<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Radius accounting identity awarenesss in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Radius-accounting-identity-awarenesss/m-p/105300#M20212</link>
    <description>&lt;P&gt;Because that’s just not how RADIUS Accounting works.&lt;BR /&gt;By the way, our integration with Active Directory &amp;nbsp;(either AD Query or Identity Collector) fundamentally the same way: we “subscribe” to an identity source to find out about what users are associated with what IP addresses.&lt;BR /&gt;The gateway will perform an LDAP query to determine what groups the user is a member of to calculate the appropriate Access Roles for that user.&lt;BR /&gt;This way, at the time the user tries to do something through the gateway, we’ll know precisely what policy applies.&lt;/P&gt;
&lt;P&gt;There isn’t a standards-based mechanism for either RADIUS or Active Directory that I’m aware of that allows anyone to query “what user is associated with this IP.”&lt;BR /&gt;Not to mention; you’d have to hold the connection while the lookup is performed, creating a performance issue for end users.&lt;/P&gt;</description>
    <pubDate>Sun, 13 Dec 2020 21:18:26 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2020-12-13T21:18:26Z</dc:date>
    <item>
      <title>Radius accounting identity awarenesss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Radius-accounting-identity-awarenesss/m-p/105274#M20207</link>
      <description>&lt;P class="Procedure_Heading"&gt;Hello,&lt;/P&gt;&lt;P class="Procedure_Heading"&gt;I have a question about radius accounting :&lt;/P&gt;&lt;P class="Procedure_Heading"&gt;Is it correct ? I understand that Radius accouting client &amp;nbsp;is the gateway which send a request to the radius accounting server to get identities?&lt;/P&gt;&lt;P&gt;But in the documentation they said that " &lt;SPAN class="mc-variable Vars_BladesFeatures.tp_idaware variable"&gt;Identity Awareness&lt;/SPAN&gt; &lt;SPAN class="mc-variable Other_Vars.tp_gwcap variable"&gt;Gateway&lt;/SPAN&gt; configured as a RADIUS Accounting server." why ?&lt;/P&gt;&lt;DIV class="Show_Horizontal_Scrollbar"&gt;&amp;nbsp;&lt;/DIV&gt;</description>
      <pubDate>Sun, 13 Dec 2020 18:09:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Radius-accounting-identity-awarenesss/m-p/105274#M20207</guid>
      <dc:creator>SAROU237</dc:creator>
      <dc:date>2020-12-13T18:09:22Z</dc:date>
    </item>
    <item>
      <title>Re: Radius accounting identity awarenesss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Radius-accounting-identity-awarenesss/m-p/105275#M20208</link>
      <description>&lt;P&gt;Can you quote the precise areas of documentation you’re seeing these two different explanations?&lt;/P&gt;
&lt;P&gt;Generally, the request is initiated from the RADIUS server (not us) to the RADIUS Accounting Server (a properly-configured Check Point gateway).&lt;BR /&gt;This is how RADIUS Accounting works.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Dec 2020 18:20:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Radius-accounting-identity-awarenesss/m-p/105275#M20208</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-13T18:20:33Z</dc:date>
    </item>
    <item>
      <title>Re: Radius accounting identity awarenesss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Radius-accounting-identity-awarenesss/m-p/105299#M20211</link>
      <description>&lt;P&gt;Why does the request is initiated from the radius server ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Because this is the gateway which need the information of a user, so he should make the request to the server. I don't understand&lt;/P&gt;</description>
      <pubDate>Sun, 13 Dec 2020 20:54:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Radius-accounting-identity-awarenesss/m-p/105299#M20211</guid>
      <dc:creator>SAROU237</dc:creator>
      <dc:date>2020-12-13T20:54:45Z</dc:date>
    </item>
    <item>
      <title>Re: Radius accounting identity awarenesss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Radius-accounting-identity-awarenesss/m-p/105300#M20212</link>
      <description>&lt;P&gt;Because that’s just not how RADIUS Accounting works.&lt;BR /&gt;By the way, our integration with Active Directory &amp;nbsp;(either AD Query or Identity Collector) fundamentally the same way: we “subscribe” to an identity source to find out about what users are associated with what IP addresses.&lt;BR /&gt;The gateway will perform an LDAP query to determine what groups the user is a member of to calculate the appropriate Access Roles for that user.&lt;BR /&gt;This way, at the time the user tries to do something through the gateway, we’ll know precisely what policy applies.&lt;/P&gt;
&lt;P&gt;There isn’t a standards-based mechanism for either RADIUS or Active Directory that I’m aware of that allows anyone to query “what user is associated with this IP.”&lt;BR /&gt;Not to mention; you’d have to hold the connection while the lookup is performed, creating a performance issue for end users.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Dec 2020 21:18:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Radius-accounting-identity-awarenesss/m-p/105300#M20212</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-13T21:18:26Z</dc:date>
    </item>
    <item>
      <title>Re: Radius accounting identity awarenesss</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Radius-accounting-identity-awarenesss/m-p/105303#M20214</link>
      <description>&lt;P&gt;If our Captive Portal is being used for web based authentication then Radius might be configured as the authentication server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This is different to Radius accounting where the user has already been authenticated maybe by connecting to a separate Wi-Fi solution and the radius messages are being sent on to Check Point as a means of&amp;nbsp; letting us know who is already logged in with what IP address.&lt;/P&gt;</description>
      <pubDate>Sun, 13 Dec 2020 21:35:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Radius-accounting-identity-awarenesss/m-p/105303#M20214</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2020-12-13T21:35:39Z</dc:date>
    </item>
  </channel>
</rss>

