01-20-2017 10:45 AM - edited 03-10-2019 06:45 AM
Hello everyone
I've set up my WLAN authentication via a Windows NPS server. The NPS server is also a domain controller in my domain, which is monitored by the FirePOWER user agent.
Now, my goal was to get the user who authenticates to the wireless lan mapped in the FMC. Unfortunately though the authentication does not show up in the FMC at the "user activity"-tab. "Normal" Windows-logons show up just fine.
So, am I missing something? Or even, is this not supported?
Thanks!
01-20-2017 08:28 PM
I don't think this is supported. The user agent watches for user logon/logoff events. NPS wont generate these kinds of events. I don't see how it could work.
HOWEVER, once the user is attached to WiFi and attempts to access a Windows resource they should authenticate against AD at that point in time - and Firepower will pick this up.
01-26-2017 04:36 AM
Yes, I am aware of that. I was just hoping to get user data on my Apple devices too...
Maybe there's a way to manipulate or (re-)create the Windows events and trick the FMC into thinking it saw a legit logon...
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide