cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
7384
Views
0
Helpful
10
Replies

FMC - Initiator User Not Found in event log

dodgerfan78
Level 1
Level 1

I have FMC 6.6, FTD 6.5 and ISE 2.7. FMC is connected to ISE via pxGrid and I see the User-to-IP mapping in the FMC: Analysis > Users shows user jbeam with an IP of 192.168.131.11 and an active session count of 1. I have a single identity policy mapped to a single access control rule. When I pass traffic through the FTD, the event log only shows the IP but the user shows up as "Not Found. Any idea what I am missing?

10 Replies 10

balaji.bandi
Hall of Fame
Hall of Fame

Can you show us ACP of the policy Logging screenshot, 

BB

***** Rate All Helpful Responses *****

How to Ask The Cisco Community for Help

Hi,

Is your user matching prefilter or acp rule. Check that from event analysis.

***** please remember to rate useful posts

Hi Guy!

I have the same problem on my environment. Please, do you found a solution for this problem?

Hi Guys, i hope is everything ok with everyone!

 

I have an importante update about this case, where i had this same scenario in two differents customers and after a lot of analysis days, with TAC Support we was able to find and fix this problem.

 

We've realized this behavior was happening after the FMC Reimage Process. After reimage we uploaded the FMC backup and all configurations has worked fine. The PxGrid integration between FMC and ISE has imported to the FMC as well and all configurations has successfully imported. But after all, we realized that Access Control Rules based on AD Users and Groups was not working, and the LOGs events about this rules has showing the Initiator User as "NOT FOUND".

 

So, the solution for this case was the Workaround of this BUG https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvr75813

Look guys, i've applied this WA for two different environments and worked fine! Could be helpful in the future troubleshootings!

 

Thanks and Best Regards!

bergonzoni
Level 1
Level 1

Hi,

Me too, I have the same issue, with FMC 6.6.1, FTD 6.4.0.10 and ISE 2.6.

Under this condition I find a lot of "Not Found" user associated to Connection Events.

I opened a TAC case, do you have any updates?

 

lap
Level 2
Level 2

Same issue here on FMC 6.6.1

bergonzoni
Level 1
Level 1

lap
Level 2
Level 2

Thanks I will have a look. Anyway recommended software version right now is 6.6.3 so it makes sense to upgrade.

Hi Guys, i hope is everything ok with everyone!

 

I have an importante update about this case, where i had this same scenario in two differents customers and after a lot of analysis days, with TAC Support we was able to find and fix this problem.

 

We've realized this behavior was happening after the FMC Reimage Process. After reimage we uploaded the FMC backup and all configurations has worked fine. The PxGrid integration between FMC and ISE has imported to the FMC as well and all configurations has successfully imported. But after all, we realized that Access Control Rules based on AD Users and Groups was not working, and the LOGs events about this rules has showing the Initiator User as "NOT FOUND".

 

So, the solution for this case was the Workaround of this BUG https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvr75813

Look guys, i've applied this WA for two different environments and worked fine! Could be helpful in the future troubleshootings!

 

Thanks and Best Regards!

Erik Ingeberg
Level 1
Level 1

Same issue here on FMC / vFTD both running 7.0.1 and ISE 3.

It was working fine when first set up, few days later I noticed it was no longer working.

Review Cisco Networking for a $25 gift card