<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Change Identity Source and retain Rules in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/change-identity-source-and-retain-rules/m-p/3883187#M923194</link>
    <description>&lt;P&gt;Do you mean change the Identity Source from Firepower User Agent to ISE? The Firepower receives user to IP mappings from the identity source, while the AD user and group information comes directly from AD or LDAP (Realm configuration). Your Firepower ACP and Identity Rules reference your Realm configuration, so as long as that remains the same, you would not need to change anything.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jul 2019 12:40:25 GMT</pubDate>
    <dc:creator>Rahul Govindan</dc:creator>
    <dc:date>2019-07-02T12:40:25Z</dc:date>
    <item>
      <title>Change Identity Source and retain Rules</title>
      <link>https://community.cisco.com/t5/network-security/change-identity-source-and-retain-rules/m-p/3882199#M923193</link>
      <description>&lt;P&gt;My FMC is configured with Active Directory as Identity Source.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a rule that blocks websites categorized as Gambling for AD user group "RestrictedUsers".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now, I want to change my Identity Source from AD to ISE and retain the existing Rule i.e., AD Group "RestrictedUsers" should not access "Gambling" websites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do I change anything in the existing rules or simply changing Identity Source from AD to ISE will do?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:15:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-identity-source-and-retain-rules/m-p/3882199#M923193</guid>
      <dc:creator>InTheJuniverse</dc:creator>
      <dc:date>2020-02-21T17:15:26Z</dc:date>
    </item>
    <item>
      <title>Re: Change Identity Source and retain Rules</title>
      <link>https://community.cisco.com/t5/network-security/change-identity-source-and-retain-rules/m-p/3883187#M923194</link>
      <description>&lt;P&gt;Do you mean change the Identity Source from Firepower User Agent to ISE? The Firepower receives user to IP mappings from the identity source, while the AD user and group information comes directly from AD or LDAP (Realm configuration). Your Firepower ACP and Identity Rules reference your Realm configuration, so as long as that remains the same, you would not need to change anything.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 12:40:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-identity-source-and-retain-rules/m-p/3883187#M923194</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2019-07-02T12:40:25Z</dc:date>
    </item>
    <item>
      <title>Re: Change Identity Source and retain Rules</title>
      <link>https://community.cisco.com/t5/network-security/change-identity-source-and-retain-rules/m-p/3884562#M923195</link>
      <description>&lt;P&gt;Thank you, Govindhan.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I may have used incorrect terminology, I'll rephrase.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My Current Setup:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Though we have a user agent configured, we aren't using it for it's purpose, as in, it just exists here and not installed on AD etc, so it's just sitting there. The problem is, the user agent isn't reliable, as far as we have noticed, it maintains the so called 'state table of last connection for a user', and even if they change the IP address, it records the old IP, not new. So, we want information to come from AD and ISE, so that we have end to end visibility of the username and IP address.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My ACP:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ACP.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/40073i313DD6D2DA1A549A/image-size/large?v=v2&amp;amp;px=999" role="button" title="ACP.png" alt="ACP.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am creating a Policy to Allow URL xyz to AD Group "_Contracts_Admin", and this authentication / authorization (?) is I believe happening on AD?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I want the authentication / authorisation to happen on ISE instead of AD, as it is our contralized AAA server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: ISE is integrated with AD and I have rules on ISE for authentication / authorisation to network&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;What do I change to achieve this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have already configure Identity Services Engine under Integration &amp;gt; Identity Sources&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ise integrated.png" style="width: 997px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/40074i5903752820BA3D31/image-size/large?v=v2&amp;amp;px=999" role="button" title="ise integrated.png" alt="ise integrated.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 11:09:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/change-identity-source-and-retain-rules/m-p/3884562#M923195</guid>
      <dc:creator>InTheJuniverse</dc:creator>
      <dc:date>2019-07-04T11:09:36Z</dc:date>
    </item>
  </channel>
</rss>

