05-22-2018 03:00 AM - edited 02-21-2020 07:47 AM
Hi,
We are replacing Palo Alto firewall with a Firepower solution.
In our Palo Alto we have this feature enabled:
This feature permit Palo Alto to known wireless User-IP mapping.
How we can replicate this feature on Firepower?
Thanks.
Marco
05-22-2018 07:25 PM
Firepower cannot consume identity that way.
You have six available methods - via Cisco User Agent, ISE/ISE-PIC, TS Agent, Captive Portal, Remote Access VPN or Traffic-based detection.
More details are found here:
06-04-2018 07:39 AM
Hi Marvin,
Based on the assumption that ISE know identity information (user\ip mapping) of wireless connected user from Wireless Controller.
Can I use this information to match policy based on user identity on Firepower?
ISE can be share these identity information to Firepower?
Thanks
06-04-2018 07:46 AM
Yes, ISE is a supported identity source which can be used to feed FMC usernames-IP address mapping. You can then use usernames (or, if you also have Active Directory integration configured, AD group membership) within your access control policies.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide