<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness - Browser Based Authentication change accessibility in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Browser-Based-Authentication-change/m-p/170881#M30950</link>
    <description>&lt;P&gt;Yes, users can browse to a specific URL on the gateway and authenticate manually.&lt;BR /&gt;You can see the precise URL for your environment and configure various aspects of it here:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-02-09 at 1.03.14 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19527iE9324DEFD8CE8E40/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-02-09 at 1.03.14 PM.png" alt="Screenshot 2023-02-09 at 1.03.14 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 09 Feb 2023 19:07:08 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-02-09T19:07:08Z</dc:date>
    <item>
      <title>Identity Awareness - Browser Based Authentication change accessibility</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Browser-Based-Authentication-change/m-p/170470#M30883</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;We have Identity Awareness with Browser based authentication activated, which is accessible "through all Interfaces". We want to change this to the option "According to the Firewall Policy".&amp;nbsp; What exact rules are needed here? There is no further explantion for the option in the SmartConsole help. I also couldn't find anything online.&lt;/P&gt;&lt;P&gt;When we activated the "According to the Firewall Policy" option once, the Portal was not accessible at all anymore, although there was a rule with the action "accept (display captive portal)".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We're running R81.10 T45.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2023 15:37:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Browser-Based-Authentication-change/m-p/170470#M30883</guid>
      <dc:creator>michael3</dc:creator>
      <dc:date>2023-02-06T15:37:12Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Browser Based Authentication change accessibility</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Browser-Based-Authentication-change/m-p/170518#M30891</link>
      <description>&lt;P&gt;TCP port 443 (https) is what is required for Captive Portal to work.&lt;BR /&gt;The rule should just have a simple Accept action (not with Display Captive Portal).&lt;/P&gt;</description>
      <pubDate>Mon, 06 Feb 2023 22:32:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Browser-Based-Authentication-change/m-p/170518#M30891</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-06T22:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Browser Based Authentication change accessibility</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Browser-Based-Authentication-change/m-p/170627#M30898</link>
      <description>&lt;P&gt;Hallo,&lt;/P&gt;&lt;P&gt;thx for your reply, so i would a need a rule like:&lt;BR /&gt;Usergroup1 -&amp;gt; GatewayIP (where the Captive portal (should) run) : https accept&lt;/P&gt;&lt;P&gt;But how do I acheive that different User objects are only allowed to access a certain destination then? Does this also mean there are no redirects anymore and customers directly have to enter the Gateway IP or DNS to the Browser?&lt;/P&gt;&lt;P&gt;At the moment we have rules like the following scheme:&lt;/P&gt;&lt;P&gt;Users1 -&amp;gt; DestinationIP1 : services accept(display captive portal)&lt;BR /&gt;Users2 -&amp;gt; DestinationnetworkX : services accept(display captive portal)&lt;/P&gt;&lt;P&gt;In the Users Object, LDAP Groups, possible source networks etc are defined.&lt;BR /&gt;If the destination is a http site, I'm automatically redirected to Identity Portal.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;I mean a redirect is not necesarry, just that I can define different usergroups with different destinations and services&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 17:45:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Browser-Based-Authentication-change/m-p/170627#M30898</guid>
      <dc:creator>michael3</dc:creator>
      <dc:date>2023-02-07T17:45:29Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Browser Based Authentication change accessibility</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Browser-Based-Authentication-change/m-p/170649#M30910</link>
      <description>&lt;P&gt;The rule I described allows the Captive Portal to be reached when "According to Firewall Policy" is used.&lt;BR /&gt;You still need to have your other rules in place.&lt;BR /&gt;Also, HTTPS Inspection must be enabled in order for redirects to occur when the destination site is HTTPS.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 07 Feb 2023 21:25:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Browser-Based-Authentication-change/m-p/170649#M30910</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-07T21:25:43Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Browser Based Authentication change accessibility</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Browser-Based-Authentication-change/m-p/170871#M30947</link>
      <description>&lt;P&gt;Hallo,&lt;/P&gt;&lt;P&gt;thank you very much, I now tried this successfully &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;I have one final question: What would I have to change, sucht that there isn't any redirect? So people&amp;nbsp;just have to know that they browse to the Gateway (Identity Portal) first and then after successful login, they can do what they are allowed according to the rules.&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 17:10:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Browser-Based-Authentication-change/m-p/170871#M30947</guid>
      <dc:creator>michael3</dc:creator>
      <dc:date>2023-02-09T17:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Browser Based Authentication change accessibility</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Browser-Based-Authentication-change/m-p/170881#M30950</link>
      <description>&lt;P&gt;Yes, users can browse to a specific URL on the gateway and authenticate manually.&lt;BR /&gt;You can see the precise URL for your environment and configure various aspects of it here:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2023-02-09 at 1.03.14 PM.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/19527iE9324DEFD8CE8E40/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2023-02-09 at 1.03.14 PM.png" alt="Screenshot 2023-02-09 at 1.03.14 PM.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 09 Feb 2023 19:07:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Browser-Based-Authentication-change/m-p/170881#M30950</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-02-09T19:07:08Z</dc:date>
    </item>
  </channel>
</rss>

