<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: User based URL Access in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3945921#M925267</link>
    <description>&lt;P&gt;Yes you can have users and groups as elements in your ACPs with only Realm integration.&lt;/P&gt;
&lt;P&gt;However until you have an identity source to associate them with IP addresses, the users and group elements will not have any effective use.&lt;/P&gt;</description>
    <pubDate>Wed, 23 Oct 2019 04:29:52 GMT</pubDate>
    <dc:creator>Marvin Rhoads</dc:creator>
    <dc:date>2019-10-23T04:29:52Z</dc:date>
    <item>
      <title>User based URL Access</title>
      <link>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3941273#M925255</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;How we can setup rules on FMC to allow users to access social media sites like facebook.com and block access to public drives like onedrive and drop box.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any way FMC allow access on user group base through Active Directory (AD). How we can setup this part of user group information gather from AD and allow access to URLs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2020 17:35:45 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3941273#M925255</guid>
      <dc:creator>Fantas</dc:creator>
      <dc:date>2020-02-21T17:35:45Z</dc:date>
    </item>
    <item>
      <title>Re: User based URL Access</title>
      <link>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3942435#M925256</link>
      <description>&lt;P&gt;You can do this on FMC if you've integrated yoru AD with Realm integration and are gathering User-IP mapping with an identity source like Firepower User Agent or Cisco ISE. You would of course require a URL Filtering license.&lt;/P&gt;
&lt;P&gt;Personally I find this easier to do (and with superior reporting and fine-grained control) using Cisco Umbrella. Of course that's a separate product with its own deployment and costs.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Oct 2019 10:52:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3942435#M925256</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-10-17T10:52:38Z</dc:date>
    </item>
    <item>
      <title>Re: User based URL Access</title>
      <link>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3943046#M925257</link>
      <description>&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;why I need user agent as If I dont wana monitor user activity.&lt;/P&gt;&lt;P&gt;I have already download user group from AD and now I wana add url filter rule but cant see anything in available realms.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But when I check in realms its their in included but cant see it under rules for url filtering.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please confirm if i am missing any thing and why cant see realms in policy rules so that I can filter user&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And Is user agent necessary for url filtering.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2019 06:06:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3943046#M925257</guid>
      <dc:creator>Fantas</dc:creator>
      <dc:date>2019-10-18T06:06:13Z</dc:date>
    </item>
    <item>
      <title>Re: User based URL Access</title>
      <link>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3943186#M925258</link>
      <description>&lt;P&gt;Simply pulling groups and user names from AD realms isn't enough. You need the username to IP address mapping. That's what an identity source like User Agent gives you.&amp;nbsp;ISE and captive portal are other identity sources.&lt;/P&gt;</description>
      <pubDate>Fri, 18 Oct 2019 10:42:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3943186#M925258</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-10-18T10:42:26Z</dc:date>
    </item>
    <item>
      <title>Re: User based URL Access</title>
      <link>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3943700#M925259</link>
      <description>&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Can we install user agent on same jump server where we access FMC or it needs to be on dedicated windows machine.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Oct 2019 05:47:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3943700#M925259</guid>
      <dc:creator>Fantas</dc:creator>
      <dc:date>2019-10-19T05:47:20Z</dc:date>
    </item>
    <item>
      <title>Re: User based URL Access</title>
      <link>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3943939#M925261</link>
      <description>&lt;P&gt;The User Agent can be on any Windows machine that has the appropriate access to the domain controller(s).&lt;/P&gt;
&lt;P&gt;The User Agent Configuration Guide has more details here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firesight/user-agent/24/config-guide/Firepower-User-Agent-Configuration-Guide-v2-4/ConfigAgent.html#65849" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firesight/user-agent/24/config-guide/Firepower-User-Agent-Configuration-Guide-v2-4/ConfigAgent.html#65849&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Oct 2019 04:12:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3943939#M925261</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-10-20T04:12:02Z</dc:date>
    </item>
    <item>
      <title>Re: User based URL Access</title>
      <link>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3945814#M925263</link>
      <description>&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Currently I am testing url filtering with FMC Realm and can see users in my access control policy.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 23:35:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3945814#M925263</guid>
      <dc:creator>Fantas</dc:creator>
      <dc:date>2019-10-22T23:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: User based URL Access</title>
      <link>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3945911#M925265</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there any other way for ISE to pass logs to FMC without pxGrid? Or is there way to perform authentication to AD via FMC?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 04:23:05 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3945911#M925265</guid>
      <dc:creator>Sakun Sharma</dc:creator>
      <dc:date>2019-10-23T04:23:05Z</dc:date>
    </item>
    <item>
      <title>Re: User based URL Access</title>
      <link>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3945921#M925267</link>
      <description>&lt;P&gt;Yes you can have users and groups as elements in your ACPs with only Realm integration.&lt;/P&gt;
&lt;P&gt;However until you have an identity source to associate them with IP addresses, the users and group elements will not have any effective use.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 04:29:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3945921#M925267</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-10-23T04:29:52Z</dc:date>
    </item>
    <item>
      <title>Re: User based URL Access</title>
      <link>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3945992#M925268</link>
      <description>&lt;P&gt;1. No.&lt;/P&gt;
&lt;P&gt;2. You could use the captive portal but I've not done so.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/security/firepower/650/configuration/guide/fpmc-config-guide-v65/introduction_to_network_discovery_and_identity.html#concept_6C9FF477EEB643FD80818C0FAA91DAB3" target="_blank"&gt;https://www.cisco.com/c/en/us/td/docs/security/firepower/650/configuration/guide/fpmc-config-guide-v65/introduction_to_network_discovery_and_identity.html#concept_6C9FF477EEB643FD80818C0FAA91DAB3&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 05:43:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3945992#M925268</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-10-23T05:43:01Z</dc:date>
    </item>
    <item>
      <title>Re: User based URL Access</title>
      <link>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3946016#M925269</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;You can do Active Authentication through Identity policy on&amp;nbsp; FMC, I am doing passive authentication and at some stage might needs active authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This Issue I have , I have did URL filtering for my inside client based on domain user name and allowed only Facebook.com in access policy but still client is able to access all other web sites including Facebook.com.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 06:19:51 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3946016#M925269</guid>
      <dc:creator>Fantas</dc:creator>
      <dc:date>2019-10-23T06:19:51Z</dc:date>
    </item>
    <item>
      <title>Re: User based URL Access</title>
      <link>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3946529#M925270</link>
      <description>&lt;P&gt;Can you share your Access Control Policy rules?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 17:45:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3946529#M925270</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2019-10-23T17:45:35Z</dc:date>
    </item>
    <item>
      <title>Re: User based URL Access</title>
      <link>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3946567#M925271</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I configured active authentication on fmc after import certificate with basic http.&lt;/P&gt;&lt;P&gt;First time browser asks for domain username and password for http site after entering I got access but now its not asking any of the http sites and I can access all http and https sites from client , its strange.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So again I am on below issues, anyone have same issues and fixed them , please share&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1 - URL Filtering are not working properly for http sites&lt;/P&gt;&lt;P&gt;2 - URL Filtering for https sites still need to be setup&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;My ACP allows only facebook.com but from client I can access all http and https sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In logs I can see my domain user access to all those web sites&lt;/P&gt;</description>
      <pubDate>Wed, 23 Oct 2019 18:29:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/user-based-url-access/m-p/3946567#M925271</guid>
      <dc:creator>Fantas</dc:creator>
      <dc:date>2019-10-23T18:29:15Z</dc:date>
    </item>
  </channel>
</rss>

