<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: USER-IP mapping FTD in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/user-ip-mapping-ftd/m-p/3988514#M922780</link>
    <description>&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Sun, 24 Nov 2019 14:37:12 GMT</pubDate>
    <dc:creator>hsangral</dc:creator>
    <dc:date>2019-11-24T14:37:12Z</dc:date>
    <item>
      <title>USER-IP mapping FTD</title>
      <link>https://community.cisco.com/t5/network-security/user-ip-mapping-ftd/m-p/3988505#M922771</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I understand that in order to Integrate FTD with ISE we need to perform PXgrid integration and add Active directory as a realm, which works well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What about the users performing Dot 1x authentication using ISE local Database, How does FTD fetch that information.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:43:04 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-ip-mapping-ftd/m-p/3988505#M922771</guid>
      <dc:creator>hsangral</dc:creator>
      <dc:date>2020-02-21T17:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: USER-IP mapping FTD</title>
      <link>https://community.cisco.com/t5/network-security/user-ip-mapping-ftd/m-p/3988509#M922774</link>
      <description>Hi,&lt;BR /&gt;The pxgrid integration between ISE and FTD would send all IP/User bindings to the FTD. However if the user is defined only in the ISE database, the AD realm defined on the FTD will not be able to query the group membership for those users. &lt;BR /&gt;&lt;BR /&gt;You could define rules on the FTD using SGTs (rather than query for group membership) that were assigned to those ISE local users or use AD to authenticate users.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Sun, 24 Nov 2019 14:22:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-ip-mapping-ftd/m-p/3988509#M922774</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-11-24T14:22:35Z</dc:date>
    </item>
    <item>
      <title>Re: USER-IP mapping FTD</title>
      <link>https://community.cisco.com/t5/network-security/user-ip-mapping-ftd/m-p/3988511#M922776</link>
      <description>&lt;HR /&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The SGT approach would not be applicable to a non sda environment.&lt;/P&gt;
&lt;P&gt;If the FTD is not using AD groups in the policies it would still fetch the Information ( user-ip mapping) and the ISE local username can be seen in the connection events ? In this case creation of realms would not be necessary. Correct me if i am wrong.&lt;/P&gt;</description>
      <pubDate>Sun, 24 Nov 2019 14:31:40 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-ip-mapping-ftd/m-p/3988511#M922776</guid>
      <dc:creator>hsangral</dc:creator>
      <dc:date>2019-11-24T14:31:40Z</dc:date>
    </item>
    <item>
      <title>Re: USER-IP mapping FTD</title>
      <link>https://community.cisco.com/t5/network-security/user-ip-mapping-ftd/m-p/3988513#M922778</link>
      <description>If you just want IP/User mappings in connections events, then I see no reason why that should not work. However if you want to use the Username/Group information in the ACP for enforcement then you'd need to learn the group mappings from the AD Realm, which is not possible if the user is in the ISE Local database.&lt;BR /&gt;&lt;BR /&gt;HTH</description>
      <pubDate>Sun, 24 Nov 2019 14:35:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-ip-mapping-ftd/m-p/3988513#M922778</guid>
      <dc:creator>Rob Ingram</dc:creator>
      <dc:date>2019-11-24T14:35:56Z</dc:date>
    </item>
    <item>
      <title>Re: USER-IP mapping FTD</title>
      <link>https://community.cisco.com/t5/network-security/user-ip-mapping-ftd/m-p/3988514#M922780</link>
      <description>&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 24 Nov 2019 14:37:12 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-ip-mapping-ftd/m-p/3988514#M922780</guid>
      <dc:creator>hsangral</dc:creator>
      <dc:date>2019-11-24T14:37:12Z</dc:date>
    </item>
  </channel>
</rss>

