You are here
SEC0165 - ASA FirePower Network Discovery (User with AD User Agent) (Part 2)
Difficulty Level:
Lab Document:
<Please login to see the content>
Category:
Security
The video demonstrates how you can leverage user identity information within Cisco ASA FirePower and FireSight System as part of User Network Discovery. We will utilize AD User Agent to obtain user-to-IP mapping, and integrate to Active Directory to obtain user and group information. This information can be used to tie user identity to network traffic as well as including them in Access Control rules for access enforcement
Part 2 of this videos goes through AD integration to obtain user and group information, and perform functionality testing
Topic:
- Network Discovery with User
- AD User Agent Install
- LDAP/AD Integration
- Discovery Policy
- User-to-IP Mapping
- User Profile
9 comments
IP Address Mapping
The labs you have provided are excellent! If a user logs into the network using a wired connection and switches to wireless is there a way to map their new ip address to username?
IP Address Mapping
You don't really have control over that. It depends on whether Windows causes a login event to happen for the FP agent to detect. The chances are it will not as users remain logged into Windows during the wired to wireless roaming process.
IP Address Mapping
I think if you are using 802.1x authentication with that same AD server, it could see the wireless lan adapter authenticate when you connect to the wifi network, and thus it would immediately map the user to the new IP. You think that might work?
IP Address Mapping
You are correct. It is possible now but only with FP 6.0 and pxGrid integration. User Agent alone would not be possible.
User Activity in the LAN
My question is regarding how Virtual Defense Center getting user activity when traffic has not passed firewall for example in your lab when user first login to the windows machine how system has User Activity in the log?
User Activity in the LAN
SourceFire user agent captured the user login activity on AD and report them to FireSight.. This is independent of the actual user traffic passing through FP.
Video is no available
Hello!
Are there any problem with the videos?
I can´t see anymore.
thanks
Video is no available
We had some technical issue. Should be back to normal now.
User Agents High Availibility
Dear Sir,
Is there any possibility to to install multiple user agents pointing to common domain controller work as High Availability.