12-19-2022 11:38 AM
We've had LDAP integration into our AD for many years for authentication into the FMC and FTD. However, we're trying to setup a rule, so that someone in our finance department is the only one who can get access to a particular website. When I configured the policy and entered the users domain username, it popped right up, and I was able to enter it into the policy. The website is blocked, and the connection event shows it was blocked because of a rule immediately after the one that was just created the specific user. For the "initiator user" user, the results show "not found". I'm not really sure what to try next, and I've not been able to find any Cisco documentation. Can someone provide an idea of where I can look? Thank you.
12-19-2022 11:53 AM - edited 12-19-2022 12:27 PM
Not sure if this will be of any use, but I resync'ed AD a while ago, and when I do a search for the user within Realms > Groups (Domain Users), I can find the user there. If I do a search for Realms > Users and put in the username, it says there "No groups were found" under the "Groups that contain selected user" column.
Disregard. There was a space in the search field.
12-19-2022 11:54 AM - edited 12-19-2022 11:56 AM
what is the version of code FMC and FTD., we used 7.X code works as expected.
have you configured Realm.
you can choose fall back - Here you can choose fall back method as Active authentication if passive authentication cannot identify the user identity.
also good steps to diagnosis :
https://integratingit.wordpress.com/2019/10/26/ftd-user-identity/
12-19-2022 02:02 PM
Sorry about that, but I had intended to provide code versions: 7.0.4 for FMC and FTD.
Realm is configured within the Identity Policy, but active authentication is not enabled. Also, the current access control policy has the identity policy configured. As I stated previously, the rule within the ACP can select the user, and AD seems to sync OK. All the info within the diagnosis article are null. Let me read through these closer - I know something is misconfigured that's probably in the articles. Thank you.
12-20-2022 09:15 AM
i have experienced that before and my resolution is having a CISCO ISE VM installed. this may help: https://www.youtube.com/watch?v=jFFhoqrR9W0 and also setup a Realms in FMC.
https://www.ciscozine.com/cisco-fmc-ise-pic-pxgrid/ hope this helps, you can contact TAC for the license info, in my case i requested that i should have license for ISE PIC since they have transitioned from agents to ISE.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide