<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mobile Access Log In and Log Out in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Log-In-and-Log-Out/m-p/85439#M80165</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if that's the case, it would be nice to understand why it doesn't happen for ALL (look at my post: UserA affected, UserB not affected).&lt;/P&gt;&lt;P&gt;Let's wait the support and I'll give write feedback here.&lt;/P&gt;&lt;P&gt;Thank you,&lt;BR /&gt;Luca&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 15 May 2020 22:19:15 GMT</pubDate>
    <dc:creator>lucafabbri365</dc:creator>
    <dc:date>2020-05-15T22:19:15Z</dc:date>
    <item>
      <title>Mobile Access Log In and Log Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Log-In-and-Log-Out/m-p/85175#M80161</link>
      <description>&lt;P&gt;Hello Community,&lt;BR /&gt;I'm writing to ask for a question regarding Mobile Access login and logout events.&lt;/P&gt;&lt;P&gt;The main objective is to retrieve login and logout events for all VPN client users and the VPN client version. I understand the "logout" event could have multiple reasons: session timeout, manual disconnection (by end-user).&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Environment Description&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;- Check Point R80.20 Take 80 (1 VM Security Managements and 2 physical cluster nodes - Open Server)&lt;BR /&gt;- LDAP authentication&lt;BR /&gt;- VPN client: Check Point Remote Access VPN client (Windows) - product: Check Point Mobile&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="01-Check Point Remote Access.PNG" style="width: 393px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6067i9C0E81E000167639/image-dimensions/393x302?v=v2" width="393" height="302" role="button" title="01-Check Point Remote Access.PNG" alt="01-Check Point Remote Access.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;- Log Generation: per Connection&lt;/P&gt;&lt;P&gt;I started to looking at login events in SmartConsole logs but I found a "strange" behavior for some users, sometimes.&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Example 1&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;- Filter:&amp;nbsp;&lt;STRONG&gt;blade:("Mobile access") AND action:"Log In" and User01&lt;/STRONG&gt;&lt;BR /&gt;- Time range: &lt;STRONG&gt;yesterday (2020-05-14)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;As you can notice by results, there is only one login event related to User01 matching the filter (I removed some parts for privacy - see the attached screenshot &lt;EM&gt;01-User01 login events - SmartConsole Log.png):&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="02-UserA login events - SmartConsole Log.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6068iA4A7E3E778730452/image-size/large?v=v2&amp;amp;px=999" role="button" title="02-UserA login events - SmartConsole Log.PNG" alt="02-UserA login events - SmartConsole Log.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Now the User01 connected to VPN in the afternoon (16:31) but also in the morning (!!!) at 08:35 (+/-), but there is no trace in the log. I tried to modify the filter including the &lt;EM&gt;Identity Awareness&lt;/EM&gt; blade too:&lt;/P&gt;&lt;P&gt;-&amp;nbsp;Filter:&amp;nbsp;&lt;STRONG&gt;blade:("Mobile access" or "Identity Awareness") AND action:"Log In" and User01&lt;/STRONG&gt;&lt;BR /&gt;- Time range: &lt;STRONG&gt;yesterday (2020-05-13)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;This time I get more results (see the attached screenshot &lt;EM&gt;02-User01 login events - SmartConsole Log.png)&lt;/EM&gt;:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="03-UserA login events - SmartConsole Log.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6069i71D18F05358728B8/image-size/large?v=v2&amp;amp;px=999" role="button" title="03-UserA login events - SmartConsole Log.PNG" alt="03-UserA login events - SmartConsole Log.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;The user authenticated at &lt;EM&gt;08:36&lt;/EM&gt; in Active Directory (because connected to VPN).&amp;nbsp;&lt;BR /&gt;If I change the time range for the same user (&lt;STRONG&gt;today - 2020-05-14&lt;/STRONG&gt;) I found expected login entries for &lt;EM&gt;Mobile Access&lt;/EM&gt; blade (see the attached screenshot &lt;EM&gt;03-User01 login events - SmartConsole Log.png)&lt;/EM&gt;:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="03-User01 login events - SmartConsole Log.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6071i3A935A6E3F7DC117/image-size/large?v=v2&amp;amp;px=999" role="button" title="03-User01 login events - SmartConsole Log.PNG" alt="03-User01 login events - SmartConsole Log.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Question: WHY, sometimes, for some users, I have no trace for Mobile Access blade ?&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Example 2&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;If I search for another user User02 (mine) it is working as expected: I notice three entries related to logins: one for blade &lt;EM&gt;Mobile Access&lt;/EM&gt; and the other two for&amp;nbsp;&lt;EM&gt;Identity Awareness&lt;/EM&gt; (see the attached screenshot &lt;EM&gt;04-User02 login events - SmartConsole Log.png):&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;-&amp;nbsp;Filter:&amp;nbsp;&lt;STRONG&gt;blade:("Mobile access" or "Identity Awareness") AND action:"Log In" and User02&lt;/STRONG&gt;&lt;BR /&gt;- Time range: &lt;STRONG&gt;yesterday (2020-05-14)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="03-User02 login events - SmartConsole Log.PNG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6070i5284A308D878F2E5/image-size/large?v=v2&amp;amp;px=999" role="button" title="03-User02 login events - SmartConsole Log.PNG" alt="03-User02 login events - SmartConsole Log.PNG" /&gt;&lt;/span&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Please, can you give me your opinion ?&lt;/P&gt;&lt;P&gt;Thank you,&lt;BR /&gt;Luca&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 08:16:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Log-In-and-Log-Out/m-p/85175#M80161</guid>
      <dc:creator>lucafabbri365</dc:creator>
      <dc:date>2020-05-14T08:16:54Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access Log In and Log Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Log-In-and-Log-Out/m-p/85236#M80162</link>
      <description>&lt;P&gt;This sounds quite similar to:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Logging-and-Reporting/Remote-vpn-login-logs-are-rewrite-after-authentication-timeout/m-p/85003#M4920" target="_blank"&gt;https://community.checkpoint.com/t5/Logging-and-Reporting/Remote-vpn-login-logs-are-rewrite-after-authentication-timeout/m-p/85003#M4920&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;May want to post in that thread and see if the TAC has gotten involved.&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 12:44:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Log-In-and-Log-Out/m-p/85236#M80162</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-05-14T12:44:50Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access Log In and Log Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Log-In-and-Log-Out/m-p/85308#M80163</link>
      <description>&lt;P&gt;Hello Timothy,&lt;BR /&gt;thank you for your answer.&lt;BR /&gt;Yes, it seems to be similar to the other post; I'll write there.&lt;/P&gt;&lt;P&gt;At meanwhile I opened a support ticket.&lt;/P&gt;&lt;P&gt;I just checked the login events (blade:"Mobile Access") for UserA this morning (2020-05-14) and I found an entry at 08:35 (+/-) and re-checked it in the afternoon: it disappeared; maybe overwritten by a new entry at 4:36pm (WHY ?!?).&lt;/P&gt;&lt;P&gt;UserB (mine), for example, is not affected by this behavior; I found two entries, one at 09:09 and the other at 5.45pm and they correspond to login I made through Check Point VPN client.&lt;/P&gt;&lt;P&gt;Bye,&lt;BR /&gt;Luca&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 May 2020 16:55:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Log-In-and-Log-Out/m-p/85308#M80163</guid>
      <dc:creator>lucafabbri365</dc:creator>
      <dc:date>2020-05-14T16:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access Log In and Log Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Log-In-and-Log-Out/m-p/85437#M80164</link>
      <description>Pretty sure this is log consolidation taking place.&lt;BR /&gt;TAC should be able to confirm if this is expected behavior or not.</description>
      <pubDate>Fri, 15 May 2020 21:21:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Log-In-and-Log-Out/m-p/85437#M80164</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-05-15T21:21:33Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access Log In and Log Out</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Log-In-and-Log-Out/m-p/85439#M80165</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;if that's the case, it would be nice to understand why it doesn't happen for ALL (look at my post: UserA affected, UserB not affected).&lt;/P&gt;&lt;P&gt;Let's wait the support and I'll give write feedback here.&lt;/P&gt;&lt;P&gt;Thank you,&lt;BR /&gt;Luca&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 May 2020 22:19:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Mobile-Access-Log-In-and-Log-Out/m-p/85439#M80165</guid>
      <dc:creator>lucafabbri365</dc:creator>
      <dc:date>2020-05-15T22:19:15Z</dc:date>
    </item>
  </channel>
</rss>

