<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness MUH agent queries in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/135506#M20422</link>
    <description>&lt;P&gt;Each agent can work with 256 users at the same terminal server, but you are correct, the amount of users connected is not in play here. One PDP - up to 50 MUHv2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sat, 04 Dec 2021 11:40:53 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2021-12-04T11:40:53Z</dc:date>
    <item>
      <title>Identity Awareness MUH agent queries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/135323#M20380</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are currently running IA collector and looking to install MUH agent on our terminal servers.&amp;nbsp; Something that concerns me in sk164998 is the below line.&amp;nbsp; Surely this doesn't mean that we should only have the agent installed on 50 term servers or what does this 50 relate to?&amp;nbsp; Is there a way for the MUH agent to feed into the IA collector and then send the identities that way to save opening up FW rules between all the TS to the GW?&amp;nbsp; I presume we don't need to update the gateway "allowed-client" list to include the TS as this connectivity is to the GW itself on https?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H4&gt;&lt;A target="_blank"&gt;How many MUHv2 Agents are supported on one Security Gateway?&lt;/A&gt;&lt;/H4&gt;&lt;H4&gt;It is a recommended best practice to have a maximum of 50 MUHv2 agents on one Security Gateway.&lt;/H4&gt;</description>
      <pubDate>Wed, 01 Dec 2021 10:54:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/135323#M20380</guid>
      <dc:creator>cem82</dc:creator>
      <dc:date>2021-12-01T10:54:07Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness MUH agent queries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/135484#M20415</link>
      <description>&lt;P&gt;Each terminal server should have a MUH agent. SK is saying, a single PDP should not have more than 50 agents reporting to it.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Dec 2021 17:04:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/135484#M20415</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-12-03T17:04:58Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness MUH agent queries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/135487#M20416</link>
      <description>&lt;P&gt;And a PDP exists on a gateway, so yes, it means no more than 50 MUHv2 agents should be reporting to a single gateway.&lt;BR /&gt;You can, of course, have different MUHv2 agents reporting to different gateways which share identities.&lt;BR /&gt;You may also want to have dedicated Identity Awareness gateways in some configurations that merely exist to consume and share identities with other gateways.&lt;/P&gt;</description>
      <pubDate>Fri, 03 Dec 2021 19:00:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/135487#M20416</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-12-03T19:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness MUH agent queries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/135500#M20420</link>
      <description>&lt;P&gt;Thanks for clarifying, I am surprised but does the number of expected users come into play on the recommendation of 50 agents?&amp;nbsp; EG if some TS are likely to only have a few users logged in at a time or is user count irrelevant and just the total number of TS should be less than 50?&lt;/P&gt;</description>
      <pubDate>Fri, 03 Dec 2021 23:06:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/135500#M20420</guid>
      <dc:creator>cem82</dc:creator>
      <dc:date>2021-12-03T23:06:34Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness MUH agent queries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/135506#M20422</link>
      <description>&lt;P&gt;Each agent can work with 256 users at the same terminal server, but you are correct, the amount of users connected is not in play here. One PDP - up to 50 MUHv2&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Dec 2021 11:40:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/135506#M20422</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2021-12-04T11:40:53Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness MUH agent queries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/135507#M20423</link>
      <description>&lt;P&gt;Awesome thanks for clarifying &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 04 Dec 2021 12:45:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/135507#M20423</guid>
      <dc:creator>cem82</dc:creator>
      <dc:date>2021-12-04T12:45:37Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness MUH agent queries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/143796#M22366</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;@and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; any changes about these limitation ?&lt;/P&gt;
&lt;H4 id="toc-hId-1225847455"&gt;&lt;A target="_blank"&gt;How many MUHv2 Agents are supported on one Security Gateway?&lt;/A&gt;&lt;/H4&gt;
&lt;H4 id="toc-hId--1326309506"&gt;It is a recommended best practice to have a maximum of 50 MUHv2 agents on one Security Gateway.&lt;/H4&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have a use case for 10.000 users connecting from a larger Citrix environment. Each Citrix host will be used by around 50 users, 200 Citrix hosts with MUHv2 agents needed.&lt;/P&gt;
&lt;P&gt;50 MUHv2 agents for one PDP needs 4 separate gateways and some more for redundancy. &amp;nbsp;They’re doing nothing then running PDP and sharing identities.&amp;nbsp;&lt;BR /&gt;Are there any changes upcoming to support more MUHv2 per PDP ?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2022 20:50:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/143796#M22366</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-03-15T20:50:18Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness MUH agent queries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/143804#M22368</link>
      <description>&lt;P&gt;In R81.20, there are some underlying infrastructure changes that should allow for better redundancy/resiliency/scalability.&lt;BR /&gt;What the final number are, not sure yet.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Mar 2022 22:07:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/143804#M22368</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-03-15T22:07:28Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness MUH agent queries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/159088#M27817</link>
      <description>&lt;P&gt;Can MUH information can be shared across gateways via IA sharing?? Or is it just to connected gateway??&lt;/P&gt;&lt;P&gt;MUH -&amp;gt; GW1 PDP (Internal GW) &amp;lt;-IA sharing-&amp;gt; GW2 PDP (Internet GW)&lt;/P&gt;&lt;P&gt;Does GW2 in that topology would understand packet tagging from MUH and we can build Access Role policy there??&lt;/P&gt;&lt;P&gt;How can we identify packet tag on pcap (wireshark)? Is it in readable format?&lt;/P&gt;</description>
      <pubDate>Sun, 09 Oct 2022 09:23:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/159088#M27817</guid>
      <dc:creator>Rafal_N</dc:creator>
      <dc:date>2022-10-09T09:23:48Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness MUH agent queries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/159179#M27834</link>
      <description>&lt;P&gt;Any identity source can be shared with any other gateway--that includes MUH.&lt;BR /&gt;And yes, you can build the appropriate access policy (with Access Roles) on other gateways as a result.&lt;BR /&gt;The packet tagging we do is described here:&amp;nbsp;&lt;A href="https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk60221&amp;amp;partition=Advanced&amp;amp;product=Identity" target="_blank"&gt;https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk60221&amp;amp;partition=Advanced&amp;amp;product=Identity&lt;/A&gt;&amp;nbsp;&lt;BR /&gt;The tags aren't readable.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 10 Oct 2022 18:47:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-MUH-agent-queries/m-p/159179#M27834</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-10T18:47:18Z</dc:date>
    </item>
  </channel>
</rss>

