13-13
User Guide for Cisco Security Manager 4.4
OL-28826-01
Chapter1 3 Managing Identity-Aware Firewall Policies
Configuring Identity-Aware Firewall Policies
Identity Configuration Wizard Active Directory Agent
Use the Active Directory Agent Settings page of the Identity Configuration wizard to identify the Active
Directory (AD) agents for a NetBIOS domain. These settings are required to enable user-identity-aware
firewall policies for users in the domain.
Tip You can configure a single AD agent group for an ASA; you do not configure a different group for each
NetBIOS domain. Thus, if you already configured the correct AD agent group in the Identity Options
policy, select the same group on this wizard page. Your selection here will replace the group defined in
the policy.
Navigation Path
Do one of the following:
From the AD Setup tab of the Identity Options page, click the Configure Identity button and
proceed to this page. See Identifying Active Directory Servers and Agents, page 13-8.
If the Identity Options policy is not already configured, you can start the wizard from the AAA
Rules, Access Rules, or Inspection Rules policies by clicking the Select button for the User field and
then clicking Yes when asked if you want to configure identity.
Interface The interface whose IP address should be used for all outgoing packets
(known as the source interface). Enter the name of an interface or
interface role, or click Select to select it from a list or to create a new
interface role.
Tips
If you enter the name of an interface, make sure the policy that uses
this AAA object is assigned to a device containing an interface
with this name.
If you enter the name of an interface role, make sure the role
represents a single interface, not multiple interfaces.
Only one source interface can be defined for the AAA servers in a
AAA server group, so if you specify more than one server, ensure
that they all use the same interface.
Add Another AD Server Click this button only if you want to create an additional server.
When you click the button, the information in the server fields is saved
and the fields are cleared so that you can add information about the next
server. You can add up to 16 servers in single-context mode and 4
servers in multiple-context mode.
Table13-3 Identity Configuration Wizard Active Directory Settings (Continued)
Element Description