39-14
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter39 Configuring the Identity Firewall
Task Flow for Configuring the Identity Firewall
Configuring Active Directory Agents
Periodically or on-demand, the AD Agent monitors the Active Directory server security event log file
via WMI for user login and logoff events. The AD Agent maintains a cache of user ID and IP address
mappings. and notifies the ASA of changes.
Requirement
AD agent IP address
Shared secret between ASA and AD agent
To configure the AD Agents, perform the following steps:
Step1 Open the Configuration > Firewall > Identity Options pane.
Step2 If necessary, check the Enable User Identity check box to enable the feature.
Step3 In the Active Directory Agent section, click Manage.
The Configure Active Directory Agents dialog box appears.
Step4 To add an AD Agent, click the Add button.
OR
Select an agent group from the list and click Edit.
See Configuring Active Directory Agent Groups, page15.
Step5 Click OK to save your changes.
What to Do Next
Configure AD Agent groups. See Configuring Active Directory Agent Groups, page15.
Configure access rules for the Identity Firewall. See Configuring Identity-based Access Rules, page19.