<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic nac_max_enforced_identities parameter in fwkern.conf in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/nac-max-enforced-identities-parameter-in-fwkern-conf/m-p/133006#M19768</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we've been having this parameter occuring for quite some time now, at first for 80.40 machines with Take ~ &amp;gt;100 and now also for 80.30 (atleast on Jumbo 236).&lt;/P&gt;&lt;P&gt;There is only one community post about it:&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/fwkern-conf-modified-at-boot/td-p/115506" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/fwkern-conf-modified-at-boot/td-p/115506&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and also only one SK where it is mentioned at all (But it's referring to typos and syntax):&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?solutionid=sk173544" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?solutionid=sk173544&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The default value seems to be 30k, which it is set to 90k automatically after rebooting the gateway.&lt;/P&gt;&lt;P&gt;The HCP on Jumbo 236 is not able to handle the parameter properly (ERROR: Parameter not supported or typo issue),&lt;BR /&gt;but as it is the only value in our fwkern.conf that shouldn't be too much of an issue:&lt;/P&gt;&lt;P&gt;#cat $FWDIR/boot/modules/fwkern.conf&lt;BR /&gt;nac_max_enforced_identities=90000&lt;/P&gt;&lt;P&gt;Should be some IA related value, but I don't think that this value will ever be relevant to our relatively small company.&lt;/P&gt;&lt;P&gt;Has any of you looked further into this and maybe knows what it does and why it is changed?&lt;BR /&gt;Maybe anyone did in fact open a TAC case for this and already got an explaining answer &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Best Regards,&lt;BR /&gt;Jonas&lt;/P&gt;</description>
    <pubDate>Mon, 01 Nov 2021 11:16:08 GMT</pubDate>
    <dc:creator>Jonas_Meineke</dc:creator>
    <dc:date>2021-11-01T11:16:08Z</dc:date>
    <item>
      <title>nac_max_enforced_identities parameter in fwkern.conf</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/nac-max-enforced-identities-parameter-in-fwkern-conf/m-p/133006#M19768</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we've been having this parameter occuring for quite some time now, at first for 80.40 machines with Take ~ &amp;gt;100 and now also for 80.30 (atleast on Jumbo 236).&lt;/P&gt;&lt;P&gt;There is only one community post about it:&lt;BR /&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/fwkern-conf-modified-at-boot/td-p/115506" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/fwkern-conf-modified-at-boot/td-p/115506&lt;/A&gt;&lt;/P&gt;&lt;P&gt;and also only one SK where it is mentioned at all (But it's referring to typos and syntax):&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?solutionid=sk173544" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?solutionid=sk173544&lt;/A&gt;&lt;/P&gt;&lt;P&gt;The default value seems to be 30k, which it is set to 90k automatically after rebooting the gateway.&lt;/P&gt;&lt;P&gt;The HCP on Jumbo 236 is not able to handle the parameter properly (ERROR: Parameter not supported or typo issue),&lt;BR /&gt;but as it is the only value in our fwkern.conf that shouldn't be too much of an issue:&lt;/P&gt;&lt;P&gt;#cat $FWDIR/boot/modules/fwkern.conf&lt;BR /&gt;nac_max_enforced_identities=90000&lt;/P&gt;&lt;P&gt;Should be some IA related value, but I don't think that this value will ever be relevant to our relatively small company.&lt;/P&gt;&lt;P&gt;Has any of you looked further into this and maybe knows what it does and why it is changed?&lt;BR /&gt;Maybe anyone did in fact open a TAC case for this and already got an explaining answer &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Best Regards,&lt;BR /&gt;Jonas&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 11:16:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/nac-max-enforced-identities-parameter-in-fwkern-conf/m-p/133006#M19768</guid>
      <dc:creator>Jonas_Meineke</dc:creator>
      <dc:date>2021-11-01T11:16:08Z</dc:date>
    </item>
    <item>
      <title>Re: nac_max_enforced_identities parameter in fwkern.conf</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/nac-max-enforced-identities-parameter-in-fwkern-conf/m-p/133011#M19769</link>
      <description>&lt;P&gt;The parameter is related to global kernel tables infrastructure and not Identity Awareness. It is indeed set automatically during boot sequence, and the correct value is 90000. If you have any issue with that, please open a TAC case, otherwise, please live as is.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 12:02:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/nac-max-enforced-identities-parameter-in-fwkern-conf/m-p/133011#M19769</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-11-01T12:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: nac_max_enforced_identities parameter in fwkern.conf</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/nac-max-enforced-identities-parameter-in-fwkern-conf/m-p/133014#M19770</link>
      <description>&lt;P&gt;Hi Val,&lt;/P&gt;&lt;P&gt;that's good to know atleast; We didn't plan to remove it (as I think it will be reset again anyway), since we didn't face any issues.&lt;/P&gt;&lt;P&gt;We just wanted to know where it comes from and what it in fact does, or rather, why it should be relevant to us.&lt;BR /&gt;As there is no explanation about this parameter anywhere on the usual Check Point sites.&lt;BR /&gt;&lt;BR /&gt;Kinda strange to me, that it is written to the fwkern.conf during reboot, instead of changing the default value directly.&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 12:39:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/nac-max-enforced-identities-parameter-in-fwkern-conf/m-p/133014#M19770</guid>
      <dc:creator>Jonas_Meineke</dc:creator>
      <dc:date>2021-11-01T12:39:05Z</dc:date>
    </item>
    <item>
      <title>Re: nac_max_enforced_identities parameter in fwkern.conf</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/nac-max-enforced-identities-parameter-in-fwkern-conf/m-p/133031#M19773</link>
      <description>&lt;P&gt;I just gave you one, didn’t I? It is a parameter related to new global kernel tables architecture. This is all you need to know. &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 01 Nov 2021 16:29:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/nac-max-enforced-identities-parameter-in-fwkern-conf/m-p/133031#M19773</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-11-01T16:29:21Z</dc:date>
    </item>
  </channel>
</rss>

