<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic When a user authenticates in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636518#M920419</link>
    <description>&lt;P&gt;When a user authenticates using 802.1x over WiFi ACS/ISE I do not see a successful authentication event on a domain controller.&lt;/P&gt;&lt;P&gt;If you have ISE configured differently so that my wireless users will actually create an event in Windows that has a username in it I would be interested to see how you are doing that.&lt;/P&gt;&lt;P&gt;To the best of my knowledge that was not possible, which was why for CX/PRSM Cisco had to patch the CDA to parse out syslog from CX.&lt;/P&gt;</description>
    <pubDate>Thu, 12 Feb 2015 16:43:09 GMT</pubDate>
    <dc:creator>nrunge1</dc:creator>
    <dc:date>2015-02-12T16:43:09Z</dc:date>
    <item>
      <title>FireSight and ISE User Identity Integration</title>
      <link>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636516#M920417</link>
      <description>&lt;P&gt;We are wishing to migrate from CX/PRSM to FirePower/FireSight. I am researching feature parity.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Today I use the CDA integration with ISE to passively capture the user identity of 802.1x wireless authenticated employees.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The goal is to on demand produce reports that map a username to their traffic in a passive fashion.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I was told by a Cisco engineer that ISE was a consumable identiy source for FireSight in the same way that LDAP is with the User Agent. Furthermore I was assured that this was the case without having licensing for PXGRID.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am unable to find any information proving this to be true. The only thing I find is information on how to use ISE as an authentication method.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I do not want to authenticate users actively. I just want to scape username information for reporting purposes. I have read the following URL and it is not what I am looking for based on our current configuration.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118541-configure-firesight-00.html" target="_blank"&gt;http://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118541-configure-firesight-00.html&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 13:23:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636516#M920417</guid>
      <dc:creator>nrunge1</dc:creator>
      <dc:date>2020-02-21T13:23:46Z</dc:date>
    </item>
    <item>
      <title>You can get usernames</title>
      <link>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636517#M920418</link>
      <description>&lt;P&gt;You can get usernames directly in sourcefire with the User Agent (that runs on a Windows box). No need for ISE.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 14:58:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636517#M920418</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2015-02-12T14:58:37Z</dc:date>
    </item>
    <item>
      <title>When a user authenticates</title>
      <link>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636518#M920419</link>
      <description>&lt;P&gt;When a user authenticates using 802.1x over WiFi ACS/ISE I do not see a successful authentication event on a domain controller.&lt;/P&gt;&lt;P&gt;If you have ISE configured differently so that my wireless users will actually create an event in Windows that has a username in it I would be interested to see how you are doing that.&lt;/P&gt;&lt;P&gt;To the best of my knowledge that was not possible, which was why for CX/PRSM Cisco had to patch the CDA to parse out syslog from CX.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 16:43:09 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636518#M920419</guid>
      <dc:creator>nrunge1</dc:creator>
      <dc:date>2015-02-12T16:43:09Z</dc:date>
    </item>
    <item>
      <title>That is correct you will not</title>
      <link>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636519#M920420</link>
      <description>&lt;P&gt;That is&amp;nbsp;correct you will not see logon/logoff for users that authenticated to RADIUS. As far as I know there is no workaround. I'm hoping that some day soon sourcefire will use CDA instead of its own User Agent.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 20:00:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636519#M920420</guid>
      <dc:creator>Collin Clark</dc:creator>
      <dc:date>2015-02-12T20:00:49Z</dc:date>
    </item>
    <item>
      <title>I believe moving forward</title>
      <link>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636520#M920421</link>
      <description>&lt;P&gt;I believe moving forward Cisco plans to integrate these sort of multiple sources of user data via PxGrid. Though I'd prefer CDA as it appears more stable than SFUA.&lt;/P&gt;&lt;P&gt;There was some lab proof of concept work demonstrated at Cisco Live Milan a couple of weeks ago.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 20:55:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636520#M920421</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-02-12T20:55:36Z</dc:date>
    </item>
    <item>
      <title>The problem with PxGrid is</title>
      <link>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636521#M920422</link>
      <description>&lt;P&gt;The problem with PxGrid is that it requires additional ISE licensing.&lt;/P&gt;&lt;P&gt;From my org's point of view we bought into CX and it didn't have ISE RADIUS identity integration. We waited and then by the time we recieved it the CX platform was on it's way out after roughly two years.&lt;/P&gt;&lt;P&gt;At this point we basically got credited back every dime we put into CX and are going to pay the difference for SF but I go back to not having feature parity and potentially having to buy more licensing to get it.&lt;/P&gt;&lt;P&gt;This is all pretty absurd when you consider that I am not wanting to do anything more than parse out text and associate it with a matched IP.&lt;/P&gt;&lt;P&gt;I am still waiting to hear back from a Cisco SE that our sales rep put me in touch with. If I hear anything definitive I should at least be able to provide closure for anyone who hits this thread.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 21:25:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636521#M920422</guid>
      <dc:creator>nrunge1</dc:creator>
      <dc:date>2015-02-12T21:25:02Z</dc:date>
    </item>
    <item>
      <title>I agree - your points are</title>
      <link>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636522#M920423</link>
      <description>&lt;P&gt;I agree - your points are similar to the ones I've made myself to the Cisco Security CSEs I work with as a partner.&lt;/P&gt;&lt;P&gt;Add your voice to the choir -&amp;nbsp;that's how we get the responsible product manager&amp;nbsp;to make it a priority.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Feb 2015 21:36:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636522#M920423</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-02-12T21:36:34Z</dc:date>
    </item>
    <item>
      <title>The answer that I recieved</title>
      <link>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636523#M920424</link>
      <description>&lt;P&gt;The answer that I recieved was in line with these features coming first half of this year using pxGrid. There was one or two other workarounds mentioned but they aren't comprable to the way it is being done today in CX.&lt;/P&gt;&lt;P&gt;I am getting some quotes on adding Plus licensing to our ISE Base.&lt;/P&gt;&lt;P&gt;There is an upside in that ISE can use pxGrid technology to get identity from AD so the SourceFire Agent would be unnecessary and everything would just flow through ISE.&lt;/P&gt;&lt;P&gt;Between that and the fact that I have to license passive gear makes it a tough pill to swallow.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Feb 2015 20:50:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636523#M920424</guid>
      <dc:creator>nrunge1</dc:creator>
      <dc:date>2015-02-13T20:50:11Z</dc:date>
    </item>
    <item>
      <title>So to cap this thread off the</title>
      <link>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636524#M920425</link>
      <description>&lt;P&gt;So to cap this thread off the pricing on pxGrid isn't bad at all if that is all you want from ISE.&amp;nbsp;&lt;/P&gt;&lt;P&gt;pxGrid doesn't actually consume licenses. You can purchase the smallest cheapest PLUS license and get pxGrid/TrustSEC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have to admit that changes my initial position. It doesn't sound like the SF Agent was stable and in my experience neither was CDA.&amp;nbsp;&lt;/P&gt;&lt;P&gt;For the cost it absolutely makes the most sense to use ISE to pull that data.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 16 Feb 2015 15:04:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636524#M920425</guid>
      <dc:creator>nrunge1</dc:creator>
      <dc:date>2015-02-16T15:04:40Z</dc:date>
    </item>
    <item>
      <title>This feature has been bumped</title>
      <link>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636525#M920426</link>
      <description>&lt;P&gt;This feature has been bumped back in the timeline. Internal documentation will say second half of 2015 however the Cisco employees I spoke with said not to count on it until Q1 2016.&lt;/P&gt;</description>
      <pubDate>Wed, 18 Feb 2015 22:41:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636525#M920426</guid>
      <dc:creator>nrunge1</dc:creator>
      <dc:date>2015-02-18T22:41:36Z</dc:date>
    </item>
    <item>
      <title>So I used the FireSight AD</title>
      <link>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636526#M920427</link>
      <description>&lt;P&gt;So I used the FireSight AD Agent for the first time. I take back everything bad I said about the CDA, the AD Agent has proven to function far less consistently.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Jul 2015 21:56:49 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636526#M920427</guid>
      <dc:creator>nrunge1</dc:creator>
      <dc:date>2015-07-14T21:56:49Z</dc:date>
    </item>
    <item>
      <title>I agree. I complained loud</title>
      <link>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636527#M920428</link>
      <description>&lt;P&gt;I agree. I complained loud and clear to Cisco&amp;nbsp;product managers, CSEs and TMEs while I was at Cisco Live about the various identity integration solutions being all over the map.&lt;/P&gt;&lt;P&gt;None of them work particularly&amp;nbsp;well in my opinion (except perhaps ISE which is a great product but&amp;nbsp;by no means ubiquitous nor should it be a prerequisite to get user identity).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Jul 2015 03:49:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636527#M920428</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2015-07-15T03:49:42Z</dc:date>
    </item>
    <item>
      <title>Funny. That was pretty much</title>
      <link>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636528#M920429</link>
      <description>&lt;P&gt;Funny. That was pretty much our office conversation today. ISE is going to be perfect. For those that own ISE. &amp;nbsp;&lt;/P&gt;&lt;P&gt;Although upcharging for a technological pivot&amp;nbsp;that essentially provides the same feature isn't a new thing for Cisco.&amp;nbsp;&lt;/P&gt;&lt;P&gt;CX &amp;gt; FirePower&lt;/P&gt;&lt;P&gt;Show n Share &amp;gt; vBrick&lt;/P&gt;&lt;P&gt;DMM &amp;gt; AppSpace&lt;/P&gt;&lt;P&gt;TCS &amp;gt; Virtual TCS&lt;/P&gt;&lt;P&gt;MCU Bridge &amp;gt; Virtual Telepresence Server&lt;/P&gt;&lt;P&gt;VCS &amp;gt; CUCM&lt;/P&gt;&lt;P&gt;And that is just our last fiscal year.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 16 Jul 2015 02:09:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firesight-and-ise-user-identity-integration/m-p/2636528#M920429</guid>
      <dc:creator>nrunge1</dc:creator>
      <dc:date>2015-07-16T02:09:13Z</dc:date>
    </item>
  </channel>
</rss>

