39-25
Cisco ASA 5500 Series Configuration Guide using ASDM
Chapter39 Configuring the Identity Firewall
Monitoring the Identity Firewall
Step3 Click Refresh to update the data in the pane.
This pane displays displays the list of user groups in the following format:
domain\group_name
Monitoring Memory Usage for the Identity Firewall
You can monitor the memory usage that the Identity Firewall consumes on the ASA.
Step1 Open the Monitoring > Properties > Identity > Memory Usage.
The Memory Usage of Identity Modules pane appears.
Step2 Click Refresh to update the data in the pane.
This pane displays the memory usage in bytes of various modules in the Identity Firewall:
Users
Groups
User Stats
LDAP
The ASA sends an LDAP query for the Active Directory groups configured on the Active Directory
server. The Active Directory server authenticates users and generates user logon security logs.
AD Agent
Miscellaneous
Total Memory Usage
Note How you configure the Identity Firewall to retrieve user information from the AD Agent impacts the
amount of memory used by the feature. You specify whether the ASA uses on demand retrieval or full
download retrieval. Selecting On Demand has the benefit of using less memory as only users of
received packets are queried and stored. See Configuring Identity Options, page16 for a description of
these options.
Monitoring Users for the Identity Firewall
You can display information about all users contained in the IP-user mapping database used by the
Identity Firewall.
Step1 Open the Monitoring > Properties > Identity > User.
The Users in the User Database pane appears.
Note Active users are highlighted in green.