<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity awareness question in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-question/m-p/112781#M15691</link>
    <description>&lt;P&gt;How are identities being acquired in this case?&lt;BR /&gt;Note that in general, you can expect erratic results on multi-user machines unless it's a terminal server and you install the appropriate agent.&lt;BR /&gt;That said, the identity shouldn't change like that, unless it's something unique with the Mac.&lt;/P&gt;</description>
    <pubDate>Tue, 09 Mar 2021 00:45:29 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-03-09T00:45:29Z</dc:date>
    <item>
      <title>Identity awareness question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-question/m-p/112773#M15689</link>
      <description>Hello everyone,

I know this may sound like a dumb question, but Im little confused as to why the output is the way it looks. So lets say you have 2 users logging into one PC (well mac in this case, but I dont think thats really relevant) and both are logged into it at the same time (lets call them user 1 and user2).

Well, I was expecting when doing command on the firewall -&amp;gt; watch -d pdp monitor ip 10.10.10.55 (ip of the machine), output to show BOTH users logged in, NOT just one...what seems to be happening is that command keeps switching between 2 users every minute or so...is that normal??
The reason Im asking this is because in IA setting on the gateway, option assume only one user is connected per machine is unchecked. This is important to the customer because we are doing url blocking based on the users, NOT ip addresses.

Anyway, maybe Im understanding this wrong...if someone could clarify, would be awesome.
Tx

Andy</description>
      <pubDate>Mon, 08 Mar 2021 23:17:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-question/m-p/112773#M15689</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-08T23:17:06Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-question/m-p/112779#M15690</link>
      <description>&lt;P&gt;&lt;A href="https://www.checkpoint.com/downloads/products/cp-identity-awareness-reference-architecture-best-practices.pdf" target="_self"&gt;As per IA Architecture and Best Practices&lt;/A&gt; , bolow are the common mistakes (see the last point):&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Forgetting to Exclude Services(see sk131792)–When using AD Query itis highly recommended to activate “assume only one user per device” or Identity Collector which “assumes one user per device”by defaultand exclude any non-user devices that may be inspected,such as Exchange servers or Citrix servers.&lt;/LI&gt;
&lt;LI&gt;It’salso highly recommended to exclude all known service accounts. These are not used in the user-based policy and so they create an unnecessary overhead.&lt;/LI&gt;
&lt;LI&gt;Forgetting to Exclude Multi-user Hosts–When using ADQuery orIdentity Collector.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 00:36:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-question/m-p/112779#M15690</guid>
      <dc:creator>Vladimir</dc:creator>
      <dc:date>2021-03-09T00:36:28Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-question/m-p/112781#M15691</link>
      <description>&lt;P&gt;How are identities being acquired in this case?&lt;BR /&gt;Note that in general, you can expect erratic results on multi-user machines unless it's a terminal server and you install the appropriate agent.&lt;BR /&gt;That said, the identity shouldn't change like that, unless it's something unique with the Mac.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 00:45:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-question/m-p/112781#M15691</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-09T00:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-question/m-p/112784#M15692</link>
      <description>&lt;P&gt;Thanks for the input gents, appreciated. I have to do bit more testing, but I was under impression that if multiple users I logging in to the same machine, pdp monitor would show that, but I dont believe thats the case. There is IA agent installed on MAC, so it authenticates to the gateway, which then goes to AD.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 00:58:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-question/m-p/112784#M15692</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-09T00:58:48Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-question/m-p/112785#M15693</link>
      <description>&lt;P&gt;The Identity Agent that runs on a regular PC or Mac "assumes" a single user is present, I believe.&lt;BR /&gt;If it's running on both users, that might explain what's going on.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 01:03:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-question/m-p/112785#M15693</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-09T01:03:14Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness question</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-question/m-p/112786#M15694</link>
      <description>&lt;P&gt;Ok, correct, that makes sense then, as it is running and showing connected on both users logged in.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tx!&lt;/P&gt;</description>
      <pubDate>Tue, 09 Mar 2021 01:50:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-question/m-p/112786#M15694</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-03-09T01:50:10Z</dc:date>
    </item>
  </channel>
</rss>

