<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Stop clearing ADQuery Identity Awareness during policy installation in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Stop-clearing-ADQuery-Identity-Awareness-during-policy/m-p/18293#M3289</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know, this shouldn't happen.&lt;/P&gt;&lt;P&gt;There's a note in our Best Practice documentation about something that happens during policy installation, namely we re-lookup all the LDAP groups associated with each user the gateway knows about.&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk88520" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk88520"&gt;Best Practices - Identity Awareness Large Scale Deployment&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That couldn't happen if we cleared all the users on policy installation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recommend opening a TAC case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Dec 2018 22:37:57 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-12-21T22:37:57Z</dc:date>
    <item>
      <title>Stop clearing ADQuery Identity Awareness during policy installation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Stop-clearing-ADQuery-Identity-Awareness-during-policy/m-p/18292#M3288</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Installing policy has the effect of clearing known user identity awareness, the primary reason why we advocate only handling this outside of business hours.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;There are however often reasons why customers ask for policy installations during work hours, is there no way for a security gateway not to clear PDP during this process as user's internet access is subsequently inhibited until they restart their browser (initiates Kerberos browser based authentication as the browser handles captive portal detection), switches or cycles connectivity (initiates captive portal detection) or re-login (initiates ADQuery event)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 20 Dec 2018 04:28:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Stop-clearing-ADQuery-Identity-Awareness-during-policy/m-p/18292#M3288</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2018-12-20T04:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: Stop clearing ADQuery Identity Awareness during policy installation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Stop-clearing-ADQuery-Identity-Awareness-during-policy/m-p/18293#M3289</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know, this shouldn't happen.&lt;/P&gt;&lt;P&gt;There's a note in our Best Practice documentation about something that happens during policy installation, namely we re-lookup all the LDAP groups associated with each user the gateway knows about.&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk88520" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk88520"&gt;Best Practices - Identity Awareness Large Scale Deployment&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;That couldn't happen if we cleared all the users on policy installation.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I recommend opening a TAC case.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Dec 2018 22:37:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Stop-clearing-ADQuery-Identity-Awareness-during-policy/m-p/18293#M3289</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-12-21T22:37:57Z</dc:date>
    </item>
  </channel>
</rss>

