EasyManuals Logo

Cisco ASA 5506-X Configuration Guide

Cisco ASA 5506-X
428 pages
To Next Page IconTo Next Page
To Next Page IconTo Next Page
To Previous Page IconTo Previous Page
To Previous Page IconTo Previous Page
Page #76 background imageLoading...
Page #76 background image
5-16
Cisco ASA Series Firewall CLI Configuration Guide
Chapter 5 Identity Firewall
Configure the Identity Firewall
If a user is added to or deleted from an Active Directory group, the ASA received the updated user group
after the import group timer ran. By default, the poll-import-user-group-timer hours value is 8 hours.
To immediately update user group information, enter the user-identity update import-user command.
Step 7 Specify the action when a client does not respond to a NetBIOS probe.
user-identity action netbios-response-fail remove-user-ip
Example:
hostname(config)# user-identity action netbios-response-fail remove-user-ip
For example, the network connection might be blocked to that client or the client is not active.
When this command is configured, the ASA removes the user identity-IP address mapping for that client.
By default, this command is disabled.
Step 8 Specify the action when the domain is down, because the Active Directory domain controller is not
responding.
user-identity action domain-controller-down domain_nickname disable-user-identity-rule
Example:
hostname(config)# user-identity action domain-controller-down SAMPLE
disable-user-identity-rule
When the domain is down and the disable-user-identity-rule keyword is configured, the ASA disables
the user identity-IP address mapping for that domain. Additionally, the status of all user IP addresses in
that domain are marked as disabled in the output displayed by the show user-identity user command.
By default, this command is disabled.
Step 9 Enable user-not-found tracking. By default, this command is disabled.
user-identity user-not-found enable
Example:
hostname(config)# user-identity user-not-found enable
Only the last 1024 IP addresses are tracked.
Step 10 Specify the action when the AD Agent is not responding.
user-identity action ad-agent-down disable-user-identity-rule
Example:
hostname(config)# user-identity action ad-agent-down disable-user-identity-rule
When the AD Agent is down and this command is configured, the ASA disables the user identity rules
associated with the users in that domain. Additionally, the status of all user IP addresses in that domain
is marked as disabled in the output displayed by the show user-identity user command.
By default, this command is disabled.
Step 11 Specify the action when a user's MAC address is found to be inconsistent with the ASA IP address
currently mapped to that MAC address.
user-identity action mac-address-mismatch remove-user-ip
Example:
hostname(config)# user-identity action mac-address-mismatch remove-user-ip

Table of Contents

Other manuals for Cisco ASA 5506-X

Questions and Answers:

Question and Answer IconNeed help?

Do you have a question about the Cisco ASA 5506-X and is the answer not in the manual?

Cisco ASA 5506-X Specifications

General IconGeneral
ModelASA 5506-X
Firewall Throughput750 Mbps
Maximum Firewall Connections50, 000
Maximum VPN Peers50
Integrated Ports8 x 1 GE
Stateful Inspection Throughput750 Mbps
Weight4.4 lb (2 kg)
Firewall Throughput (Multiprotocol)750 Mbps
Firewall Throughput (Application Visibility and Control AVC)250 Mbps
Concurrent Sessions50, 000
New Connections per Second10, 000
IPsec VPN Throughput100 Mbps
Interfaces8 x 1 GE
Memory4 GB
Flash Memory8 GB
Form FactorDesktop
VPN Throughput100 Mbps
Maximum Concurrent Sessions50, 000
New Sessions per Second10, 000
Operating Temperature32 to 104°F (0 to 40°C)
Storage Temperature-13 to 158°F (-25 to 70°C)
Power SupplyExternal
Humidity10% to 90% non-condensing

Related product manuals