<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic R81 Identity Collector and different user subnets in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-Identity-Collector-and-different-user-subnets/m-p/128251#M18669</link>
    <description>&lt;P&gt;My first post here in Checkmates and also a newbie when it comes to Checkpoint.&lt;/P&gt;
&lt;P&gt;Below is my Checkpoint LAB running on EVEng.&lt;/P&gt;
&lt;P&gt;GW1 &amp;amp; GW2 on R81; SMS on R81&lt;/P&gt;
&lt;P&gt;MS Active Directory 2016 + Identity Collector installed on it&lt;/P&gt;
&lt;P&gt;Identity Awareness enabled + Browser-Based Authentication (Captive Portal) + Identity Collector&lt;/P&gt;
&lt;P&gt;Captive Portal is working properly, able to redirect traffic and able to login using AD based credentials and can browse internet once logged-in&lt;/P&gt;
&lt;P&gt;Able to identify DomainUser1 in 10.10.20.x/24 network and has PDP information thus able to browse internet without being redirected to captive portal.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;No PDP information for DomainUser2 if in 10.10.40.x /24 network thus redirected to Captive Portal.&lt;/P&gt;
&lt;P&gt;I wanted to have10.10.40.x/24 network being identified by PDP as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="diagram_cp.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13558i35F3F431BED74475/image-size/large?v=v2&amp;amp;px=999" role="button" title="diagram_cp.png" alt="diagram_cp.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 01 Sep 2021 00:38:30 GMT</pubDate>
    <dc:creator>josaic</dc:creator>
    <dc:date>2021-09-01T00:38:30Z</dc:date>
    <item>
      <title>R81 Identity Collector and different user subnets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-Identity-Collector-and-different-user-subnets/m-p/128251#M18669</link>
      <description>&lt;P&gt;My first post here in Checkmates and also a newbie when it comes to Checkpoint.&lt;/P&gt;
&lt;P&gt;Below is my Checkpoint LAB running on EVEng.&lt;/P&gt;
&lt;P&gt;GW1 &amp;amp; GW2 on R81; SMS on R81&lt;/P&gt;
&lt;P&gt;MS Active Directory 2016 + Identity Collector installed on it&lt;/P&gt;
&lt;P&gt;Identity Awareness enabled + Browser-Based Authentication (Captive Portal) + Identity Collector&lt;/P&gt;
&lt;P&gt;Captive Portal is working properly, able to redirect traffic and able to login using AD based credentials and can browse internet once logged-in&lt;/P&gt;
&lt;P&gt;Able to identify DomainUser1 in 10.10.20.x/24 network and has PDP information thus able to browse internet without being redirected to captive portal.&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Issue:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;No PDP information for DomainUser2 if in 10.10.40.x /24 network thus redirected to Captive Portal.&lt;/P&gt;
&lt;P&gt;I wanted to have10.10.40.x/24 network being identified by PDP as well.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="diagram_cp.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13558i35F3F431BED74475/image-size/large?v=v2&amp;amp;px=999" role="button" title="diagram_cp.png" alt="diagram_cp.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2021 00:38:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-Identity-Collector-and-different-user-subnets/m-p/128251#M18669</guid>
      <dc:creator>josaic</dc:creator>
      <dc:date>2021-09-01T00:38:30Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Identity Collector and different user subnets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-Identity-Collector-and-different-user-subnets/m-p/128301#M18681</link>
      <description>&lt;P&gt;Where is the AD server in this diagram?&amp;nbsp;&lt;BR /&gt;I'm assuming machines in the 10.10.40/24 network are authenticating to the same AD server that is running Identity Collector?&lt;/P&gt;</description>
      <pubDate>Mon, 30 Aug 2021 05:03:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-Identity-Collector-and-different-user-subnets/m-p/128301#M18681</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-30T05:03:24Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Identity Collector and different user subnets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-Identity-Collector-and-different-user-subnets/m-p/128467#M18716</link>
      <description>&lt;P&gt;Hi. Active Directory and Identity Collector is the same machine. In the diagram you can see the Identity Collector/AD there.&lt;/P&gt;</description>
      <pubDate>Tue, 31 Aug 2021 14:14:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-Identity-Collector-and-different-user-subnets/m-p/128467#M18716</guid>
      <dc:creator>josaic</dc:creator>
      <dc:date>2021-08-31T14:14:09Z</dc:date>
    </item>
    <item>
      <title>Re: R81 Identity Collector and different user subnets</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-Identity-Collector-and-different-user-subnets/m-p/128493#M18720</link>
      <description>&lt;P&gt;Ok, that wasn't clear in the diagram, and I missed that detail in your text.&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;any ideas?&lt;/P&gt;</description>
      <pubDate>Wed, 01 Sep 2021 00:38:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/R81-Identity-Collector-and-different-user-subnets/m-p/128493#M18720</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-01T00:38:04Z</dc:date>
    </item>
  </channel>
</rss>

