<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point Identity Awareness identity collector agent proxy bypass explicit proxy in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/173354#M31529</link>
    <description>&lt;P&gt;No, no, no, I was asking if you are seeing traffic towards the GW from Identity client in the proxy logs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also you did not tell me anything if you have set the proxy on User ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ty,&lt;/P&gt;
&lt;P&gt;PS: according to some, the domains or FQDN can be also in the bypass list... '&lt;SPAN&gt;could use this format.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;netsh winhttp set proxy proxy-server="&lt;/SPAN&gt;&lt;SPAN&gt;192.168.2.2:8080&lt;/SPAN&gt;&lt;SPAN&gt;" bypass-list=&lt;/SPAN&gt;&lt;SPAN&gt;"*.ourdomain.com;*.yourdomain.com*"'&lt;BR /&gt;So give that a try....&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 02 Mar 2023 12:27:52 GMT</pubDate>
    <dc:creator>Sorin_Gogean</dc:creator>
    <dc:date>2023-03-02T12:27:52Z</dc:date>
    <item>
      <title>Check Point Identity Awareness identity collector agent proxy bypass explicit proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/173247#M31524</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;I am trying to deploy a Identity Awareness identity collector agent on a server and to bypass the proxy server.&lt;/P&gt;&lt;P&gt;When we try to exclude the agent from the proxy traffic using command it does not work.&lt;/P&gt;&lt;P&gt;netsh winhttp set proxy proxy.company.com:80 "10.0.0.0/8"&lt;/P&gt;&lt;P&gt;Current WinHTTP proxy settings:&lt;/P&gt;&lt;P&gt;Proxy Server(s) : proxy.company.com:80&lt;BR /&gt;Bypass List : 10.0.0.0/8&lt;/P&gt;&lt;P&gt;Only when we configure netsh winhttp reset proxy to completely shutdown the proxy on OS level the agent connects successfully to the gateway.&lt;/P&gt;&lt;P&gt;I there any supported documented configuration possibly to exclude the only the IA identity collector agent from proxy traffic using netsh?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 01 Mar 2023 18:13:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/173247#M31524</guid>
      <dc:creator>dehaasm</dc:creator>
      <dc:date>2023-03-01T18:13:01Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Identity Awareness identity collector agent proxy bypass explicit proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/173327#M31525</link>
      <description>&lt;P&gt;Hello,&lt;BR /&gt;&lt;BR /&gt;I don't remember seeing proxy options when I tested the Identity Client (still it was 1 year ago).&lt;BR /&gt;Anyway, is the FQDN that you are addressing your client covered by the 10.0.0.0/8 ? You might try to skip some domain or full FQDN, still I'm not convinced netsh supports that. &lt;BR /&gt;&lt;BR /&gt;T&lt;SPAN&gt;hank you,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 10:47:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/173327#M31525</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2023-03-02T10:47:14Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Identity Awareness identity collector agent proxy bypass explicit proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/173332#M31526</link>
      <description>&lt;P&gt;Hi Sorin,&lt;/P&gt;&lt;P&gt;Yes it is covered with that, only disabling the explicit proxy completely works, hence the reason for the question. If it is not (yet) supported by Check Point I would like to hear that.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 10:59:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/173332#M31526</guid>
      <dc:creator>dehaasm</dc:creator>
      <dc:date>2023-03-02T10:59:52Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Identity Awareness identity collector agent proxy bypass explicit proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/173338#M31527</link>
      <description>&lt;P&gt;And with that set-up, you are seeing the Client traffic in the proxy logs ?&lt;BR /&gt;Can you try and do that exception at the user level, same time with the machine level.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could be that the Identity Client is started by user and not machine (just an ideea).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ty,&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 11:11:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/173338#M31527</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2023-03-02T11:11:28Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Identity Awareness identity collector agent proxy bypass explicit proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/173345#M31528</link>
      <description>&lt;P&gt;Yes with the netsh http proxy reset command we see the logs coming into the gateway and the trust is established.&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 11:40:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/173345#M31528</guid>
      <dc:creator>dehaasm</dc:creator>
      <dc:date>2023-03-02T11:40:23Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Identity Awareness identity collector agent proxy bypass explicit proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/173354#M31529</link>
      <description>&lt;P&gt;No, no, no, I was asking if you are seeing traffic towards the GW from Identity client in the proxy logs.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also you did not tell me anything if you have set the proxy on User ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ty,&lt;/P&gt;
&lt;P&gt;PS: according to some, the domains or FQDN can be also in the bypass list... '&lt;SPAN&gt;could use this format.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;netsh winhttp set proxy proxy-server="&lt;/SPAN&gt;&lt;SPAN&gt;192.168.2.2:8080&lt;/SPAN&gt;&lt;SPAN&gt;" bypass-list=&lt;/SPAN&gt;&lt;SPAN&gt;"*.ourdomain.com;*.yourdomain.com*"'&lt;BR /&gt;So give that a try....&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 12:27:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/173354#M31529</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2023-03-02T12:27:52Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Identity Awareness identity collector agent proxy bypass explicit proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/173415#M31530</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;can you have someone on your team comment on this?&lt;/P&gt;</description>
      <pubDate>Thu, 02 Mar 2023 20:21:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/173415#M31530</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-02T20:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Identity Awareness identity collector agent proxy bypass explicit proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/175191#M31934</link>
      <description>&lt;P&gt;no answer from internally is it supported to have explicit proxy with IA agent installed?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 08:40:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/175191#M31934</guid>
      <dc:creator>dehaasm</dc:creator>
      <dc:date>2023-03-17T08:40:58Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Identity Awareness identity collector agent proxy bypass explicit proxy</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/175263#M31945</link>
      <description>&lt;P&gt;I tagged the wrong person.&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1635"&gt;@Liel_Shaish&lt;/a&gt;&amp;nbsp;can you or someone on the team comment on this?&lt;/P&gt;
&lt;P&gt;I would also ask the TAC if you haven't already.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Mar 2023 23:17:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Awareness-identity-collector-agent-proxy/m-p/175263#M31945</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-03-17T23:17:27Z</dc:date>
    </item>
  </channel>
</rss>

