<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness and UPN suffix in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/86518#M11178</link>
    <description>Short comment, username@XYZ.local also doesnt work, only clean username.....</description>
    <pubDate>Wed, 27 May 2020 16:06:51 GMT</pubDate>
    <dc:creator>Sergo89</dc:creator>
    <dc:date>2020-05-27T16:06:51Z</dc:date>
    <item>
      <title>Identity Awareness and UPN suffix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/86425#M11177</link>
      <description>&lt;P&gt;Hi Guys&lt;/P&gt;&lt;P&gt;I have a problem, CP Identity Awareness doesnt want to recognize users, who logged in UPN credentials. For example, XYZ.local is a standard AD Domain, but also it has UPN suffix XYZ.com for communication with O365 etc. For windows login (and WLC with Radius) doesnt matter, it can be just username, or &lt;A href="mailto:username@XYZ.local" target="_blank"&gt;username@XYZ.local&lt;/A&gt;&amp;nbsp;or &lt;A href="mailto:username@XYZ.com" target="_blank"&gt;username@XYZ.com&lt;/A&gt;. CheckPoint understand only username and&amp;nbsp;&amp;nbsp;&lt;A href="mailto:username@XYZ.local" target="_blank"&gt;username@XYZ.local&lt;/A&gt;.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I talked to CP support, they advised to create additional LDAP account unit (XYZ.com), but it doesnt's work, still same issues with name recognizing, and also Remote Access VPN stops (lose access to original domain XYZ.local)&lt;/P&gt;&lt;P&gt;do you have any ideas how to fix it?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Wed, 27 May 2020 04:47:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/86425#M11177</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2020-05-27T04:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and UPN suffix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/86518#M11178</link>
      <description>Short comment, username@XYZ.local also doesnt work, only clean username.....</description>
      <pubDate>Wed, 27 May 2020 16:06:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/86518#M11178</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2020-05-27T16:06:51Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and UPN suffix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/86823#M11179</link>
      <description>&lt;P&gt;Not sure,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;?&lt;/P&gt;</description>
      <pubDate>Sun, 31 May 2020 04:24:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/86823#M11179</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-31T04:24:57Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and UPN suffix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/86851#M11180</link>
      <description>&lt;P&gt;Which identity sources are used?&lt;/P&gt;</description>
      <pubDate>Sun, 31 May 2020 08:58:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/86851#M11180</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2020-05-31T08:58:26Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and UPN suffix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/86885#M11181</link>
      <description>Hi Royi&lt;BR /&gt;Active Directory Query (LDAP), and RADIUS accounting turned on... WLC sends info to checkpoint, and i can recognize wireless users in CP logs&lt;BR /&gt;thanks</description>
      <pubDate>Sun, 31 May 2020 16:07:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/86885#M11181</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2020-05-31T16:07:18Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and UPN suffix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/86914#M11182</link>
      <description>&lt;P&gt;Some manipulation on the RADIUS side might help e.g.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-crp-realm-names" target="_blank"&gt;https://docs.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-crp-realm-names&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Jun 2020 08:18:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/86914#M11182</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2020-06-01T08:18:36Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and UPN suffix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/86975#M11183</link>
      <description>Thanks Chris, i think you right, need to try to cut suffix there.</description>
      <pubDate>Mon, 01 Jun 2020 19:16:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/86975#M11183</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2020-06-01T19:16:42Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and UPN suffix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/87002#M11184</link>
      <description>I would also suggest using "alias feature" in Identity Collector (which can replace AD Query).&lt;BR /&gt;This feature allows to replace one domain with another - read more about it on our admin guide.&lt;BR /&gt;&lt;BR /&gt;As for Identity Collector vs. AD Query differences - see sk108235.</description>
      <pubDate>Tue, 02 Jun 2020 06:44:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/87002#M11184</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2020-06-02T06:44:23Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and UPN suffix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/87016#M11185</link>
      <description>&lt;P&gt;Thanks&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For completeness do we have any other options to manipulate the RADIUS data (realm matching) if it can't be done upstream?&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Chris&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jun 2020 07:26:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/87016#M11185</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2020-06-02T07:26:19Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and UPN suffix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/87082#M11186</link>
      <description>Thanks Royi, i will try. Just some questions, IA and Remote Access VPN use different ways for authorization? If i turn off AD Query in IA, VPN should continue works?</description>
      <pubDate>Tue, 02 Jun 2020 16:11:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/87082#M11186</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2020-06-02T16:11:06Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and UPN suffix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/87099#M11187</link>
      <description>Thanks guys, i didnt fix my problem, but found another solution.&lt;BR /&gt;Royi, i deployed IC, it works, but it not recognize Radius users, dont see them, anyway i kept it.&lt;BR /&gt;Chris, your solution works (i played with realm info), but looks like WLC send info to CheckPoint (and own log) before NPS (Radius) server, i can change realm info, but CHeckPoint sees original request with domain info.&lt;BR /&gt;I blocked any access to wireless with domain info, just username, or no wifi &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;BR /&gt;Also opened Cisco's support case, not sure, maybe possible to cut realm info on WLC directly&lt;BR /&gt;thanks guys!</description>
      <pubDate>Tue, 02 Jun 2020 19:53:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-UPN-suffix/m-p/87099#M11187</guid>
      <dc:creator>Sergo89</dc:creator>
      <dc:date>2020-06-02T19:53:07Z</dc:date>
    </item>
  </channel>
</rss>

