10-24-2023 12:11 AM
Hello,
In order to be able to see usernames in the FMC connection event log, would it be enough to add our AD server as a realm and create an identity policy or do we also need to configure an identiy source (like Cisco ISE) for this to work?
Thanks
/Chess
Solved! Go to Solution.
10-24-2023 12:26 AM
@Chess Norris If you are using the FTD for Remote Access VPN then the users will be learnt passively (you don't need to specify an ID source). However if you want the usernames for wired/wireless authenticated users to be learnt by the FMC/FTD, then you need to send the IP/Username bindings to the FMC via pxgrid.
10-24-2023 12:26 AM
@Chess Norris If you are using the FTD for Remote Access VPN then the users will be learnt passively (you don't need to specify an ID source). However if you want the usernames for wired/wireless authenticated users to be learnt by the FMC/FTD, then you need to send the IP/Username bindings to the FMC via pxgrid.
10-24-2023 12:28 AM
Thank you for the confirmation.
/Chess
10-24-2023 06:58 AM
Adding to what @Rob Ingram correctly noted:
Realm integration tells FMC these are the AD groups and their members for your configured realm.
The ISE identity source maps IP addresses to users. ISE obtains that information via either Active (802.1x) or passive (via PassiveID feature which reads from your DCs' event logs) authentication.
10-24-2023 09:13 AM
Thanks Marvin!
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide