12-30-2022 02:05 AM
Hi,
I need to set up an URL filtering policy based on AD groups. Most users will have URL restrisction while a specific AD group will have full access.
I have 2 cisco FTD managed by an FMC.
Is it possible to set up this rules without ISE ? Is it still possible to use TS agent user ?
I can already retrieve users and AD groups from the server...
Thanks for your help.
Franck
Solved! Go to Solution.
12-30-2022 02:13 AM
Hi @Franck Network the firepower user agent has been depreciated since version FMC 6.7.
You'd need to use ISE/ISE-PIC to send the IP/user bindings to the FMC.
12-30-2022 02:13 AM
Hi @Franck Network the firepower user agent has been depreciated since version FMC 6.7.
You'd need to use ISE/ISE-PIC to send the IP/user bindings to the FMC.
01-02-2023 01:06 AM
Thanks Rob !
Very heavy solution ! For 2 FTD, I need 2 more devices (FMC, ISE).
Regards,
FJ
01-02-2023 01:42 AM
@Franck Network if you don't already have ISE, then consider ISE-PIC which is similar to User Agent in that it also uses WMI to gather login events from AD. ISE-PIC costs less than ISE, with limited features but provides the functionality you require.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide