<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: FMC 6.2.2 - Unknown Users in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3323173#M924664</link>
    <description>Had exact same issue but in my lab, Everything was configured correctly but the design of my network through an ASA 5515-X wasn't correct.&lt;BR /&gt;&lt;BR /&gt;There are also bugs associated with this issue which you can check on: tools.cisco.com/bugsearch&lt;BR /&gt;&lt;BR /&gt;Also, Have a pending TAC case open regarding some users reported as unknown while others are not working. Will update soon!&lt;BR /&gt;</description>
    <pubDate>Thu, 01 Feb 2018 08:38:43 GMT</pubDate>
    <dc:creator>nehmaan123</dc:creator>
    <dc:date>2018-02-01T08:38:43Z</dc:date>
    <item>
      <title>FMC 6.2.2 - Unknown Users</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3318029#M924657</link>
      <description>&lt;P&gt;Alright experts, I need some assistance because this isn't making a lick of sense.&amp;nbsp; I have a customer running FMC 6.2.2 and AD User Agent 2.3 that is having an issue where a lot of their connection events are showing Unkown under Initiator User.&amp;nbsp; Some users show their AD accounts but most do not.&amp;nbsp; The site is not using a proxy server and from my understanding this was working previously before the AD admin changed the rights of the user that was configured for the AD User Agent.&amp;nbsp; He configured the user according to this document:&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118637-configure-firesight-00.html" target="_blank"&gt;https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118637-configure-firesight-00.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As it sits, I'm going to see if we can test with an AD domain admin account just to see if it produces the same result.&amp;nbsp; I'm wondering if any of you have seen this behavior?&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 15:12:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3318029#M924657</guid>
      <dc:creator>Ryan Curry</dc:creator>
      <dc:date>2020-02-21T15:12:25Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2.2 - Unknown Users</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3318074#M924658</link>
      <description>Do you see any activity under the Analysis &amp;gt; Users &amp;gt; User activity section of the FMC? If this broke after a permissions change, I would try to reset it back to what is was and see if this starts showing all the users back. I have had to go through the "Troubleshoot" section of the document to configure the right permissions for a non-admin User agent user.</description>
      <pubDate>Wed, 24 Jan 2018 23:08:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3318074#M924658</guid>
      <dc:creator>Rahul Govindan</dc:creator>
      <dc:date>2018-01-24T23:08:15Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2.2 - Unknown Users</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3318076#M924659</link>
      <description>&lt;P&gt;Check out this trouble shooting guide.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118159-troubleshoot-firesite-00.html" target="_self"&gt;https://www.cisco.com/c/en/us/support/docs/security/firesight-management-center/118159-troubleshoot-firesite-00.html&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jan 2018 23:15:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3318076#M924659</guid>
      <dc:creator>Philip D'Ath</dc:creator>
      <dc:date>2018-01-24T23:15:13Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2.2 - Unknown Users</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3318549#M924660</link>
      <description>&lt;P&gt;Perfect, I'll check that out and see what I find.&amp;nbsp; Thank you Philip!&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 14:14:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3318549#M924660</guid>
      <dc:creator>Ryan Curry</dc:creator>
      <dc:date>2018-01-25T14:14:57Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2.2 - Unknown Users</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3318563#M924661</link>
      <description>&lt;P&gt;Yup, I'm getting a fair amount of users listed in there and most are discovered by passive authentication.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 14:38:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3318563#M924661</guid>
      <dc:creator>Ryan Curry</dc:creator>
      <dc:date>2018-01-25T14:38:14Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2.2 - Unknown Users</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3318799#M924662</link>
      <description>&lt;P&gt;So I did some more testing and can see one of the users I'm having the issue with log in.&amp;nbsp; Yet, when we do a test that hits a policy that should allow him through based on his ID it fails.&amp;nbsp; When I go to look at the event it still shows "unknown user" even though it shows his ID under Analysis&amp;gt;User&amp;gt;User Activity.&amp;nbsp; It's almost like it's not&amp;nbsp;correlating that Initiator User and the&amp;nbsp;Initiator IP.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Jan 2018 18:54:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3318799#M924662</guid>
      <dc:creator>Ryan Curry</dc:creator>
      <dc:date>2018-01-25T18:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2.2 - Unknown Users</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3323173#M924664</link>
      <description>Had exact same issue but in my lab, Everything was configured correctly but the design of my network through an ASA 5515-X wasn't correct.&lt;BR /&gt;&lt;BR /&gt;There are also bugs associated with this issue which you can check on: tools.cisco.com/bugsearch&lt;BR /&gt;&lt;BR /&gt;Also, Have a pending TAC case open regarding some users reported as unknown while others are not working. Will update soon!&lt;BR /&gt;</description>
      <pubDate>Thu, 01 Feb 2018 08:38:43 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3323173#M924664</guid>
      <dc:creator>nehmaan123</dc:creator>
      <dc:date>2018-02-01T08:38:43Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2.2 - Unknown Users</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3330251#M924667</link>
      <description>&lt;P&gt;Correct me if I'm wrong, but it looks like you're just doing passive authentication.&amp;nbsp; If that's the case, then you will see A LOT of unknown user activity.&amp;nbsp; This is because the system will only identify users when it is able to passively ID them through the identity policy you've setup.&amp;nbsp; Passive authentication through AD user agent has always been iffy for us, so we've never set internal policies based on user groups.&amp;nbsp; I've been told and have seen demos of it working MUCH better with Cisco ISE and AnyConnect as 802.1x agent.&amp;nbsp; &amp;nbsp;It's also worth noting that you can have that User Agent on up to 5 domain servers, which could also help.&amp;nbsp; I personally have only gotten the user-based control to work with the remote VPN users, since they're actively authenticated.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Feb 2018 17:32:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3330251#M924667</guid>
      <dc:creator>workforcesoftware</dc:creator>
      <dc:date>2018-02-13T17:32:36Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2.2 - Unknown Users</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3332514#M924668</link>
      <description>&lt;P&gt;So I was finally able to get a TAC engineer to work on the issue and after about 4 - 5 hours he was able to get the issue resolved I believe.&amp;nbsp; I know there was a bunch of hocus pocus he was doing in the CLI, but we believe the gist of the issue is that we had a second authentication realm that was causing issues even though it was inactive.&amp;nbsp; Once we removed that and gave it some time (about 24 hours) we were seeing the correct users versus either stale entries or Unknown.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I would suggest if experiencing this issue, check if there's an inactive realm and remove it and/or open a TAC case.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Feb 2018 14:59:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3332514#M924668</guid>
      <dc:creator>Ryan Curry</dc:creator>
      <dc:date>2018-02-16T14:59:26Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2.2 - Unknown Users</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3353429#M924669</link>
      <description>&lt;P&gt;I have the same problem on one of our clients and was solved by TAC.&lt;/P&gt;
&lt;P&gt;I'm going to post how we can identify this problem, but the solution sould be aplied by TAC. They used scripts to directly modify records on snort DB.&lt;/P&gt;
&lt;P&gt;If you can identify the problem, TAC can apply the scripts in a few minutes webex session.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Problem description:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;"User activity" show all users&lt;/P&gt;
&lt;P&gt;&amp;nbsp;Only a few was matched by policy, as seen on events.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What he do, was to check user-ip map.&lt;/P&gt;
&lt;P&gt;First, he created an script on manager and sensor, to see user-ip and user-group mappings.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FS:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;==============================
|          Database          |
==============================

##) IP Address [Realm ID]
 1) ::ffff:10.x.x.x [2]
 2) ::ffff:10.y.y.y [2]
 3) ::ffff:10.z.z.z [2]


##) Group Name (ID) [realm: Realm Name (ID)]
 1) Domain Users (6) [realm: xxx.local (2)]
 2) Restringidos (25) [realm: xxx.local (2)]
&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SFR:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;==============================
|          Database          |
==============================

No IP Addresses

##) Group Name (ID)
 1) Restringidos (25)
 2) Domain Users (6)
&lt;/PRE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then, and &lt;STRONG&gt;this can be done before calling TAC&lt;/STRONG&gt;, he checked the file with ip-user mappings.&lt;/P&gt;
&lt;P&gt;The file was 40k on FSight and only a few bytes on sensor.&lt;/P&gt;
&lt;P&gt;I figured out how it works. Sensor donwnload full file each 5min and make incremental updates on a separate file. So it has two, full, which should be same size as the file on manager, and a smallone.&lt;/P&gt;
&lt;P&gt;Expert mode command: &lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;ls -halt /var/sf/user_enforcement/&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;SFR, not working:&lt;/P&gt;
&lt;P&gt;&lt;FONT size="2" face="courier new,courier"&gt;root@SFR2:/var/sf/user_enforcement# ls -halt&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;total 60K&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;-rw-r--r--&amp;nbsp; 1 root root&amp;nbsp; 497 Mar 22 16:28 user_ip_map.1521735637&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;drwxr-xr-x&amp;nbsp; 2 www&amp;nbsp; www&amp;nbsp; 4.0K Mar 22 16:21 .&lt;BR /&gt;&lt;/FONT&gt;&lt;FONT size="2" face="courier new,courier"&gt;-rw-r--r--&amp;nbsp; 1 root root&amp;nbsp; 23K Mar 22 16:20 user_ip_map.snapshot.1521735637&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;-rw-r--r--&amp;nbsp; 1 root root&amp;nbsp;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt; 509 &lt;/FONT&gt;&lt;/STRONG&gt;&lt;FONT color="#FF0000"&gt;Mar 22 16:15&lt;/FONT&gt;&lt;STRONG&gt;&lt;FONT color="#FF0000"&gt; user_ip_map.1521734735&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;-rw-r--r--&amp;nbsp; 1 root root&amp;nbsp; 20K Mar 22 16:02 user_ip_map.snapshot.1521734538&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT size="2" face="courier new,courier"&gt;drwxr-xr-x 67 root root 4.0K Nov 29&amp;nbsp; 2016 ..&lt;/FONT&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then, he created and run a second script, which clear the DB.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;(I can't post the full script here)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After that, the file user_ip_map show almost the same size on SFR than FS (same command). And users become detected correctly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please rate if this info was helpfull&lt;/P&gt;
&lt;P&gt;Guido&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Mar 2018 18:20:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3353429#M924669</guid>
      <dc:creator>Guido Arturo Catalano</dc:creator>
      <dc:date>2018-03-22T18:20:32Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2.2 - Unknown Users</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3908766#M924670</link>
      <description>&lt;P&gt;Hi, can any one help on how the configure the AD users to show under event connections?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2019 16:30:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/3908766#M924670</guid>
      <dc:creator>Santimac</dc:creator>
      <dc:date>2019-08-15T16:30:13Z</dc:date>
    </item>
    <item>
      <title>Re: FMC 6.2.2 - Unknown Users</title>
      <link>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/4129836#M1072577</link>
      <description>&lt;P&gt;Hi There,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am also facing the same issue, can you please help me with the first and second scripts.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Ismail Kalolwala&lt;/P&gt;</description>
      <pubDate>Tue, 04 Aug 2020 01:32:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/fmc-6-2-2-unknown-users/m-p/4129836#M1072577</guid>
      <dc:creator>ismail_salma1987</dc:creator>
      <dc:date>2020-08-04T01:32:19Z</dc:date>
    </item>
  </channel>
</rss>

