<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness ignores machines in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-ignores-machines/m-p/74935#M11653</link>
    <description>&lt;P&gt;Quoting from here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk60301" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk60301&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;User Change:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If an unknown user association is encountered, and "assume one user per IP" is "on", all of the currently associated users are revoked, and the new association is added as the only user for this IP address. If there were any machine associations for this IP address, they are left intact. See "Single User Assumption" in the Identity Awareness Administration Guide for more information.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Multi user host detected:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If 7 (by default) users are currently associated for the same IP address, the IP address is automatically considered a "multi user host". A log about it is issued, all of the currently associated users are revoked and all new user associations for this IP address are ignored.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In a nutshell, AD Query as the default choice only working reliably if users do not change machines too often. AD Query looks for log on events only and ignores log off ones. You can tweak the behaviour by tuning "Single User Assumption" settings (see the guide), but if you want a reliable tool allowing often user changes on a single PC, use IA Agent.&lt;/P&gt;</description>
    <pubDate>Wed, 12 Feb 2020 08:37:45 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2020-02-12T08:37:45Z</dc:date>
    <item>
      <title>Identity Awareness ignores machines</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-ignores-machines/m-p/74930#M11652</link>
      <description>&lt;P&gt;Hello!&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am setting up a test environment. There is a distributed installation of Check Point, a pair of test computers, AD DS, IIS. AD Query connects correctly. Then, when changing the user, the message "&lt;STRONG&gt;Machine (machine name) at (IP address) has 1 users (or more) currently connected to it, and will be automatically ignored"&amp;nbsp;&lt;/STRONG&gt;appears in the logs. I did not make any additional settings on the gateway or in the account unit. Please tell me how to fix it.&lt;/P&gt;&lt;P&gt;Thanks!!&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 08:17:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-ignores-machines/m-p/74930#M11652</guid>
      <dc:creator>Alexey_Dagil</dc:creator>
      <dc:date>2020-02-12T08:17:55Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness ignores machines</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-ignores-machines/m-p/74935#M11653</link>
      <description>&lt;P&gt;Quoting from here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk60301" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk60301&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;STRONG&gt;User Change:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If an unknown user association is encountered, and "assume one user per IP" is "on", all of the currently associated users are revoked, and the new association is added as the only user for this IP address. If there were any machine associations for this IP address, they are left intact. See "Single User Assumption" in the Identity Awareness Administration Guide for more information.&lt;BR /&gt;&lt;BR /&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;STRONG&gt;Multi user host detected:&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;If 7 (by default) users are currently associated for the same IP address, the IP address is automatically considered a "multi user host". A log about it is issued, all of the currently associated users are revoked and all new user associations for this IP address are ignored.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;In a nutshell, AD Query as the default choice only working reliably if users do not change machines too often. AD Query looks for log on events only and ignores log off ones. You can tweak the behaviour by tuning "Single User Assumption" settings (see the guide), but if you want a reliable tool allowing often user changes on a single PC, use IA Agent.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 08:37:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-ignores-machines/m-p/74935#M11653</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-02-12T08:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness ignores machines</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-ignores-machines/m-p/74936#M11654</link>
      <description>&lt;P&gt;In addition, look here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114096" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk114096&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;for setting multi-user threshold, if required&lt;/P&gt;</description>
      <pubDate>Wed, 12 Feb 2020 08:40:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-ignores-machines/m-p/74936#M11654</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-02-12T08:40:20Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness ignores machines</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-ignores-machines/m-p/75058#M11655</link>
      <description>Thanks! It was a Multi-User detection threshold.</description>
      <pubDate>Thu, 13 Feb 2020 06:06:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-ignores-machines/m-p/75058#M11655</guid>
      <dc:creator>Alexey_Dagil</dc:creator>
      <dc:date>2020-02-13T06:06:35Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness ignores machines</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-ignores-machines/m-p/75076#M11656</link>
      <description>&lt;P&gt;I am glad it works for you now&lt;/P&gt;</description>
      <pubDate>Thu, 13 Feb 2020 09:49:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-ignores-machines/m-p/75076#M11656</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2020-02-13T09:49:35Z</dc:date>
    </item>
  </channel>
</rss>

