<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Identity Agent Revoke IP in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Revoke-IP/m-p/34286#M88239</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have found an issue and its apparent on at least two of our customers firewalls. When the terminal server multi user agent is connected, if we click disconnect from gateway in agent window, or if I run the command "pdp control revoke_ip" the agent will never be able to reconnect. Even after uninstalling the agent, rebooting and reinstalling, the agent will no longer reconnect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any possibility the checkpoint or the windows server has revoked the ssl certificate meaning until I delete that revocation it will never connect?&amp;nbsp;Even after months, the client cannot reconnect so it seems something has permanently blocked this connection (where other clients are still connected without issue) but i can't figure out where this is happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 18 Feb 2019 23:05:13 GMT</pubDate>
    <dc:creator>Ryan_Ryan</dc:creator>
    <dc:date>2019-02-18T23:05:13Z</dc:date>
    <item>
      <title>Identity Agent Revoke IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Revoke-IP/m-p/34286#M88239</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have found an issue and its apparent on at least two of our customers firewalls. When the terminal server multi user agent is connected, if we click disconnect from gateway in agent window, or if I run the command "pdp control revoke_ip" the agent will never be able to reconnect. Even after uninstalling the agent, rebooting and reinstalling, the agent will no longer reconnect.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is there any possibility the checkpoint or the windows server has revoked the ssl certificate meaning until I delete that revocation it will never connect?&amp;nbsp;Even after months, the client cannot reconnect so it seems something has permanently blocked this connection (where other clients are still connected without issue) but i can't figure out where this is happening.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 18 Feb 2019 23:05:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Revoke-IP/m-p/34286#M88239</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2019-02-18T23:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent Revoke IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Revoke-IP/m-p/34287#M88240</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You do not mention the version used - for R77.30,&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;pdp control revoke_ip should not terminate the connection (according to&amp;nbsp;sk122838), but if you&amp;nbsp;try to connect to the web resource again, you should be redirected to the Captive Portal (see&amp;nbsp;Identity Awareness Administration Guide R77 Versions p.79).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;So after disconnect, when trying to connect again the user&amp;nbsp;must authenticate again. I would involve TAC here as this behaviour is&amp;nbsp;not as expected.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2019 08:26:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Revoke-IP/m-p/34287#M88240</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-02-19T08:26:03Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent Revoke IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Revoke-IP/m-p/34288#M88241</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Forgot that! its R77.30.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I also forgot to mention this is the Multi User Host agent. (although it may also be present in the single user agent - have not tried that yet) Anyone else have it installed, feel free to give it a try, if you click disconnect from gateway on the agent, or if you click revoke IP, once the agent then shows disconnected, you will not get it to reconnect, although I did have success on one machine by uninstalling, rebooting and reinstalling, I have had other machines even doing that doesn't fix it.seems once you click that button&amp;nbsp;you are stuck, (repairing connection doesn't work/factory reset settings doesnt work)&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Would be very interested if someone else was able to confirm this behaviour.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 19 Feb 2019 22:02:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Revoke-IP/m-p/34288#M88241</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2019-02-19T22:02:02Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent Revoke IP</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Revoke-IP/m-p/34289#M88242</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I did know that the MUH Agent is used, but i found nothing more even in&amp;nbsp;sk66761. Admin Guide speaks of&amp;nbsp;Configure a shared secret between the Terminal Servers Identity Agents and the gateway. But then, it should just work...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This sounds like a Windows registry issue - sometimes, uninstall fails to clean the registry. sk118612 give it as&amp;nbsp;&lt;EM&gt;HKEY_USERS\S-1-5-18\Software\CheckPoint\IA&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 20 Feb 2019 07:51:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Agent-Revoke-IP/m-p/34289#M88242</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-02-20T07:51:47Z</dc:date>
    </item>
  </channel>
</rss>

