<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Agent - disable exiting for existing agents in AI Network Firewall</title>
    <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Identity-Agent-disable-exiting-for-existing-agents/m-p/34604#M88198</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mark,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll get one open and see what their recommendation is.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;we have our clients running on the latest version, R80.174&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 21 Feb 2019 16:22:58 GMT</pubDate>
    <dc:creator>NorthernNetGuy</dc:creator>
    <dc:date>2019-02-21T16:22:58Z</dc:date>
    <item>
      <title>Identity Agent - disable exiting for existing agents</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Identity-Agent-disable-exiting-for-existing-agents/m-p/34601#M88195</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I've configured the global properties such that nac_agent_disable_quit has been enabled, however agents that are already deployed are able to exit the agent still. New deploys are correctly receiving this setting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What have people done to ensure this setting is changed for agents that are already deployed?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2019 15:16:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Identity-Agent-disable-exiting-for-existing-agents/m-p/34601#M88195</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2019-02-20T15:16:55Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent - disable exiting for existing agents</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Identity-Agent-disable-exiting-for-existing-agents/m-p/34602#M88196</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You've got a good one there. I am thinking that this may be a bug. As I can't find official documentation that suggests that is normal behaviour.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'd get a TAC case raised to investigate further.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Just out of interest are the existing clients running the latest version of the identity agent? Or an older one?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Mark&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2019 22:35:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Identity-Agent-disable-exiting-for-existing-agents/m-p/34602#M88196</guid>
      <dc:creator>Mark_Mitchell</dc:creator>
      <dc:date>2019-02-20T22:35:58Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent - disable exiting for existing agents</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Identity-Agent-disable-exiting-for-existing-agents/m-p/34603#M88197</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This sounds like "as-it-is" as explained in the IA Admin Guide:&lt;/P&gt;&lt;P&gt;You can change settings for Endpoint Identity Agent parameters to control Endpoint Identity Agent behavior. You can change some of the settings in SmartConsole and others using the Endpoint Identity Agent Configuration tool.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In &lt;SPAN&gt;SmartConsole&amp;nbsp;you can comfigure e.g. "Allow user to save password", but for&amp;nbsp;nac_agent_disable_quit you have to use the&amp;nbsp;Endpoint Identity Agent Configuration tool. To&amp;nbsp;configure these settings from Dashboard and deploy it to the users would be a RFE.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Feb 2019 09:28:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Identity-Agent-disable-exiting-for-existing-agents/m-p/34603#M88197</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-02-21T09:28:57Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent - disable exiting for existing agents</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Identity-Agent-disable-exiting-for-existing-agents/m-p/34604#M88198</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Mark,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll get one open and see what their recommendation is.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;we have our clients running on the latest version, R80.174&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Feb 2019 16:22:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Identity-Agent-disable-exiting-for-existing-agents/m-p/34604#M88198</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2019-02-21T16:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent - disable exiting for existing agents</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Identity-Agent-disable-exiting-for-existing-agents/m-p/34605#M88199</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I'm seeing the opposite of what you're saying here.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We can configure the nac_agent_disable_quit in smartconsole dashboard, it's under global properties-&amp;gt;advanced-&amp;gt;identity awareness-&amp;gt;agent. These settings just don't seem to push out to the agents during their authenticated sessions.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I don't see changing this setting as an option in the Endpoint Identity Agent Configuration Tool, and I don't see it stating that it can in the IA admin guide. Could you clarify where this can be done in the tool?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 21 Feb 2019 16:27:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Identity-Agent-disable-exiting-for-existing-agents/m-p/34605#M88199</guid>
      <dc:creator>NorthernNetGuy</dc:creator>
      <dc:date>2019-02-21T16:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent - disable exiting for existing agents</title>
      <link>https://community.checkpoint.com/t5/AI-Network-Firewall/Identity-Agent-disable-exiting-for-existing-agents/m-p/34606#M88200</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Sorry, i&amp;nbsp;did mix things up a bit&amp;nbsp;&lt;img id="smileysad" class="emoticon emoticon-smileysad" src="https://community.checkpoint.com/i/smilies/16x16_smiley-sad.png" alt="Smiley Sad" title="Smiley Sad" /&gt;&amp;nbsp;- you are absolutely right in that this global property should be enforced for all users, so we certainly have a bug here. A workaround may be available by tweaking the Win Registry (see&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk88520&amp;amp;partition=General&amp;amp;product=Identity"&gt;sk88520: Best Practices - &lt;STRONG&gt;Identity&lt;/STRONG&gt; Awareness Large Scale Deployment&lt;/A&gt;&amp;nbsp;for&amp;nbsp;a complete List of Windows Registry Tweaks on Identity Agent Client), but TAC is the right place to report that.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 22 Feb 2019 09:22:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/AI-Network-Firewall/Identity-Agent-disable-exiting-for-existing-agents/m-p/34606#M88200</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-02-22T09:22:20Z</dc:date>
    </item>
  </channel>
</rss>

