cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
2085
Views
0
Helpful
5
Replies

Firepower URL Filtering Policy doesn't recognize users from AD

toddjustice
Level 1
Level 1

I have a Firepower Management Center deployed with some basic URL filtering enabled.  When I apply URL filtering via IP, the filtering applies, but when I attempt to filter via domain user instead, the filter never applies.

 

I've created the Realm, I've been able to download the users, I've created the Identity Policy (with passive authentication) and the users are available in the access control rules.  Am I missing something?

5 Replies 5

mikael.lahtela
Level 4
Level 4
Hi,

Did you install the User Agent and connect it to AD and Firepower Mangement Center or connect Firepower with ISE?
https://www.cisco.com/c/en/us/td/docs/security/firesight/user-agent/23/config-guide/Firepower-User-Agent-Configuration-Guide-v2-3/Intro.html

br, Micke

Yes, that's actually the document that I followed to perform the initial configuration.  The FMC is able to pull the usernames/groups from AD, but it seems like it can't lookup the user account in the rule and it just bypasses it.

Hi,

Try to create a new rule on top with AD username and add the URL categories you would like to filter. 

 

-Abheesh

It does not help...

I can see that question is old, but the problem is old. Did you by any chance find the solution in the meantime? If so, can you post the solution?

 

Regards,

 

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card