1-15
Cisco ASA Series CLI Configuration Guide
Chapter 1 Configuring the Identity Firewall
Task Flow for Configuring the Identity Firewall
Step 4
hostname(config)#
user-identity
logout-probe
netbios
local-system probe-time
minutes
minutes
retry-interval
seconds
seconds
retry-count
times
[
user-not-needed
|
match-any
|
exact-match
]
Example:
hostname(config)# user-identity logout-probe netbios
local-system probe-time minutes 10 retry-interval
seconds 10 retry-count 2 user-not-needed
Enables NetBIOS probing. Enabling this option
configures how often the ASA probes the user client
IP address to determine whether the client is still
active. By default, NetBIOS probing is disabled.
To minimize the NetBIOS packets, the ASA only
sends a NetBIOS probe to a client when the user has
been idle for more than the specified number of
minutes.
Specify the number of times to retry the probe:
•
match
-
any
—As long as the NetBIOS response
from the client contains the user name of the
user assigned to the IP address, the user identity
is be considered valid.
•
exact
-
match
—The user name of the user
assigned to the IP address must be the only one
in the NetBIOS response. Otherwise, the user
identity of that IP address is considered invalid.
•
user
-
not
-
needed
—As long as the ASA received
a NetBIOS response from the client the user
identity is considered valid.
The Identity Firewall only performs NetBIOS
probing for those users identities that are in the
active state and exist in at least one security policy.
The ASA does not perform NetBIOS probing for
clients where the users logged in through
cut-through proxy or by using VPN.
Step 5
hostname(config)#
user-identity
inactive-user-timer
minutes
minutes
Example:
hostname(config)#
user-identity inactive-user-timer
minutes 120
Specifies the amount of time before a user is
considered idle, meaning the ASA has not received
traffic from the user's IP address for specified
amount of time.
When the timer expires, the user's IP address is
marked as inactive and removed from the local
cached user identity-IP address mappings database
and the ASA no longer notifies the AD Agent about
that IP address removal. Existing traffic is still
allowed to pass. When this command is specified,
the ASA runs an inactive timer even when the
NetBIOS Logout Probe is configured.
By default, the idle timeout is set to 60 minutes.
Note
The Idle Timeout option does not apply to
VPN or cut through proxy users.
Command
Purpose
Summary of Contents for 5505 - ASA Firewall Edition Bundle
Page 28: ...Glossary GL 24 Cisco ASA Series CLI Configuration Guide ...
Page 61: ...P A R T 1 Getting Started with the ASA ...
Page 62: ......
Page 219: ...P A R T 2 Configuring High Availability and Scalability ...
Page 220: ......
Page 403: ...P A R T 2 Configuring Interfaces ...
Page 404: ......
Page 499: ...P A R T 2 Configuring Basic Settings ...
Page 500: ......
Page 533: ...P A R T 2 Configuring Objects and Access Lists ...
Page 534: ......
Page 601: ...P A R T 2 Configuring IP Routing ...
Page 602: ......
Page 745: ...P A R T 2 Configuring Network Address Translation ...
Page 746: ......
Page 845: ...P A R T 2 Configuring AAA Servers and the Local Database ...
Page 846: ......
Page 981: ...P A R T 2 Configuring Access Control ...
Page 982: ......
Page 1061: ...P A R T 2 Configuring Service Policies Using the Modular Policy Framework ...
Page 1062: ......
Page 1093: ...P A R T 2 Configuring Application Inspection ...
Page 1094: ......
Page 1191: ...P A R T 2 Configuring Unified Communications ...
Page 1192: ......
Page 1333: ...P A R T 2 Configuring Connection Settings and QoS ...
Page 1334: ......
Page 1379: ...P A R T 2 Configuring Advanced Network Protection ...
Page 1380: ......
Page 1475: ...P A R T 2 Configuring Modules ...
Page 1476: ......
Page 1549: ...P A R T 2 Configuring VPN ...
Page 1550: ......
Page 1965: ...P A R T 2 Configuring Logging SNMP and Smart Call Home ...
Page 1966: ......
Page 2059: ...P A R T 2 System Administration ...
Page 2060: ......
Page 2098: ...1 8 Cisco ASA Series CLI Configuration Guide Chapter 1 Troubleshooting Viewing the Coredump ...
Page 2099: ...P A R T 2 Reference ...
Page 2100: ......