<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple Users in Source User Name in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiple-Users-in-Source-User-Name/m-p/256518#M50237</link>
    <description>&lt;P&gt;For a computer where multiple people are logged in at the same time, consider using the &lt;A href="https://support.checkpoint.com/results/sk/sk134312" target="_self"&gt;Multi-User Host agent&lt;/A&gt;, which can actually differentiate access by multiple users from the same computer.&lt;/P&gt;
&lt;P&gt;When not using MUH and not, if multiple identities are associated with an IP due to configuration (e.g. &lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;p&lt;/FONT&gt;&lt;FONT face="courier new,courier"&gt;dp conciliation idc_multiple_users&lt;/FONT&gt;&lt;/STRONG&gt; is enabled), all of the identities will apply to the IP.&amp;nbsp;&lt;BR /&gt;Which explains the behavior you are seeing precisely.&lt;BR /&gt;Note all of this is described in &lt;A href="https://support.checkpoint.com/results/sk/sk105889" target="_self"&gt;sk105889&lt;/A&gt;&amp;nbsp;though it doesn't list the command to disable it&amp;nbsp;(e.g. &lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;p&lt;/FONT&gt;&lt;FONT face="courier new,courier"&gt;dp conciliation idc_multiple_users disable&lt;/FONT&gt;&lt;/STRONG&gt;), which is what you need to do here to get the behavior you desire.&lt;BR /&gt;I assume pdp c&lt;/P&gt;</description>
    <pubDate>Wed, 03 Sep 2025 15:40:15 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-09-03T15:40:15Z</dc:date>
    <item>
      <title>Multiple Users in Source User Name</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiple-Users-in-Source-User-Name/m-p/256402#M50207</link>
      <description>&lt;P&gt;I have running Identity Awareness by using Identity Collector method to collect the info.&lt;/P&gt;&lt;P&gt;I had login a PC via multiple user. In log, the source username show both name.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on below article, it can solved by tick ""Assume that only one user...". but this is using AD Query method.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Identity-Awareness-Multiple-Users-as-Source-User-Name/td-p/189137" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Identity-Awareness-Multiple-Users-as-Source-User-Name/td-p/189137&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;so now i using&amp;nbsp;Identity Collector, what setting i can change to solve this issue?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2025 14:50:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiple-Users-in-Source-User-Name/m-p/256402#M50207</guid>
      <dc:creator>lzl</dc:creator>
      <dc:date>2025-09-02T14:50:50Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Users in Source User Name</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiple-Users-in-Source-User-Name/m-p/256414#M50210</link>
      <description>&lt;P&gt;Is option I pointed to checked?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 02 Sep 2025 17:40:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiple-Users-in-Source-User-Name/m-p/256414#M50210</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-02T17:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Users in Source User Name</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiple-Users-in-Source-User-Name/m-p/256449#M50219</link>
      <description>&lt;P&gt;IDC as far as I know should already assume a single user per computer, per:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk105889" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk105889&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;You can check the current state of that option on your gateway with:&amp;nbsp;pdp conciliation idc_multiple_users stat&lt;/P&gt;
&lt;P&gt;If it's already disabled but you're still seeing multiple users per machine, best raise a TAC case for investigation.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 02:00:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiple-Users-in-Source-User-Name/m-p/256449#M50219</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-09-03T02:00:43Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Users in Source User Name</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiple-Users-in-Source-User-Name/m-p/256450#M50220</link>
      <description>&lt;P&gt;Never seen that sk, thank you for that!&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 02:04:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiple-Users-in-Source-User-Name/m-p/256450#M50220</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-09-03T02:04:39Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Users in Source User Name</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiple-Users-in-Source-User-Name/m-p/256453#M50221</link>
      <description>&lt;P&gt;Hi Emmap,&lt;/P&gt;&lt;P&gt;Thanks for sharing.&lt;/P&gt;&lt;P&gt;My setup requirement also is allow one user can login into a decvice at once. Just the PC will be use by multiple people. So the PC will login by multiple users. So in the "source name", i will see the username who had login to this PC.&amp;nbsp;&lt;/P&gt;&lt;P&gt;In identity collector, when select the IP related, i can see many username logged in the list. I try tick the "Ignore revoked user" to check it work or not.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;As i asking this is to confirm&amp;nbsp;even though there have 2 username showed, but only the latest user will used by gateway when go through the rule right? because i have some issue (seem latest logged user can using previous user rights asboth users in different group ) when do the testing.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 03:28:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiple-Users-in-Source-User-Name/m-p/256453#M50221</guid>
      <dc:creator>lzl</dc:creator>
      <dc:date>2025-09-03T03:28:18Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Users in Source User Name</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiple-Users-in-Source-User-Name/m-p/256456#M50223</link>
      <description>&lt;P&gt;You'll see in the traffic logs who the gateway is associating with which IP address. If there's only the one user there, then that's already ensuring that only the latest user to log in is associated with the IP address.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 06:03:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiple-Users-in-Source-User-Name/m-p/256456#M50223</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-09-03T06:03:41Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple Users in Source User Name</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiple-Users-in-Source-User-Name/m-p/256518#M50237</link>
      <description>&lt;P&gt;For a computer where multiple people are logged in at the same time, consider using the &lt;A href="https://support.checkpoint.com/results/sk/sk134312" target="_self"&gt;Multi-User Host agent&lt;/A&gt;, which can actually differentiate access by multiple users from the same computer.&lt;/P&gt;
&lt;P&gt;When not using MUH and not, if multiple identities are associated with an IP due to configuration (e.g. &lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;p&lt;/FONT&gt;&lt;FONT face="courier new,courier"&gt;dp conciliation idc_multiple_users&lt;/FONT&gt;&lt;/STRONG&gt; is enabled), all of the identities will apply to the IP.&amp;nbsp;&lt;BR /&gt;Which explains the behavior you are seeing precisely.&lt;BR /&gt;Note all of this is described in &lt;A href="https://support.checkpoint.com/results/sk/sk105889" target="_self"&gt;sk105889&lt;/A&gt;&amp;nbsp;though it doesn't list the command to disable it&amp;nbsp;(e.g. &lt;STRONG&gt;&lt;FONT face="courier new,courier"&gt;p&lt;/FONT&gt;&lt;FONT face="courier new,courier"&gt;dp conciliation idc_multiple_users disable&lt;/FONT&gt;&lt;/STRONG&gt;), which is what you need to do here to get the behavior you desire.&lt;BR /&gt;I assume pdp c&lt;/P&gt;</description>
      <pubDate>Wed, 03 Sep 2025 15:40:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Multiple-Users-in-Source-User-Name/m-p/256518#M50237</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-09-03T15:40:15Z</dc:date>
    </item>
  </channel>
</rss>

