<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Identity awareness - just to see traffic only in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-just-to-see-traffic-only/m-p/99547#M10392</link>
    <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;We do not have identity awareness switched on at the min, we use IP based objects only.&lt;/P&gt;&lt;P&gt;If I wanted to switch it on just so we can log the users traffic etc, would this be OK?&lt;/P&gt;&lt;P&gt;Would this not cause any impact to my current rulebase?&lt;/P&gt;&lt;P&gt;Would it automatically start putting the user in the logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 20 Oct 2020 07:42:58 GMT</pubDate>
    <dc:creator>carl_t</dc:creator>
    <dc:date>2020-10-20T07:42:58Z</dc:date>
    <item>
      <title>Identity awareness - just to see traffic only</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-just-to-see-traffic-only/m-p/99547#M10392</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;We do not have identity awareness switched on at the min, we use IP based objects only.&lt;/P&gt;&lt;P&gt;If I wanted to switch it on just so we can log the users traffic etc, would this be OK?&lt;/P&gt;&lt;P&gt;Would this not cause any impact to my current rulebase?&lt;/P&gt;&lt;P&gt;Would it automatically start putting the user in the logs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 07:42:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-just-to-see-traffic-only/m-p/99547#M10392</guid>
      <dc:creator>carl_t</dc:creator>
      <dc:date>2020-10-20T07:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness - just to see traffic only</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-just-to-see-traffic-only/m-p/99554#M10393</link>
      <description>&lt;P&gt;It would not impact the database, it will collect the information and can have a very slight performance impact, so when your gateway is already at it's peak of its capabilities (fully loaded memory and multiple cores close to 100%) I would not activate it, but in all other case there would not be a noticable impact.&lt;/P&gt;
&lt;P&gt;In your logs you should indeed see user information pop up (if your allowed to see it).&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 08:16:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-just-to-see-traffic-only/m-p/99554#M10393</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2020-10-20T08:16:01Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness - just to see traffic only</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-just-to-see-traffic-only/m-p/99579#M10394</link>
      <description>&lt;P&gt;Additionally to &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/17364"&gt;@Maarten_Sjouw&lt;/a&gt;&amp;nbsp;, you can utilize affinity to separate fwk cores from IA (pdpd and pepd) work this approach you would have zero impact. That's of you have enough CPU cores to play with.&lt;/P&gt;</description>
      <pubDate>Tue, 20 Oct 2020 11:56:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-just-to-see-traffic-only/m-p/99579#M10394</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2020-10-20T11:56:43Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness - just to see traffic only</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-just-to-see-traffic-only/m-p/100020#M10395</link>
      <description>&lt;P&gt;We've supported this even before we had support do Identity Awareness in the rulebase (back in R71), so yes.&lt;/P&gt;</description>
      <pubDate>Sat, 24 Oct 2020 05:39:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-just-to-see-traffic-only/m-p/100020#M10395</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-10-24T05:39:40Z</dc:date>
    </item>
  </channel>
</rss>

