<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Identity awareness Users limit in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Users-limit/m-p/102182#M10194</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Can someone help me interpret this logs?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-11-16 16_17_37-poller - 172.20.3.2 - Connessione Desktop remoto.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8952iC4588A13DFDDFA4C/image-size/large?v=v2&amp;amp;px=999" role="button" title="2020-11-16 16_17_37-poller - 172.20.3.2 - Connessione Desktop remoto.png" alt="2020-11-16 16_17_37-poller - 172.20.3.2 - Connessione Desktop remoto.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;(note that this has been filtered with the ip 10.0.4.80)&lt;/P&gt;&lt;P&gt;The person who is complaining about the malfunctioning Identity awareness told me that he logged into&amp;nbsp;the machine 10.0.4.80 with his user and &lt;EM&gt;from&lt;/EM&gt;&amp;nbsp;that machine he used other credentials (that can be seen expiring alltogether at 16:53.05) to log into other machines for example in RDP. The malfunctioning that he's experiencing is that the url-filtering doesn't let him into pages permitted for his user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now it seems like those credentials have been detected by the Identity awareness and, at some point, the highlighted alert popped up&amp;nbsp;(&lt;EM&gt;Machine (machine name) at (IP address) has 1 users (or more) currently connected to it, and will be automatically ignored&lt;/EM&gt;).&lt;/P&gt;&lt;P&gt;Now I've read &lt;A href="https://community.checkpoint.com/t5/Next-Generation-Firewall/Identity-Awareness-ignores-machines/td-p/74930" target="_self"&gt;something&lt;/A&gt; about that message, and it seems to me that the outcome of reaching that threshold should not be a ban.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anything suspicious that could have caused the reported malfunctionig or is this actually ok?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 16 Nov 2020 16:02:20 GMT</pubDate>
    <dc:creator>Stefano_Cappell</dc:creator>
    <dc:date>2020-11-16T16:02:20Z</dc:date>
    <item>
      <title>Identity awareness Users limit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Users-limit/m-p/102182#M10194</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;Can someone help me interpret this logs?&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2020-11-16 16_17_37-poller - 172.20.3.2 - Connessione Desktop remoto.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/8952iC4588A13DFDDFA4C/image-size/large?v=v2&amp;amp;px=999" role="button" title="2020-11-16 16_17_37-poller - 172.20.3.2 - Connessione Desktop remoto.png" alt="2020-11-16 16_17_37-poller - 172.20.3.2 - Connessione Desktop remoto.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;(note that this has been filtered with the ip 10.0.4.80)&lt;/P&gt;&lt;P&gt;The person who is complaining about the malfunctioning Identity awareness told me that he logged into&amp;nbsp;the machine 10.0.4.80 with his user and &lt;EM&gt;from&lt;/EM&gt;&amp;nbsp;that machine he used other credentials (that can be seen expiring alltogether at 16:53.05) to log into other machines for example in RDP. The malfunctioning that he's experiencing is that the url-filtering doesn't let him into pages permitted for his user.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now it seems like those credentials have been detected by the Identity awareness and, at some point, the highlighted alert popped up&amp;nbsp;(&lt;EM&gt;Machine (machine name) at (IP address) has 1 users (or more) currently connected to it, and will be automatically ignored&lt;/EM&gt;).&lt;/P&gt;&lt;P&gt;Now I've read &lt;A href="https://community.checkpoint.com/t5/Next-Generation-Firewall/Identity-Awareness-ignores-machines/td-p/74930" target="_self"&gt;something&lt;/A&gt; about that message, and it seems to me that the outcome of reaching that threshold should not be a ban.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there anything suspicious that could have caused the reported malfunctionig or is this actually ok?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2020 16:02:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Users-limit/m-p/102182#M10194</guid>
      <dc:creator>Stefano_Cappell</dc:creator>
      <dc:date>2020-11-16T16:02:20Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness Users limit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Users-limit/m-p/102197#M10195</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;why would IA expire all 7 sessions at once there? I thought it would simply disallow 8th user IP association on the same machine.&lt;/P&gt;</description>
      <pubDate>Mon, 16 Nov 2020 19:34:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Users-limit/m-p/102197#M10195</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2020-11-16T19:34:55Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness Users limit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Users-limit/m-p/102243#M10196</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/6500"&gt;@Stefano_Cappell&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;From what I understand, all the users logged in to this machine are service accounts (besides the real user).&lt;/P&gt;
&lt;P&gt;I do recommend filtering out service accounts as it will both save GW resources and not process them, and also avoid such scenarios.&lt;/P&gt;
&lt;P&gt;Please read about service accounts under&amp;nbsp;sk86441 ("Filter-out service accounts").&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11456"&gt;@Kaspars_Zibarts&lt;/a&gt;&amp;nbsp;- once we understand that more than 7 users were logged into one machine, all these identities are revoked as we are tagging this machine as MUH machine. According to our decision, having too many users (and access roles, due to that) on one machine can cause permission escalated to some of the users, and we would like to avoid that). Thanks for tagging me btw&amp;nbsp;8)&lt;/img&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 17 Nov 2020 08:02:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-Users-limit/m-p/102243#M10196</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2020-11-17T08:02:09Z</dc:date>
    </item>
  </channel>
</rss>

