<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness forMacbook user? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-forMacbook-user/m-p/177699#M32545</link>
    <description>&lt;P&gt;If Mac users generate the same event logs as Windows users, it should work.&lt;BR /&gt;You would have to check in the relevant Windows servers to see if the same events are there as for a Windows user.&lt;BR /&gt;If you can confirm the relevant events are there for Mac and they're not getting read correctly, I recommend a TAC case: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Otherwise, you'll need to use other methods to acquire identities from Mac users (either Transparent Kerberos, Identity Collector, or Captive Portal).&lt;/P&gt;</description>
    <pubDate>Sat, 08 Apr 2023 01:08:55 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-04-08T01:08:55Z</dc:date>
    <item>
      <title>Identity Awareness forMacbook user?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-forMacbook-user/m-p/177619#M32541</link>
      <description>&lt;P&gt;Hello, all!&amp;nbsp; We use Identity Collector in our environment (R81.10).&amp;nbsp; Everything is working fine for most of our users, they are getting Identity assigned on the gateways, getting the AD Group info, and matching the appropriate rules, etc.&amp;nbsp; These users are mostly all on Windows workstations.&amp;nbsp; Now, we have a user on a Macbook that doesn't get Identity Awareness on the gateways... in the Logs it shows just their IP with no username, and in CLI on the gateway, if I do "pdp monitor ip x.x.x.x" it says "no information found for x.x.x.x."&lt;/P&gt;&lt;P&gt;So, basically no Identity Awareness for this user at all!&lt;/P&gt;&lt;P&gt;Now I know Identity Collector is an app that interfaces with Windows Active Directory via the Microsoft API, and I know this is a Macbook we're talking about... however, the help desk says this Macbook is joined to AD, and the user tells me they sign into the Macbook with their AD credentials.&amp;nbsp; So with that being said, shouldn't this work?&amp;nbsp; Or, because it's a Macbook, do the login events "look" different in AD somehow, and Identity Collector doesn't recognize those?&amp;nbsp; Is there any work-around, or any ideas on what is going on?&lt;/P&gt;</description>
      <pubDate>Thu, 06 Apr 2023 20:46:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-forMacbook-user/m-p/177619#M32541</guid>
      <dc:creator>Cypress</dc:creator>
      <dc:date>2023-04-06T20:46:00Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness forMacbook user?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-forMacbook-user/m-p/177639#M32542</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/92523"&gt;@Cypress&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I can confirm the behavior you're seeing, as indeed we are not seeing any event from AD when some of our Users that are with MAC's are logging on their non-windows boxes.&lt;/P&gt;
&lt;P&gt;I can see from Linux boxes, but not from MAC's , so I'll look around and see what I can find.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;PS: could the Identity agent work (see&amp;nbsp;sk63920)&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 07:10:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-forMacbook-user/m-p/177639#M32542</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2023-04-07T07:10:09Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness forMacbook user?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-forMacbook-user/m-p/177687#M32544</link>
      <description>&lt;P&gt;Thanks for looking into it.&amp;nbsp; I will research into the agent, maybe we can put that on the small number of MAC users we have.&amp;nbsp; The odd thing is, pretty sure this was working on AD Query.&amp;nbsp; We switched from AD Query to Identity Collector last year (I imagine most Check Point users did the same!)&lt;/P&gt;</description>
      <pubDate>Fri, 07 Apr 2023 20:48:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-forMacbook-user/m-p/177687#M32544</guid>
      <dc:creator>Cypress</dc:creator>
      <dc:date>2023-04-07T20:48:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness forMacbook user?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-forMacbook-user/m-p/177699#M32545</link>
      <description>&lt;P&gt;If Mac users generate the same event logs as Windows users, it should work.&lt;BR /&gt;You would have to check in the relevant Windows servers to see if the same events are there as for a Windows user.&lt;BR /&gt;If you can confirm the relevant events are there for Mac and they're not getting read correctly, I recommend a TAC case: &lt;A href="https://help.checkpoint.com" target="_blank"&gt;https://help.checkpoint.com&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Otherwise, you'll need to use other methods to acquire identities from Mac users (either Transparent Kerberos, Identity Collector, or Captive Portal).&lt;/P&gt;</description>
      <pubDate>Sat, 08 Apr 2023 01:08:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-forMacbook-user/m-p/177699#M32545</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-08T01:08:55Z</dc:date>
    </item>
  </channel>
</rss>

