We currently have Cisco ASA's as VPN Concentrators and have syslogging to a CP IDA Collector to populate the identities for access rules on our CP firewalls.
We are migrating from the Cisco ASA's to Cisco FTD's and are having issues. We've verified the IPs and verified the traffic is getting allowed to the IDA Collector but it doesn't look like the CP IDA Collector is parsing out any identities from the Cisco FTD's syslogs. When migrating to the Cisco FTD's we are using the same syslog events as was configured and working on the ASA's as well.
In CP IDA there is only the option for Cisco ASA 9.1 on the syslog options and not anything for the FTD but I'd be surprised if there are differences in the format as you can still get to the ASA CLI under the hood of the FTD code.
I'm only assuming that we aren't the only ones to do this as the FTD's have been out there for a good bit.
Has anyone else got experience with this setup?