<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic identity logging of internet browsing in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-logging-of-internet-browsing/m-p/141417#M26936</link>
    <description>&lt;P&gt;Hello CheckMates,&lt;/P&gt;
&lt;P&gt;we had a use case getting reports for internet browsing with user identity.&lt;BR /&gt;Normally this is no problem, but we have the requirement to install nothing in the customers directory service (ActiveDirectory).&lt;BR /&gt;Meaning no Identity Collector, no TerminalServerIdentityAgent. We can do logins or requests to the ActiveDirectory but all has to be done via external software/processes.&lt;/P&gt;
&lt;P&gt;AD-Query will work, but this will be not more supported and does not work with the newest domain controller versions.&lt;/P&gt;
&lt;P&gt;I've a feeling maybe captive portal is a solution but does this work for 3000-5000 users?&lt;BR /&gt;Does captive portal support authentication with SingleSignOn via ActiveDirectory ?&lt;BR /&gt;Does captive portal support authentication for users of TerminalServer (CitrixVDI, Microsoft TerminalServer) environments ?&lt;BR /&gt;Does captive portal support authentication if the connection seen on the gateway coming from a proxy with X_forwarding_for-flag set ?&lt;/P&gt;
&lt;P&gt;Any other ideas ?&lt;BR /&gt;Identity Collector running on a server not member of this ActiveDirectory ?&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
    <pubDate>Mon, 14 Feb 2022 12:22:40 GMT</pubDate>
    <dc:creator>Wolfgang</dc:creator>
    <dc:date>2022-02-14T12:22:40Z</dc:date>
    <item>
      <title>identity logging of internet browsing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-logging-of-internet-browsing/m-p/141417#M26936</link>
      <description>&lt;P&gt;Hello CheckMates,&lt;/P&gt;
&lt;P&gt;we had a use case getting reports for internet browsing with user identity.&lt;BR /&gt;Normally this is no problem, but we have the requirement to install nothing in the customers directory service (ActiveDirectory).&lt;BR /&gt;Meaning no Identity Collector, no TerminalServerIdentityAgent. We can do logins or requests to the ActiveDirectory but all has to be done via external software/processes.&lt;/P&gt;
&lt;P&gt;AD-Query will work, but this will be not more supported and does not work with the newest domain controller versions.&lt;/P&gt;
&lt;P&gt;I've a feeling maybe captive portal is a solution but does this work for 3000-5000 users?&lt;BR /&gt;Does captive portal support authentication with SingleSignOn via ActiveDirectory ?&lt;BR /&gt;Does captive portal support authentication for users of TerminalServer (CitrixVDI, Microsoft TerminalServer) environments ?&lt;BR /&gt;Does captive portal support authentication if the connection seen on the gateway coming from a proxy with X_forwarding_for-flag set ?&lt;/P&gt;
&lt;P&gt;Any other ideas ?&lt;BR /&gt;Identity Collector running on a server not member of this ActiveDirectory ?&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 12:22:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-logging-of-internet-browsing/m-p/141417#M26936</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2022-02-14T12:22:40Z</dc:date>
    </item>
    <item>
      <title>Re: identity logging of internet browsing</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-logging-of-internet-browsing/m-p/141484#M26937</link>
      <description>&lt;P&gt;If I get your question right, you can not install IC on the AD but you could on another server.&lt;/P&gt;&lt;P&gt;It will work as long as you get a user member of Event Log Readers group and have connectivity to both AD and FW according to the relevant SK and the firewall can do the reverse lookup.&lt;/P&gt;&lt;P&gt;It's usually my preferred choice of deployment, as customers never give access to their AD but would give me a dedicated server on which I could manage the IC software which doesn't require a domain admin account.&lt;/P&gt;</description>
      <pubDate>Mon, 14 Feb 2022 21:46:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-logging-of-internet-browsing/m-p/141484#M26937</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2022-02-14T21:46:30Z</dc:date>
    </item>
  </channel>
</rss>

