<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity collector and MUH agent - Ignores more than 7 Logins in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-and-MUH-agent-Ignores-more-than-7-Logins/m-p/121824#M17408</link>
    <description>&lt;P&gt;Just a shot in the dark, but did you try pdp update all command?&lt;/P&gt;</description>
    <pubDate>Tue, 22 Jun 2021 12:27:44 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2021-06-22T12:27:44Z</dc:date>
    <item>
      <title>Identity collector and MUH agent - Ignores more than 7 Logins</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-and-MUH-agent-Ignores-more-than-7-Logins/m-p/121792#M17394</link>
      <description>&lt;P&gt;Hi all Checkmates,&lt;/P&gt;&lt;P&gt;This is my first post, so first of all thanks for all the great post and knowledge sharing.&lt;/P&gt;&lt;P&gt;This weekend I change my FW setup from identity sharing to identity collector, for a simpler identity sharing between my firewalls&lt;BR /&gt;On the firewall clusters I also disabled "Active directory query" as this would be done on the ID Collector.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Now FWCLUS01/DMZ ignores more than 7 logins&lt;BR /&gt;"x.x.x.x with machine: &lt;A href="mailto:Termial-Server100@domain.xzy," target="_blank"&gt;Termial-Server100@domain.xzy,&lt;/A&gt; was marked as a multi user host IP. user login events for that IP will be ignored from now on"&lt;/P&gt;&lt;P&gt;It is ingnored when it hit's the native Multi-user host Detection Threshold = 7 . I have tried to change this threshold by using the cli configuration tool "adlogconfig a" and change the "Multi-user host Detection Threshold" to "10" and install policy.&lt;BR /&gt;This does not change the behavior.&lt;/P&gt;&lt;P&gt;Do any of you know if this setting is an option when running with Identity collector ?&lt;/P&gt;&lt;P&gt;The Firewall (FWCLUS02/WAN) collecting user from terminal server via MUH Agent is accepting the the increasement of "Multi-user host Detection Threshold" but I guess this is because the MUH Agent config is this FWCLUS02/WAN and it looks at the parameter.&amp;nbsp;&lt;/P&gt;&lt;P&gt;My firewall setup:&lt;BR /&gt;The user on the terminal server environment is auth with MUH agent against FWCLUS02/WAN=Blue line&lt;BR /&gt;Identity sharing is used on both FWCLUS01/DMZ and FWCLUS02/WAN shown as the = Green line&lt;BR /&gt;VDA User A is connecting to the DMZapplicaiton = red&lt;BR /&gt;All FW/SMS is running R80.40 Take 118&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CHK Identity collector.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/12268i7509206A7AF730E7/image-size/medium?v=v2&amp;amp;px=400" role="button" title="CHK Identity collector.jpg" alt="CHK Identity collector.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;When the VDA user A connects to DMZapplication and FWCLUS01/DMZ looks up the amount of user on the terminal server from identity collector and if it is above 7 it will add into this state "x.x.x.x with machine: &lt;A href="mailto:Termial-Server100@domain.xzy," target="_blank"&gt;Termial-Server100@domain.xzy,&lt;/A&gt; was marked as a multi user host IP. user login events for that IP will be ignored from now on"&lt;BR /&gt;&lt;BR /&gt;It looks like when Identity collector is used it looks like i'm missing the parameter to increase "Multi-user host Detection Threshold" to more than 7.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hope someone in the checkmates community have been through the same and have a solution for it.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;/Henrik&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 06:28:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-and-MUH-agent-Ignores-more-than-7-Logins/m-p/121792#M17394</guid>
      <dc:creator>Henrik_Oersnes_</dc:creator>
      <dc:date>2021-06-22T06:28:25Z</dc:date>
    </item>
    <item>
      <title>Re: Identity collector and MUH agent - Ignores more than 7 Logins</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-and-MUH-agent-Ignores-more-than-7-Logins/m-p/121824#M17408</link>
      <description>&lt;P&gt;Just a shot in the dark, but did you try pdp update all command?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 12:27:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-and-MUH-agent-Ignores-more-than-7-Logins/m-p/121824#M17408</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2021-06-22T12:27:44Z</dc:date>
    </item>
    <item>
      <title>Re: Identity collector and MUH agent - Ignores more than 7 Logins</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-and-MUH-agent-Ignores-more-than-7-Logins/m-p/121883#M17420</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;I just tried it this morning nothing changed.&lt;BR /&gt;When I did a test after your command I was able to see the connection to the "DMZapplication" showed up in the logs for FWCLUS01DMZ as a compleat different user.&lt;BR /&gt;This user was who ever loged into the Terminal server latest!&lt;/P&gt;&lt;P&gt;I might have a misconfiguration/design somware.&lt;BR /&gt;Atm. it looks like the Identity collector does not work well with in a MUH setup.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 05:41:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-and-MUH-agent-Ignores-more-than-7-Logins/m-p/121883#M17420</guid>
      <dc:creator>Henrik_Oersnes_</dc:creator>
      <dc:date>2021-06-23T05:41:32Z</dc:date>
    </item>
    <item>
      <title>Re: Identity collector and MUH agent - Ignores more than 7 Logins</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-and-MUH-agent-Ignores-more-than-7-Logins/m-p/121886#M17421</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/16379"&gt;@Henrik_Oersnes_&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;another shot in the dark....Did you tried the new MUH v2 agent on your terminalserver&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk164998" target="_blank" rel="noopener"&gt;Terminal Server Agent v2 (MUH2) - FAQ&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 06:13:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-and-MUH-agent-Ignores-more-than-7-Logins/m-p/121886#M17421</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2021-06-23T06:13:36Z</dc:date>
    </item>
    <item>
      <title>Re: Identity collector and MUH agent - Ignores more than 7 Logins</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-and-MUH-agent-Ignores-more-than-7-Logins/m-p/121893#M17422</link>
      <description>&lt;P&gt;Are the terminal server IPs excluded in the identity collector config? Try to authenticate every user only via one mechanism, either via identity collector or MUHv2 agent.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 07:31:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-and-MUH-agent-Ignores-more-than-7-Logins/m-p/121893#M17422</guid>
      <dc:creator>Benedikt_Weissl</dc:creator>
      <dc:date>2021-06-23T07:31:34Z</dc:date>
    </item>
    <item>
      <title>Re: Identity collector and MUH agent - Ignores more than 7 Logins</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-and-MUH-agent-Ignores-more-than-7-Logins/m-p/121918#M17423</link>
      <description>&lt;P&gt;Hi,&lt;BR /&gt;This is a design flaw from&amp;nbsp;my side. I have misunderstood what the use case is for Identity collector.&lt;/P&gt;&lt;P&gt;I expected that the Firewall cluster/GW participated in the identity collector setup, also would send back info about users connected to them as MUH can't connect to the identity collector.&lt;/P&gt;&lt;P&gt;In my case I will need setup "Identity sharing" between the two cluster.&lt;BR /&gt;And as you write Benedik_Weissl exclude the server running with the MUH.&lt;BR /&gt;Hope to change my configuration this Friday and let you know if it works.&lt;/P&gt;&lt;P&gt;Hope Checkpoint would move MUH feature to Identity collector in a furture relase.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for your inputs.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Jun 2021 11:28:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-and-MUH-agent-Ignores-more-than-7-Logins/m-p/121918#M17423</guid>
      <dc:creator>Henrik_Oersnes_</dc:creator>
      <dc:date>2021-06-23T11:28:15Z</dc:date>
    </item>
  </channel>
</rss>

