<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Collector Users unable to browse to internet in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Users-unable-to-browse-to-internet/m-p/65501#M13374</link>
    <description>Identity Agent has 2 variants: Full and Light. Light requires no admin privileges to install and only provides user identity. Full provides machine identity and packet tagging as well, but needs admin privileges to be installed.&lt;BR /&gt;Usually these are deployed centrally by some form of software management tool or GPO.</description>
    <pubDate>Tue, 22 Oct 2019 06:53:39 GMT</pubDate>
    <dc:creator>Nik_Bloemers</dc:creator>
    <dc:date>2019-10-22T06:53:39Z</dc:date>
    <item>
      <title>Identity Collector Users unable to browse to internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Users-unable-to-browse-to-internet/m-p/65128#M13310</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We successfully implement Identity Collector and working on R80.30. But we encounter an problem, the user is connected thru the WiFi and able to browse the internet but when the user disconnect to WiFi then connect thru LAN cable the user unable to browse the internet. By the way, the network of the WiFi is different to the LAN. Our workaround is login thru captive portal or restart the laptop.&lt;/P&gt;&lt;P&gt;Is there a solution for this issue? Or is this a limitation of the Identity Collector?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Appreciate your answers,&lt;/P&gt;</description>
      <pubDate>Wed, 16 Oct 2019 15:48:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Users-unable-to-browse-to-internet/m-p/65128#M13310</guid>
      <dc:creator>mbsm</dc:creator>
      <dc:date>2019-10-16T15:48:11Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Users unable to browse to internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Users-unable-to-browse-to-internet/m-p/65154#M13319</link>
      <description>This is a limitation. Identity Collector can only see logon events and determine the user/IP combination at that time. So when the client IP changes, there is not way for IC to know about that until something generates a logon security event.&lt;BR /&gt;When fast roaming between wired/wireless is required, the recommended way is to use the identity agent, this will constantly update the user/IP asssociation.&lt;BR /&gt;&lt;BR /&gt;Also, another workaround aside from restarting the laptop would be locking/unlocking it, that should generate an AD login event.</description>
      <pubDate>Thu, 17 Oct 2019 06:11:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Users-unable-to-browse-to-internet/m-p/65154#M13319</guid>
      <dc:creator>Nik_Bloemers</dc:creator>
      <dc:date>2019-10-17T06:11:38Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Users unable to browse to internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Users-unable-to-browse-to-internet/m-p/65250#M13341</link>
      <description>Short of using Identity Agents on user machines, this limitation will apply.</description>
      <pubDate>Thu, 17 Oct 2019 23:46:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Users-unable-to-browse-to-internet/m-p/65250#M13341</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-10-17T23:46:02Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Users unable to browse to internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Users-unable-to-browse-to-internet/m-p/65499#M13373</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Is Admin account required for the Identity Agent implementation or like on the Identity Collector that a domain user can be used?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 06:38:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Users-unable-to-browse-to-internet/m-p/65499#M13373</guid>
      <dc:creator>mbsm</dc:creator>
      <dc:date>2019-10-22T06:38:04Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Users unable to browse to internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Users-unable-to-browse-to-internet/m-p/65501#M13374</link>
      <description>Identity Agent has 2 variants: Full and Light. Light requires no admin privileges to install and only provides user identity. Full provides machine identity and packet tagging as well, but needs admin privileges to be installed.&lt;BR /&gt;Usually these are deployed centrally by some form of software management tool or GPO.</description>
      <pubDate>Tue, 22 Oct 2019 06:53:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Users-unable-to-browse-to-internet/m-p/65501#M13374</guid>
      <dc:creator>Nik_Bloemers</dc:creator>
      <dc:date>2019-10-22T06:53:39Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Users unable to browse to internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Users-unable-to-browse-to-internet/m-p/65546#M13384</link>
      <description>&lt;P&gt;you should enable browser based authentication to avoid this kind of behavior but it require additional configuration steps for make it work&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 09:29:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Users-unable-to-browse-to-internet/m-p/65546#M13384</guid>
      <dc:creator>Marco_Valenti</dc:creator>
      <dc:date>2019-10-22T09:29:39Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Users unable to browse to internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Users-unable-to-browse-to-internet/m-p/65579#M13395</link>
      <description>&lt;P&gt;As others already pointed out then would need the Agent installed.&lt;/P&gt;&lt;P&gt;One thing that is also possibly though waiting for it to happen is if you are using a NAC like Cisco ICE or HPE ClearPass where can use these as a Source for the Identity Collector.&lt;/P&gt;&lt;P&gt;That way as you move from Wired to Wirelss then the NAC has the log entry for you that the Identity Collector can take to update.&lt;/P&gt;&lt;P&gt;Useful if rolling out something like that but obviously probably easier to roll out the Agent if not rolling out the NAC anyway.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Oct 2019 15:29:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Users-unable-to-browse-to-internet/m-p/65579#M13395</guid>
      <dc:creator>mdjmcnally</dc:creator>
      <dc:date>2019-10-22T15:29:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector Users unable to browse to internet</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Users-unable-to-browse-to-internet/m-p/66210#M13553</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;&lt;P&gt;I appreciate your reply on this issue, and we already raise this to TAC.&lt;/P&gt;&lt;P&gt;But unfortunately, as we try to replicate the issue the users was still able to access the internet. We are still investigating&amp;nbsp; for the possible cause of this scenario. As checked on the logs for Identity Collector Server located on the C:\Windows\Temp\ia_ag.log, the Wireless IP of the User was changed to Wire IP which could indicate that the AD capture the change of the user's IP.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 30 Oct 2019 09:03:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-Users-unable-to-browse-to-internet/m-p/66210#M13553</guid>
      <dc:creator>mbsm</dc:creator>
      <dc:date>2019-10-30T09:03:19Z</dc:date>
    </item>
  </channel>
</rss>

