cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2173
Views
0
Helpful
5
Replies

Firepower URL Filtering Policy doesn't recognize users from AD

toddjustice
Level 1
Level 1

I have a Firepower Management Center deployed with some basic URL filtering enabled.  When I apply URL filtering via IP, the filtering applies, but when I attempt to filter via domain user instead, the filter never applies.

 

I've created the Realm, I've been able to download the users, I've created the Identity Policy (with passive authentication) and the users are available in the access control rules.  Am I missing something?

5 Replies 5

mikael.lahtela
Level 4
Level 4
Hi,

Did you install the User Agent and connect it to AD and Firepower Mangement Center or connect Firepower with ISE?
https://www.cisco.com/c/en/us/td/docs/security/firesight/user-agent/23/config-guide/Firepower-User-Agent-Configuration-Guide-v2-3/Intro.html

br, Micke

Yes, that's actually the document that I followed to perform the initial configuration.  The FMC is able to pull the usernames/groups from AD, but it seems like it can't lookup the user account in the rule and it just bypasses it.

Hi,

Try to create a new rule on top with AD username and add the URL categories you would like to filter. 

 

-Abheesh

It does not help...

I can see that question is old, but the problem is old. Did you by any chance find the solution in the meantime? If so, can you post the solution?

 

Regards,

 

Review Cisco Networking for a $25 gift card