<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Limiting concurrent user authentication in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/168957#M30548</link>
    <description>&lt;P&gt;Hello Checkpoint Checkmates Forum,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im new in this solution, but have similar experience with another firewall product.&lt;/P&gt;&lt;P&gt;According to my topic, I recently had a question from a customer about the Checkpoint Firewall's ability to restrict concurrent user authentication, whether local users or AD integration are used. Does Checkpoint Firewall support this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The use case is similar with this for other product :&amp;nbsp;&lt;A href="https://community.fortinet.com/t5/FortiGate/Technical-Tip-Limiting-concurrent-user-authentication/ta-p/199277" target="_blank"&gt;https://community.fortinet.com/t5/FortiGate/Technical-Tip-Limiting-concurrent-user-authentication/ta-p/199277&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example : we have user "CheckPoint", so this user only permitted to use a maximum of 5 devices for a captive portal or vpn.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 24 Jan 2023 15:46:48 GMT</pubDate>
    <dc:creator>Fabz</dc:creator>
    <dc:date>2023-01-24T15:46:48Z</dc:date>
    <item>
      <title>Limiting concurrent user authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/168957#M30548</link>
      <description>&lt;P&gt;Hello Checkpoint Checkmates Forum,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Im new in this solution, but have similar experience with another firewall product.&lt;/P&gt;&lt;P&gt;According to my topic, I recently had a question from a customer about the Checkpoint Firewall's ability to restrict concurrent user authentication, whether local users or AD integration are used. Does Checkpoint Firewall support this?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The use case is similar with this for other product :&amp;nbsp;&lt;A href="https://community.fortinet.com/t5/FortiGate/Technical-Tip-Limiting-concurrent-user-authentication/ta-p/199277" target="_blank"&gt;https://community.fortinet.com/t5/FortiGate/Technical-Tip-Limiting-concurrent-user-authentication/ta-p/199277&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For example : we have user "CheckPoint", so this user only permitted to use a maximum of 5 devices for a captive portal or vpn.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 15:46:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/168957#M30548</guid>
      <dc:creator>Fabz</dc:creator>
      <dc:date>2023-01-24T15:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting concurrent user authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/168973#M30555</link>
      <description>&lt;P&gt;Excellent question! Honestly, I never thought about it in all these years, but now that you mentioned it, Im also cusious to see if there is a way. I looked everywhere in global properties, gateway settings and cant find setting related to number or re-authentications.&lt;/P&gt;
&lt;P&gt;I also checked guidbedit as well, but not sure if there is something there, but will keep looking.&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 17:28:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/168973#M30555</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-24T17:28:21Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting concurrent user authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/168997#M30562</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes i also looked at sk document, but found nothing. May this feature will be available on the next new OS?&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 23:42:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/168997#M30562</guid>
      <dc:creator>Fabz</dc:creator>
      <dc:date>2023-01-24T23:42:12Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting concurrent user authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/168998#M30563</link>
      <description>&lt;P&gt;&lt;SPAN&gt;hi&amp;nbsp;&lt;/SPAN&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/38213"&gt;@the_rock&lt;/a&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes i also looked at sk document, but found nothing. May this feature will be available on the next new OS? Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jan 2023 23:43:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/168998#M30563</guid>
      <dc:creator>Fabz</dc:creator>
      <dc:date>2023-01-24T23:43:59Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting concurrent user authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/169001#M30565</link>
      <description>&lt;P&gt;Hopefully&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/181"&gt;@_Val_&lt;/a&gt;&amp;nbsp;or&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;may know...they are CP encyclopedias.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 01:11:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/169001#M30565</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-25T01:11:29Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting concurrent user authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/169031#M30572</link>
      <description>&lt;P&gt;In what precise context are we discussing authentication?&lt;BR /&gt;For example, in Remote Access, there's a Global Property that specifically disallows a user from connecting to the gateway more than once.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19288i2FD4CA99608079BE/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;In other contexts...not sure.&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;do we have some way to prevent a single user from showing up on multiple IPs?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 05:42:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/169031#M30572</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-25T05:42:13Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting concurrent user authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/169033#M30573</link>
      <description>&lt;P&gt;Hm, totally missed that option today in my lab, will verify again tomorrow.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 05:54:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/169033#M30573</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-01-25T05:54:23Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting concurrent user authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/169109#M30600</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp; is it alao applicable for Captive Portal?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 13:27:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/169109#M30600</guid>
      <dc:creator>Fabz</dc:creator>
      <dc:date>2023-01-25T13:27:16Z</dc:date>
    </item>
    <item>
      <title>Re: Limiting concurrent user authentication</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/169177#M30617</link>
      <description>&lt;P&gt;Captive Portal is part of Identity Awareness, and the above only applies to Remote Access VPN.&lt;BR /&gt;While we have mechanisms to filter out users that appear on multiple computers, that requires R81.20.&lt;BR /&gt;This doesn't "restrict" a user to, say, 5 logins, but it invalidates ALL sessions for any user that exceeds whatever you've configured the threshholds for.&lt;BR /&gt;This is also not the specific use case for this feature (it's designed for Service accounts specifically), so it may not work for that purpose.&lt;/P&gt;
&lt;P&gt;Assuming you're using an external identity source like Active Directly, it should be possible to configure such login limits there.&amp;nbsp;&lt;BR /&gt;For locally defined users where the password is defined in the Check Point management, there is no way to prevent them from logging in multiple times; this would be an RFE.&lt;/P&gt;</description>
      <pubDate>Wed, 25 Jan 2023 19:39:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Limiting-concurrent-user-authentication/m-p/169177#M30617</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-01-25T19:39:36Z</dc:date>
    </item>
  </channel>
</rss>

