<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Collector and multiple accounts with different privileges on same machine in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-multiple-accounts-with-different/m-p/199787#M37470</link>
    <description>&lt;P&gt;What version/JHF?&lt;BR /&gt;The log card for the drop should show the groups that were identified for that user.&lt;BR /&gt;Does the user show up in pdp monitor output?&lt;/P&gt;</description>
    <pubDate>Tue, 05 Dec 2023 18:49:37 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-12-05T18:49:37Z</dc:date>
    <item>
      <title>Identity Collector and multiple accounts with different privileges on same machine</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-multiple-accounts-with-different/m-p/199475#M37395</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I'm experiencing some issues with the Identity Collector and firewall rules that are dependent on that service.&lt;/P&gt;&lt;P&gt;I will try to explain the issues in the following:&lt;/P&gt;&lt;P&gt;I log on to ip 1.2.3.4 with my accoount Y and Identity Collector tells that to the firewall (user Y is logged on to 1.2.3.4).&lt;/P&gt;&lt;P&gt;I have a rule that says if you're a member of AD group X, it can download executables etc. My account Y is member of that group, and can download.&lt;/P&gt;&lt;P&gt;So good so far.&lt;/P&gt;&lt;P&gt;Now I open a command prompt with my administrator account Z on the same machine with ip 1.2.3.4. The Identity Collector registers that account Z is now logged on to 1.2.3.4. If I now go and try to download an executable (e.g. a patch from somewhere) I can't because account Z is not member of the AD group that allows download.&lt;/P&gt;&lt;P&gt;So, it seems like the Identity Collector gets confused when I use different accounts on the some ip: I have logged on to Windows on the machine with ip 1.2.3.4 and account Y, but I need to use my administrator account Z on occasion and now the Identity Collector tells the firewall that Z is logged on to 1.2.3.4.&lt;/P&gt;&lt;P&gt;I don't know if that is by design, however, it is causing some issues for me an my team.&lt;/P&gt;&lt;P&gt;Have any of you experienced something similar and have you got an idea how to fix it so to say? Is there a way to get around this issue?&lt;/P&gt;&lt;P&gt;I hope it makes sense and 'm sorry if it all sounds a bit confusing. Please ask me to elaborate if necessary.&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 14:50:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-multiple-accounts-with-different/m-p/199475#M37395</guid>
      <dc:creator>JPR</dc:creator>
      <dc:date>2023-12-01T14:50:46Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and multiple accounts with different privileges on same machine</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-multiple-accounts-with-different/m-p/199480#M37398</link>
      <description>&lt;P&gt;The only way you can differentiate multiple users with different levels of access on the same IP is to deploy MUH on the relevant workstation.&lt;BR /&gt;It is otherwise not possible for the gateway to determine which user at that IP is making the connection.&lt;BR /&gt;Therefore, this is expected behavior.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Dec 2023 14:57:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-multiple-accounts-with-different/m-p/199480#M37398</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-01T14:57:29Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and multiple accounts with different privileges on same machine</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-multiple-accounts-with-different/m-p/199714#M37453</link>
      <description>&lt;P&gt;Okay, thanks. That's what I thought as well.&lt;/P&gt;&lt;P&gt;So, I tried marking my own computer as MUH, but now it doesn't recognize my account as being part of the allow download group.&lt;/P&gt;&lt;P&gt;The download rule is an inline rule at looks like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="ruledl.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23544iED2C5447BC44B92D/image-size/large?v=v2&amp;amp;px=999" role="button" title="ruledl.png" alt="ruledl.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;But now when I try to download an executable I hit the above rule (as I should), however, it gets blocked by the clean up rule (209.4) and not accepted by the 209.1 (I am member of the AD group that allows download). Do you have any idea why that is and if I can do anything about that?&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 09:10:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-multiple-accounts-with-different/m-p/199714#M37453</guid>
      <dc:creator>JPR</dc:creator>
      <dc:date>2023-12-05T09:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and multiple accounts with different privileges on same machine</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-multiple-accounts-with-different/m-p/199787#M37470</link>
      <description>&lt;P&gt;What version/JHF?&lt;BR /&gt;The log card for the drop should show the groups that were identified for that user.&lt;BR /&gt;Does the user show up in pdp monitor output?&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 18:49:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-multiple-accounts-with-different/m-p/199787#M37470</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-05T18:49:37Z</dc:date>
    </item>
  </channel>
</rss>

