08-30-2017 09:03 AM - edited 02-21-2020 06:15 AM
Hi All,
where do you install the agent for user mapping ?
I understand it must be AD,if so does that mean all ADs?
how about if you use NTLM, does the browser automatically authenticate the user using their current session?
Thanks
08-30-2017 11:31 AM
The User Agent can be installed on any Windows host in your Active Directory (AD) domain. A given user agent can support up to four Domain Controllers (DCs). Altogether you must have a User Agent querying every DC in your domain that processes user login events.
With respect to NTLM authentication, the Firepower User Guide informs us as follows:
"If transparent authentication is configured in a user's browser, the user is automatically logged in. If transparent authentication is not configured, users log in to the network using their browser's default authentication popup window."
08-30-2017 01:08 PM
many thanks
will it pull all 4 DCs at the same time on the interval setup ?
So If I have 12 DCs then i need 3 agents ? One question is how will it deal with conflicts ?
Finally, if I use NTLM, can it attempt to find the user and if not pass rather than block ?
Out of interest does the agent reads the event logs to determine usermapping ?
if so does the agent username needs to have certain domain rights?
08-30-2017 08:33 PM
Yes -12 DCs would require 3 User Agent instances.
I'm not positive on how it handles the polling intervals under the covers. I don't believe that's publicly documented explicitly. You should be able to look at the event logs on the system where User Agent is installed to see the polling events and their timestamp.
Details are shown here:
You access control policy can have a default rule or set of rules to be used in the event of no available authentication status.
User Agent queries the Windows Event Log using WMI. So yes, some minimum privileges are required. there is a technot detailing them here:
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide