Heads Up :
The post you are writing will appear in a public forum. Please ensure all content is appropriate for public consumption. Review the employee guidelines for the community here.
Here is the reason you did not get any user-ip mappings in ASA.The domain name configured in ASA should be netbios domain name and it needs to be matched with the one you see in "adacfg dc list" output, otherwise ASA will drop any user-ip reports fro...
Two more CLIs to collect.Here is the new list.in AD agent serveradacfg dc listadacfg cache list adacfg client listin ASAshow user-identity user all list detail.show user-idneityt ad-agentshow user-idneityt ad-agent statisAlso you may tuen on debug "d...
First of all, I 'd like to check if ASA correctly receives user-ip mapping for test4.local\rodrigo from AD agent.Can you please collect the output of the following CLIs in AD agent server?adacfg dc listadacfg cache listAlso the CLI in ASA and check i...
We may have different network deployment scenarios. Whether or not IDFW is supporting NAT really depends on the deployment. For IDFW to work with NAT, the base line is that AD /ASA should see the real IP address of AD logon user.In your deployment di...
Actually there are some limitation for IDFW to work with NAT.Basically, AD server and users should be at the same side of ASA.Here is a deployment scenario. For example, AD server and logon users are in inside network. Users from inside network can a...