<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: identity information from MUH agent does not propogate to all gateways in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/105737#M9963</link>
    <description>&lt;P&gt;OK, update -&amp;nbsp;&lt;/P&gt;&lt;P&gt;I installed latest JHF (take 183) and enabled the '&lt;SPAN&gt;Get identities from other gateways' on FW2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;('share local identities with other gateways' was always ticked on both gateways.)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, it doesn't looks like it helped. I still don't see username in logs from FW2, only on FW1.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a similar problem from the other way around:&lt;/P&gt;&lt;P&gt;Users are establishing VPN connection (SSLVPN) with FW2, however when trying to access resources behind FW1, their user data isn't propogated.&lt;/P&gt;&lt;P&gt;When I tried to enable '&lt;SPAN&gt;Get identities from other gateways' on FW1, it broke the IA mechanism, and no user data was available for TS agent AND PCs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm kinda lost here with how this mechanism works...&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 17 Dec 2020 11:37:58 GMT</pubDate>
    <dc:creator>Jonathan</dc:creator>
    <dc:date>2020-12-17T11:37:58Z</dc:date>
    <item>
      <title>identity information from MUH agent does not propogate to all gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104406#M9949</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;R80.20&lt;/P&gt;&lt;P&gt;Users on PCs and on Termainl Servers sits behind FW1.&lt;/P&gt;&lt;P&gt;Terminal Servers installed with Checkpoint MUH.&lt;/P&gt;&lt;P&gt;FW1 sits behind FW2 which also have IA blade enabled.&lt;/P&gt;&lt;P&gt;Users coming from PCs are correctly identified by both FW (I can see in the log filesthe users under the "Source Username" column).&lt;/P&gt;&lt;P&gt;Users coming from TS are only identified on FW1. In the logs, "Source username" is empty once the packet hits the FW2, and ofcourse firewall rules defined by access_role are not applied.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this expected behaviour? Do I need to enable "Get identites from other gatewys" on FW2? If YES, then why is it working with users on PCs?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 06 Dec 2020 14:11:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104406#M9949</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2020-12-06T14:11:40Z</dc:date>
    </item>
    <item>
      <title>Re: identity information from MUH agent does not propogate to all gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104433#M9950</link>
      <description>&lt;P&gt;Are all the gateways involved R80.20?&lt;BR /&gt;Is NAT involved at all?&lt;/P&gt;</description>
      <pubDate>Sun, 06 Dec 2020 22:58:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104433#M9950</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-06T22:58:47Z</dc:date>
    </item>
    <item>
      <title>Re: identity information from MUH agent does not propogate to all gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104476#M9951</link>
      <description>&lt;P&gt;Yes, all gateways and management server R80.20&lt;/P&gt;&lt;P&gt;One MGMT server for all gateways.&lt;/P&gt;&lt;P&gt;What do you mean if NAT is involved? In what way?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 09:54:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104476#M9951</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2020-12-07T09:54:21Z</dc:date>
    </item>
    <item>
      <title>Re: identity information from MUH agent does not propogate to all gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104547#M9952</link>
      <description>&lt;P&gt;Are there NAT rules configured on one gateway that might impact how the other gateway sees it?&lt;/P&gt;</description>
      <pubDate>Mon, 07 Dec 2020 17:19:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104547#M9952</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-07T17:19:03Z</dc:date>
    </item>
    <item>
      <title>Re: identity information from MUH agent does not propogate to all gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104632#M9953</link>
      <description>&lt;P&gt;I don't know of any such NATs. I double checked and didn't see any.&lt;/P&gt;&lt;P&gt;FW2 is the default gateway for FW1&lt;/P&gt;</description>
      <pubDate>Tue, 08 Dec 2020 08:58:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104632#M9953</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2020-12-08T08:58:08Z</dc:date>
    </item>
    <item>
      <title>Re: identity information from MUH agent does not propogate to all gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104735#M9954</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 09:15:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104735#M9954</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2020-12-09T09:15:35Z</dc:date>
    </item>
    <item>
      <title>Re: identity information from MUH agent does not propogate to all gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104804#M9955</link>
      <description>&lt;P&gt;What version of MUH are you using?&lt;BR /&gt;Note that I highly recommend upgrading to R80.40, which allows for several improvements in MUH (more users on a terminal server and more traffic types are supported).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 16:14:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104804#M9955</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-09T16:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: identity information from MUH agent does not propogate to all gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104831#M9956</link>
      <description>&lt;P&gt;I'll check tomorrow the MUH version.&lt;/P&gt;&lt;P&gt;But since the user is correctly identified by FW1, could it still be connected to the MUH itself?&lt;/P&gt;&lt;P&gt;We will upgrade to 80.40 in the future but not right now...&lt;/P&gt;&lt;P&gt;Looks like some configuration issue with the gateways themselves, no?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 18:39:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104831#M9956</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2020-12-09T18:39:48Z</dc:date>
    </item>
    <item>
      <title>Re: identity information from MUH agent does not propogate to all gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104833#M9957</link>
      <description>&lt;P&gt;The newer versions of MUH operate a bit differently than older versions and sync data incompatible with older gateway versions.&lt;BR /&gt;Not sure if that has been backported to earlier releases or not.&lt;BR /&gt;I strongly recommend a TAC case here.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 19:08:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104833#M9957</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-09T19:08:07Z</dc:date>
    </item>
    <item>
      <title>Re: identity information from MUH agent does not propogate to all gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104835#M9958</link>
      <description>&lt;P&gt;Ok, just verifying again:&amp;nbsp;&lt;/P&gt;&lt;P&gt;'Get identities from other gateways' shouldn't be checked on FW2?&lt;/P&gt;&lt;P&gt;Currently it's not checked, but again, identites from PCs propegate fine to FW2...&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 19:20:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104835#M9958</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2020-12-09T19:20:42Z</dc:date>
    </item>
    <item>
      <title>Re: identity information from MUH agent does not propogate to all gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104840#M9959</link>
      <description>&lt;P&gt;This option definitely needs to be enabled if you’re using any of the agents (MUH or otherwise) since the agent only speaks to one gateway.&lt;BR /&gt;You didn’t say how the gateways are acquiring identities otherwise.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Dec 2020 20:37:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104840#M9959</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-09T20:37:36Z</dc:date>
    </item>
    <item>
      <title>Re: identity information from MUH agent does not propogate to all gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104897#M9960</link>
      <description>&lt;P&gt;We only use agents on our terminal servers. Users using their own PCs don't have agents installed.&lt;/P&gt;&lt;P&gt;So maybe I'm making a salad here, but I need to understand the flow here -&amp;nbsp;&lt;/P&gt;&lt;P&gt;User1 on a PC, sits behind FW1, and want to reach a resource behind FW2.&lt;/P&gt;&lt;P&gt;First point of contact is with FW1, so Identity awareness data is collected there.&lt;/P&gt;&lt;P&gt;request from PC is now routed forward to FW2 since it's the DG of FW1.&lt;/P&gt;&lt;P&gt;Isn't identity data also transfered from FW1 to FW2 or does FW2 aquires it's own Identity data independently from the user's PC?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also, any negative impact if I enable the 'Get identity data from other gateways' online?&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 05:53:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104897#M9960</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2020-12-10T05:53:44Z</dc:date>
    </item>
    <item>
      <title>Re: identity information from MUH agent does not propogate to all gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104898#M9961</link>
      <description>&lt;P&gt;You still haven't answered the question: how is Identity Awareness to 'acquire' the identity.&lt;BR /&gt;If it's AD Query and you've configured both firewalls to acquire them from the same set of AD servers, then both gateways will find out about the same logins done to those servers.&lt;BR /&gt;However, this only works for single user hosts.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;For terminal servers, MUH must be used as multiple users are coming from the same IP and MUH helps differentiate between the users.&lt;BR /&gt;However, MUH (or any of the agents) can only talk to one gateway.&lt;BR /&gt;If the gateway isn't sharing identities, no other gateway will find out about that identity.&lt;/P&gt;
&lt;P&gt;So, yes, you have to share identities between gateways to make this work.&lt;BR /&gt;It does not add a lot of overhead as it is a demand-driven process.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a larger issue, you should configure each firewall to acquire identities from the closest AD server (not necessarily the same ones).&lt;BR /&gt;You may also want to move to Identity Collector, which scales better than AD Query.&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 06:06:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104898#M9961</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-10T06:06:56Z</dc:date>
    </item>
    <item>
      <title>Re: identity information from MUH agent does not propogate to all gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104915#M9962</link>
      <description>&lt;P&gt;Sorry for that - Yes, it's AD Query and both FW are configured with the same AD server.&lt;/P&gt;&lt;P&gt;Thanks for calrifying things. I'll check that box later on and give an update here if that solved the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Dec 2020 07:35:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/104915#M9962</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2020-12-10T07:35:05Z</dc:date>
    </item>
    <item>
      <title>Re: identity information from MUH agent does not propogate to all gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/105737#M9963</link>
      <description>&lt;P&gt;OK, update -&amp;nbsp;&lt;/P&gt;&lt;P&gt;I installed latest JHF (take 183) and enabled the '&lt;SPAN&gt;Get identities from other gateways' on FW2.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;('share local identities with other gateways' was always ticked on both gateways.)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;However, it doesn't looks like it helped. I still don't see username in logs from FW2, only on FW1.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a similar problem from the other way around:&lt;/P&gt;&lt;P&gt;Users are establishing VPN connection (SSLVPN) with FW2, however when trying to access resources behind FW1, their user data isn't propogated.&lt;/P&gt;&lt;P&gt;When I tried to enable '&lt;SPAN&gt;Get identities from other gateways' on FW1, it broke the IA mechanism, and no user data was available for TS agent AND PCs.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I'm kinda lost here with how this mechanism works...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 11:37:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/105737#M9963</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2020-12-17T11:37:58Z</dc:date>
    </item>
    <item>
      <title>Re: identity information from MUH agent does not propogate to all gateways</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/105766#M9964</link>
      <description>&lt;P&gt;Recommend a TAC case here to do further troubleshooting.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2020 17:20:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-information-from-MUH-agent-does-not-propogate-to-all/m-p/105766#M9964</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-17T17:20:37Z</dc:date>
    </item>
  </channel>
</rss>

