<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity awareness blade issue in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140158#M21473</link>
    <description>&lt;P&gt;What version/JHF level?&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 02 Feb 2022 06:51:04 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-02-02T06:51:04Z</dc:date>
    <item>
      <title>Identity awareness blade issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140130#M21463</link>
      <description>&lt;P&gt;Hey guys,&lt;/P&gt;
&lt;P&gt;I hope someone can clarify this for me. I dont believe it ever worked properly for the customer. So, here is the situation. IA blade is enabled and there are few access roles configured. It does work for the most part, but one thing that fails is this...&lt;/P&gt;
&lt;P&gt;So, if same user logs into multiple machines, then ONLY first machine they logged into will give them Internet access, not any sequential ones. So say user joesmith logs into windows box with IP 10.10.10.10, then to another windows with IP 10.10.10.11 and 3rd one 10.10.10.12...well, ONLY 10.10.10.10 IP machine will give them proper external access, not any other ones.&lt;/P&gt;
&lt;P&gt;Option on gateway to assume that only one user is connected per machine is not checked, so logically, one would think that would allow same user to get access when connected to multiple machines. The drop we see on fw is that it comes to right layer and then explicit clean up rule drops the traffic, since it does not recognize access role association. We tried revoking IP, user, pdp update all...nothing worked.&lt;/P&gt;
&lt;P&gt;Not sure if there is something else Im missing here?&lt;/P&gt;
&lt;P&gt;Thanks as always!&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 00:57:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140130#M21463</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-02T00:57:32Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness blade issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140158#M21473</link>
      <description>&lt;P&gt;What version/JHF level?&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 06:51:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140158#M21473</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-02-02T06:51:04Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness blade issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140180#M21478</link>
      <description>&lt;P&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk115776&amp;amp;partition=Advanced&amp;amp;product=Identity" target="_blank"&gt;sk115776: Specific user is not identified by &lt;STRONG&gt;Identity&lt;/STRONG&gt; &lt;STRONG&gt;Awareness&lt;/STRONG&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 09:34:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140180#M21478</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-02-02T09:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness blade issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140211#M21486</link>
      <description>&lt;P&gt;R81.10 mgmt jumbo 9, R80.40 jumbo 120 gateway cluster&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 11:36:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140211#M21486</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-02T11:36:24Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness blade issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140212#M21487</link>
      <description>&lt;P&gt;Thanks a lot G, will check this in a bit.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 11:37:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140212#M21487</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-02T11:37:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness blade issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140237#M21496</link>
      <description>&lt;P&gt;I really hope this works. I did the changes and will ask customer to test. Funny enough, I went to that gateway setting thats in sk yesterday, but totally omitted the part about "automatically exclude users...". My bad...will let you know for sure if this fixes it. Thanks as always brother, grateful for all the help.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 13:50:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140237#M21496</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-02T13:50:15Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness blade issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140255#M21506</link>
      <description>&lt;P&gt;Sadly, did not help. I made changes and asked client to test, but same behavior, no access when same user logs into 2nd machine. I will call TAC later and see if we can do some tests, since we already have active case opened for this since the weekend.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 15:10:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140255#M21506</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-02T15:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness blade issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140265#M21510</link>
      <description>&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_IdentityAwareness_AdminGuide/Topics-IDAG/CLI/pdp-conciliation.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R80.40/WebAdminGuides/EN/CP_R80.40_IdentityAwareness_AdminGuide/Topics-IDAG/CLI/pdp-conciliation.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Try enabling any of the above, depending on the source from where your identities are being learned.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 15:59:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140265#M21510</guid>
      <dc:creator>lfar</dc:creator>
      <dc:date>2022-02-02T15:59:55Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness blade issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140267#M21511</link>
      <description>&lt;P&gt;I ran it on both cluster members and asked client to test, so will see if any difference. Will keep you posted.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 16:10:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140267#M21511</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-02T16:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness blade issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140269#M21512</link>
      <description>&lt;P&gt;No luck, just tried.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 16:23:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140269#M21512</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-02T16:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness blade issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140291#M21519</link>
      <description>&lt;P&gt;Just quick update guys...spoke with TAC and Harry had me do below options (we had checked internal users before, as well as all gateways directories). Once this was done, we pushed policy, but also had to install identity agent on windows machine we tested and then same user worked fine! I will still ask customer to test with few different users.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15214iBB92F1954EF4AE64/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_2.png" alt="Screenshot_2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 19:47:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140291#M21519</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-02T19:47:12Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness blade issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140306#M21526</link>
      <description>&lt;P&gt;Have had the issue that needed to install the identity agents if users roam quickly between wifi/lan to make sure update correctly.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 23:05:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140306#M21526</guid>
      <dc:creator>Magnus-Holmberg</dc:creator>
      <dc:date>2022-02-02T23:05:19Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness blade issue</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140315#M21527</link>
      <description>&lt;P&gt;I never realized that before, but I guess IA agent is needed on windows in situation like this. Otherwise, if its only 1 user logged into 1 machine at the time, no need for IA agent.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Feb 2022 23:48:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-blade-issue/m-p/140315#M21527</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-02-02T23:48:39Z</dc:date>
    </item>
  </channel>
</rss>

