<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Firepower 6.2 / Identity Policy with authentication rules required in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/firepower-6-2-identity-policy-with-authentication-rules-required/m-p/3029818#M998892</link>
    <description>&lt;P&gt;Hello everyone!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I've got a Firepower v6.2 and I'm trying to configure ACLs including filtering by users. I managed to integrate the Firepower with Active Directory, that is I can download users and groups succesfully.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've already configured an Identity Policy included in the Standard Rules.&amp;nbsp;The authentication is passive. However, when I'm trying to add an ACL in the users tab, there is a warning saying "Identity Policy with authentication rules required" and I can't add users to the ACL.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any thoughts?.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Fernanda&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 13:24:16 GMT</pubDate>
    <dc:creator />
    <dc:date>2019-03-12T13:24:16Z</dc:date>
    <item>
      <title>Firepower 6.2 / Identity Policy with authentication rules required</title>
      <link>https://community.cisco.com/t5/network-security/firepower-6-2-identity-policy-with-authentication-rules-required/m-p/3029818#M998892</link>
      <description>&lt;P&gt;Hello everyone!&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;I've got a Firepower v6.2 and I'm trying to configure ACLs including filtering by users. I managed to integrate the Firepower with Active Directory, that is I can download users and groups succesfully.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've already configured an Identity Policy included in the Standard Rules.&amp;nbsp;The authentication is passive. However, when I'm trying to add an ACL in the users tab, there is a warning saying "Identity Policy with authentication rules required" and I can't add users to the ACL.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Any thoughts?.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Fernanda&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 13:24:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-6-2-identity-policy-with-authentication-rules-required/m-p/3029818#M998892</guid>
      <dc:creator />
      <dc:date>2019-03-12T13:24:16Z</dc:date>
    </item>
    <item>
      <title>Have you setup a Cisco User</title>
      <link>https://community.cisco.com/t5/network-security/firepower-6-2-identity-policy-with-authentication-rules-required/m-p/3029819#M998893</link>
      <description>&lt;P&gt;Have you setup a Cisco User Agent in your domain (or have an alternate source of user to IP mapping like ISE/ISE-PIC available)?&lt;/P&gt;
&lt;P&gt;http://www.cisco.com/c/en/us/td/docs/security/firepower/621/configuration/guide/fpmc-config-guide-v621/user_identity_sources.html#ID-2225-00000063&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2017 05:06:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-6-2-identity-policy-with-authentication-rules-required/m-p/3029819#M998893</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-05-19T05:06:13Z</dc:date>
    </item>
    <item>
      <title>Hello Marvin</title>
      <link>https://community.cisco.com/t5/network-security/firepower-6-2-identity-policy-with-authentication-rules-required/m-p/3029820#M998894</link>
      <description>&lt;P&gt;Hello Marvin&lt;/P&gt;
&lt;P&gt;Thanks for replying. Yes, I already did so. I've got a Cisco User Agent in my domain and the integration is correct. In fact, the users and groups were downloaded succesfully and it can be seen in the Task tab. I think the issue is that the Identify Policy has not been applied correctly. That's why when creating an ACL, the Firepower is not seeing the&amp;nbsp;configured policy.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Fernanda&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2017 14:19:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-6-2-identity-policy-with-authentication-rules-required/m-p/3029820#M998894</guid>
      <dc:creator />
      <dc:date>2017-05-19T14:19:34Z</dc:date>
    </item>
    <item>
      <title>That may well be the case.</title>
      <link>https://community.cisco.com/t5/network-security/firepower-6-2-identity-policy-with-authentication-rules-required/m-p/3029821#M998895</link>
      <description>&lt;P&gt;That may well be the case. Once you have created an Identity Policy you must explicitly reference it in your Access Control Policy.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here's where you do that:&lt;/P&gt;
&lt;P&gt;&lt;IMG src="https://community.cisco.com/legacyfs/online/media/fmc_acp_with_identity.png" class="migrated-markup-image" /&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2017 15:00:41 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-6-2-identity-policy-with-authentication-rules-required/m-p/3029821#M998895</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-05-19T15:00:41Z</dc:date>
    </item>
    <item>
      <title>Great!. It worked!.</title>
      <link>https://community.cisco.com/t5/network-security/firepower-6-2-identity-policy-with-authentication-rules-required/m-p/3029822#M998896</link>
      <description>&lt;P&gt;Great!. It worked!.&lt;/P&gt;
&lt;P&gt;Many thanks.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2017 19:50:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-6-2-identity-policy-with-authentication-rules-required/m-p/3029822#M998896</guid>
      <dc:creator />
      <dc:date>2017-05-19T19:50:26Z</dc:date>
    </item>
    <item>
      <title>You're welcome.</title>
      <link>https://community.cisco.com/t5/network-security/firepower-6-2-identity-policy-with-authentication-rules-required/m-p/3029823#M998897</link>
      <description>&lt;P&gt;You're welcome.&lt;/P&gt;
&lt;P&gt;Thanks for letting us know it's resolved and for the rating.&lt;/P&gt;</description>
      <pubDate>Sat, 20 May 2017 03:48:29 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-6-2-identity-policy-with-authentication-rules-required/m-p/3029823#M998897</guid>
      <dc:creator>Marvin Rhoads</dc:creator>
      <dc:date>2017-05-20T03:48:29Z</dc:date>
    </item>
    <item>
      <title>Re: That may well be the case.</title>
      <link>https://community.cisco.com/t5/network-security/firepower-6-2-identity-policy-with-authentication-rules-required/m-p/3767885#M998898</link>
      <description>&lt;P&gt;Marvin, I follow your posts very closely and they are almost always precise.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Fri, 21 Dec 2018 14:24:53 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/firepower-6-2-identity-policy-with-authentication-rules-required/m-p/3767885#M998898</guid>
      <dc:creator>InTheJuniverse</dc:creator>
      <dc:date>2018-12-21T14:24:53Z</dc:date>
    </item>
  </channel>
</rss>

