&lt;/P&gt;&lt;P&gt;Server status:   ACTIVE, Last transaction at unknown&lt;/P&gt;&lt;P&gt;Number of pending requests              0&lt;/P&gt;&lt;P&gt;Average round trip time                 0ms&lt;/P&gt;&lt;P&gt;Number of authentication requests       0&lt;/P&gt;&lt;P&gt;Number of authorization requests        0&lt;/P&gt;&lt;P&gt;Number of accounting requests           0&lt;/P&gt;&lt;P&gt;Number of retransmissions               0&lt;/P&gt;&lt;P&gt;Number of accepts                       0&lt;/P&gt;&lt;P&gt;Number of rejects                       0&lt;/P&gt;&lt;P&gt;Number of challenges                    0&lt;/P&gt;&lt;P&gt;Number of malformed responses           0&lt;/P&gt;&lt;P&gt;Number of bad authenticators            0&lt;/P&gt;&lt;P&gt;Number of timeouts                      0&lt;/P&gt;&lt;P&gt;Number of unrecognized responses        0&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Server Group:    AD-ALL&lt;/P&gt;&lt;P&gt;Server Protocol: ldap&lt;/P&gt;&lt;P&gt;Server Address:  192.168.229.40&lt;/P&gt;&lt;P&gt;Server port:     0&lt;/P&gt;&lt;P&gt;Server status:   ACTIVE, Last transaction at unknown&lt;/P&gt;&lt;P&gt;Number of pending requests              0&lt;/P&gt;&lt;P&gt;Average round trip time                 0ms&lt;/P&gt;&lt;P&gt;Number of authentication requests       0&lt;/P&gt;&lt;P&gt;Number of authorization requests        0&lt;/P&gt;&lt;P&gt;Number of accounting requests           0&lt;/P&gt;&lt;P&gt;Number of retransmissions               0&lt;/P&gt;&lt;P&gt;Number of accepts                       0&lt;/P&gt;&lt;P&gt;Number of rejects                       0&lt;/P&gt;&lt;P&gt;Number of challenges                    0&lt;/P&gt;&lt;P&gt;Number of malformed responses           0&lt;/P&gt;&lt;P&gt;Number of bad authenticators            0&lt;/P&gt;&lt;P&gt;Number of timeouts                      0&lt;/P&gt;&lt;P&gt;Number of unrecognized responses        0&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Server Group:    AD-ALL&lt;/P&gt;&lt;P&gt;Server Protocol: ldap&lt;/P&gt;&lt;P&gt;Server Address:  192.168.229.41&lt;/P&gt;&lt;P&gt;Server port:     0&lt;/P&gt;&lt;P&gt;Server status:   ACTIVE, Last transaction at unknown&lt;/P&gt;&lt;P&gt;Number of pending requests              0&lt;/P&gt;&lt;P&gt;Average round trip time                 0ms&lt;/P&gt;&lt;P&gt;Number of authentication requests       0&lt;/P&gt;&lt;P&gt;Number of authorization requests        0&lt;/P&gt;&lt;P&gt;Number of accounting requests           0&lt;/P&gt;&lt;P&gt;Number of retransmissions               0&lt;/P&gt;&lt;P&gt;Number of accepts                       0&lt;/P&gt;&lt;P&gt;Number of rejects                       0&lt;/P&gt;&lt;P&gt;Number of challenges                    0&lt;/P&gt;&lt;P&gt;Number of malformed responses           0&lt;/P&gt;&lt;P&gt;Number of bad authenticators            0&lt;/P&gt;&lt;P&gt;Number of timeouts                      0&lt;/P&gt;&lt;P&gt;Number of unrecognized responses        0&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;Server Group:    AD-ALL&lt;/P&gt;&lt;P&gt;Server Protocol: ldap&lt;/P&gt;&lt;P&gt;Server Address:  192.168.229.42&lt;/P&gt;&lt;P&gt;Server port:     0&lt;/P&gt;&lt;P&gt;Server status:   ACTIVE, Last transaction at unknown&lt;/P&gt;&lt;P&gt;Number of pending requests              0&lt;/P&gt;&lt;P&gt;Average round trip time                 0ms&lt;/P&gt;&lt;P&gt;Number of authentication requests       0&lt;/P&gt;&lt;P&gt;Number of authorization requests        0&lt;/P&gt;&lt;P&gt;Number of accounting requests           0&lt;/P&gt;&lt;P&gt;Number of retransmissions               0&lt;/P&gt;&lt;P&gt;Number of accepts                       0&lt;/P&gt;&lt;P&gt;Number of rejects                       0&lt;/P&gt;&lt;P&gt;Number of challenges                    0&lt;/P&gt;&lt;P&gt;Number of malformed responses           0&lt;/P&gt;&lt;P&gt;Number of bad authenticators            0&lt;/P&gt;&lt;P&gt;Number of timeouts                      0&lt;/P&gt;&lt;P&gt;Number of unrecognized responses        0&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;fw-1# sho user-identity ad-agent                &lt;/P&gt;&lt;P&gt;Primary AD Agent:&lt;/P&gt;&lt;P&gt;Status                    up&lt;/P&gt;&lt;P&gt;Mode:                     on-demand&lt;/P&gt;&lt;P&gt;IP address:               192.168.11.8&lt;/P&gt;&lt;P&gt;Authentication port:      udp/1645&lt;/P&gt;&lt;P&gt;Accounting port:          udp/1646&lt;/P&gt;&lt;P&gt;ASA listening port:       udp/3799&lt;/P&gt;&lt;P&gt;Interface:                Intranet&lt;/P&gt;&lt;P&gt;Up time:                  1 day 0 hours&lt;/P&gt;&lt;P&gt;Average RTT:              0 msec&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;AD Domain Status:&lt;/P&gt;&lt;P&gt;Domain DOMAIN:              up&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;fw-1#&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 30 Jul 2012 07:22:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980606#M401526</guid>
      <dc:creator>WALTER GROSSENBACHER</dc:creator>
      <dc:date>2012-07-30T07:22:38Z</dc:date>
    </item>
    <item>
      <title>Identity Based Firewall doesn't work using Citrix Published Desk</title>
      <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980607#M401527</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is normal if the first DC stays up, meaning it hasnt had to failover to another DC. However this is needed in order to authenticate your vpn users is my assumption. For the identity firewall this is done through radius and it is supposed to hit the adagent using radius, then the adagent should be monitoring the event logs and the ASA should fire a netbios probe in order to the domain\user of the user trying to traverse the firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope that helps,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2012 04:17:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980607#M401527</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-31T04:17:45Z</dc:date>
    </item>
    <item>
      <title>Identity Based Firewall doesn't work using Citrix Published Desk</title>
      <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980608#M401528</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Also one thing to consider, and i dont know if you currently use this but if the shared workstations are on their own subnet you can consider cut-through proxy for internet access in order to speed up the user-to-ip mappings?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2012 04:23:44 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980608#M401528</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-07-31T04:23:44Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Based Firewall doesn't work using Citrix Published</title>
      <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980609#M401529</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your replies. I'm still waiting for the feedback of our AD responsibles. As soon I get their feedback I will let you know.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Walter&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2012 06:33:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980609#M401529</guid>
      <dc:creator>WALTER GROSSENBACHER</dc:creator>
      <dc:date>2012-07-31T06:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Based Firewall doesn't work using Citrix Published</title>
      <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980610#M401530</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tarik&lt;/P&gt;&lt;P&gt;Cut-trough-proxy is not an option. I'm still waiting for the feedback of our Windows Team.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Sent from Cisco Technical Support iPad App&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2012 11:15:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980610#M401530</guid>
      <dc:creator>WALTER GROSSENBACHER</dc:creator>
      <dc:date>2012-07-31T11:15:00Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Based Firewall doesn't work using Citrix Published</title>
      <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980611#M401531</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I got more information about or AD infrastructure. (Picture modified for internet use &lt;SPAN __jive_emoticon_name="wink" __jive_macro_name="emoticon" class="jive_macro jive_emote" src="https://community.cisco.com/images/emoticons/wink.gif"&gt;&lt;/SPAN&gt;)&lt;/P&gt;&lt;P&gt;The users we are using to cross the Identity Based Firewalls (IDBF) are all part of the green domain called DOMAIN.&lt;/P&gt;&lt;P&gt;All servers in the domain DOMAIN (green), except the one in the DMZ, whitch is a "Read Only DC" are configured on the Firewalls and on the AD Agent.&lt;/P&gt;&lt;P&gt;Is it necessary, that we have to configure the DCs of the root domain as well?&lt;/P&gt;&lt;P&gt;And about the DC in the DMZ? Is it necessary that we have to configure this one as well, even when it's configured as "Read Only DC"?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="http://supportforums.cisco.com/sites/default/files/legacy/2/2/6/96622-SNAG-2012-08-03-0000.png" class="jive-image" /&gt; &lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;Walter&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2012 07:04:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980611#M401531</guid>
      <dc:creator>WALTER GROSSENBACHER</dc:creator>
      <dc:date>2012-08-03T07:04:05Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Based Firewall doesn't work using Citrix Published</title>
      <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980612#M401532</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The configuration looks fine, I have a question regarding the machine that the ADAgent is installed on, was it already joined to the Green Domain before the AD Agent was installed? You dont have to configure the root domain controllers since the users you are authenticating are a member of the green domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I wanted to know if you can verify that all the domain controllers of the Green Domain have these steps and meet these requirements (I hate to reference this material but it looks like you are hitting this issue):&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="http://support.microsoft.com/kb/973995"&gt;http://support.microsoft.com/kb/973995&lt;/A&gt; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A name="wp1064810"&gt;&lt;/A&gt; &lt;/P&gt;&lt;P&gt; This patch fixes a memory leak in Microsoft's WMI, which if left unfixed&amp;nbsp; can sporadically prevent Active Directory from writing the necessary&amp;nbsp; authentication-related events to the Security Log for that domain&amp;nbsp; controller and would prevent the AD Agent from learning about the&amp;nbsp; mappings corresponding to some of the user logins that authenticate&amp;nbsp; through that domain controller. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ibf/setup_guide/ibf10_install.html#wp1060694"&gt;http://www.cisco.com/en/US/docs/security/ibf/setup_guide/ibf10_install.html#wp1060694&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2012 07:30:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980612#M401532</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-08-03T07:30:19Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Based Firewall doesn't work using Citrix Published</title>
      <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980613#M401533</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;If you can reproduce this issue please issue "debug user-identity" on the ASA and can you set the debug logs on the IDFW and send a timestamp of when you can reproduce this issue?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Adagent debug section &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/ibf/setup_guide/ibf10_troubleshooting.html#wp1147840"&gt;http://www.cisco.com/en/US/docs/security/ibf/setup_guide/ibf10_troubleshooting.html#wp1147840&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2012 08:08:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980613#M401533</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-08-03T08:08:21Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Based Firewall doesn't work using Citrix Published</title>
      <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980614#M401534</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you Tarik!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But what you didn't know is, that we are using domain controller machines running Windows Server 2008 R2 with SP1 installed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Referencing your Link (&lt;A href="http://www.cisco.com/en/US/docs/security/ibf/setup_guide/ibf10_install.html#wp1060694"&gt;http://www.cisco.com/en/US/docs/security/ibf/setup_guide/ibf10_install.html#wp1060694&lt;/A&gt;&lt;span class="lia-unicode-emoji" title=":disappointed_face:"&gt;😞&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;For domain controller machines running Windows Server 2008 R2, the following Microsoft hotfix must be installed (unless SP1 is installed):&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;A name="wp1064813"&gt;&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;A href="http://support.microsoft.com/kb/981314"&gt;http://support.microsoft.com/kb/981314&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;A name="wp1064814"&gt;&lt;/A&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;This patch fixes a memory leak in Microsoft's WMI, which if left unfixed can sporadically prevent Active Directory from writing the necessary authentication-related events to the Security Log for that domain controller and would prevent the AD Agent from learning about the mappings corresponding to some of the user logins that authenticate through that domain controller.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In our case. We doesn't have to install any patch fix.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Walter&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2012 08:37:03 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980614#M401534</guid>
      <dc:creator>WALTER GROSSENBACHER</dc:creator>
      <dc:date>2012-08-03T08:37:03Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Based Firewall doesn't work using Citrix Published</title>
      <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980615#M401535</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the update. Our option now is to run the debug as the issue is reproduced on the ASA and the ADagent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2012 08:40:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980615#M401535</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-08-03T08:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Based Firewall doesn't work using Citrix Published</title>
      <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980616#M401536</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That is what I'm doing next. I will inform you as soon i have some results.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Walter&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2012 08:45:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980616#M401536</guid>
      <dc:creator>WALTER GROSSENBACHER</dc:creator>
      <dc:date>2012-08-03T08:45:26Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Based Firewall doesn't work using Citrix Published</title>
      <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980617#M401537</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tarik!&lt;/P&gt;&lt;P&gt;I got some output out of the &lt;EM&gt;c:\IBF\radiusServer\runtime\logs\localStore&lt;/EM&gt;. Interesting is the "&lt;STRONG&gt;5400 NOTICE Failed-Attempt&lt;/STRONG&gt;" entry. But I can't find the "FailureReason" as described in &lt;A href="http://www.cisco.com/en/US/docs/security/ibf/setup_guide/ibf10_log_msgs.html"&gt;http://www.cisco.com/en/US/docs/security/ibf/setup_guide/ibf10_log_msgs.html&lt;/A&gt;: &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2012-08-03 13:52:37.498 +01:00 0057180965 11003 DEBUG RADIUS: Returned RADIUS Access-Reject, IBFVersion=ibf-1.0 (win32), ConfigVersionId=9, Device IP Address=192.168.11.1, Device Port=1025, DestinationIPAddress=0.0.0.0, DestinationPort=1645, RadiusPacketType=AccessRequest, RadiusIdentifier=35, User-Name=192.168.52.97, NAS-IP-Address=192.168.11.1, cisco-av-pair=entity-attr:request=*, cisco-av-pair=entity-attr:entity-id:ip=192.168.52.97, cisco-av-pair=entity-attr:cntl:notify=true, IbfSessionID=s00752/132508682/7488750, SelectedAccessService=Network Access, Response={RadiusPacketType=AccessReject; },&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2012-08-03 13:52:37.498 +01:00 0057180966 &lt;STRONG&gt;5400 NOTICE Failed-Attempt&lt;/STRONG&gt;: IBF request failed, IBFVersion=ibf-1.0 (win32), ConfigVersionId=9, Device IP Address=192.168.11.1, Device Port=1025, DestinationIPAddress=0.0.0.0, DestinationPort=1645, RadiusPacketType=AccessRequest, UserName=192.168.52.97, Protocol=Radius, RequestLatency=3, NetworkDeviceName=fwa1, User-Name=192.168.52.97, NAS-IP-Address=192.168.11.1, cisco-av-pair=entity-attr:request=*, cisco-av-pair=entity-attr:entity-id:ip=192.168.52.97, cisco-av-pair=entity-attr:cntl:notify=true, IbfSessionID=s00752/132508682/7488750, SelectedAccessService=Network Access, Step=11001 , Step=11017 , Step=15012 , Step=12864 , Step=12866 , Step=11003 , Response={RadiusPacketType=AccessReject; },&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2012-08-03 13:52:37.500 +01:00 0057180967 11001 DEBUG RADIUS: Received RADIUS Access-Request, IBFVersion=ibf-1.0 (win32), ConfigVersionId=9, Device IP Address=192.168.11.1, Device Port=1025, DestinationIPAddress=0.0.0.0, DestinationPort=1645, IbfSessionID=s00752/132508682/7488751, &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2012-08-03 13:52:37.500 +01:00 0057180968 11017 DEBUG RADIUS: RADIUS created a new session, IBFVersion=ibf-1.0 (win32), ConfigVersionId=9, Device IP Address=192.168.11.1, Device Port=1025, DestinationIPAddress=0.0.0.0, DestinationPort=1645, IbfSessionID=s00752/132508682/7488751, &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;2012-08-03 13:52:37.501 +01:00 0057180969 15012 DEBUG Policy: Selected Access Service, IBFVersion=ibf-1.0 (win32), ConfigVersionId=9, Device IP Address=192.168.11.1, UserName=10.25.170.248, Protocol=Radius, Time And Date=1343994757, PolicyType=ServiceSelectionPolicy, IbfSessionID=s00752/132508682/7488751, SelectedAccessService=Network Access, &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt; &lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Have a nice Weekend! &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Walter&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2012 12:49:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980617#M401537</guid>
      <dc:creator>WALTER GROSSENBACHER</dc:creator>
      <dc:date>2012-08-03T12:49:42Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Based Firewall doesn't work using Citrix Published</title>
      <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980618#M401538</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Walt,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Are all authentication requests failing? If not, then we need to see if you can get TAC involved. It seems as if either the ip mapping isnt available on the ADAgent.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However did you get a chance to cross reference the IP mapping at the time this occured?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Tarik Admani &lt;BR /&gt;*Please rate helpful posts*&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 03 Aug 2012 15:41:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980618#M401538</guid>
      <dc:creator>Tarik Admani</dc:creator>
      <dc:date>2012-08-03T15:41:02Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Based Firewall doesn't work using Citrix Published</title>
      <link>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980619#M401539</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tarik!&lt;/P&gt;&lt;P&gt;I will make more debugging tomorrow together with a Windows Specialist. I'll inform you about the results tomorrow. What we will do as well is to collect informations to open a TAC case if necessary.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Walter &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 06 Aug 2012 06:29:24 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/identity-based-firewall-doesn-t-work-using-citrix-published/m-p/1980619#M401539</guid>
      <dc:creator>WALTER GROSSENBACHER</dc:creator>
      <dc:date>2012-08-06T06:29:24Z</dc:date>
    </item>
  </channel>
</rss>

