cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1708
Views
0
Helpful
1
Replies

FMC internal users

I have FTD 1010 and mange it using FMC.

I want to add internal users to attach them to access policy to apply different web and app filter?

and i dont have AD or LDAB server  

1 Reply 1

JohnLong3
Level 1
Level 1

Hello,

 

Unfortunately, the FMC does not support a manual upload of users as it needs to be able to communicate with a user database and an identity source. In order to use users in the Access Control Policy rules, these things need to happen:

 

1) FMC needs to be connected to a AD or LDAP server in order to download the users (via Realm settings)

2) The FMC then needs to be connected to an "Identity Source", such as ISE or User Agent in order to get the user to IP mappings.

3) FMC then syncs what it knows about the user to IP mappings with the managed devices (in this case, the 1010) so that it can enforce policy rules based on user

 

For more information, please see the section of the FMC Configuration Guide called "Discovery and Identity" starting here - https://www.cisco.com/c/en/us/td/docs/security/firepower/650/configuration/guide/fpmc-config-guide-v65/create_and_manage_realms.html

Review Cisco Networking for a $25 gift card