<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Device or Identity based rules for non-AD devices/users in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Device-or-Identity-based-rules-for-non-AD-devices-users/m-p/201409#M33570</link>
    <description>&lt;P&gt;As long as the gateway can resolve the DNS names, that's one option.&lt;/P&gt;</description>
    <pubDate>Fri, 22 Dec 2023 23:30:01 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-12-22T23:30:01Z</dc:date>
    <item>
      <title>Device or Identity based rules for non-AD devices/users</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Device-or-Identity-based-rules-for-non-AD-devices-users/m-p/200342#M33446</link>
      <description>&lt;P&gt;Hello!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have a customer who is extensively using Identitiy based Policies for its users and now faces a challenge that I don't see a good solution for (yet):&lt;/P&gt;&lt;P&gt;They have a bunch of users with devices (Ipdas/IOS) that have no connection to the AD, but still need their own set of rules in the policy.&lt;/P&gt;&lt;P&gt;First I suggested to assign them a specific subnet, but it seems that is not possible, as they have to use a WiFi SSID which is shared with other users and devices.&lt;BR /&gt;Having them authenticate with machine certs is also no option here according to the customer.&lt;BR /&gt;Now the only option that comes to my mind would be the usercheck page where they can log in to get access. This should work with local (=non-AD users), right?&lt;BR /&gt;Would there be any other option I just missed? Something more transparent for the user maybe? Some other way to have them authenticate with a local account that I do not think of yet?&lt;/P&gt;&lt;P&gt;Any input on this would be great!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Cheers,&lt;BR /&gt;Alex&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 15:10:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Device-or-Identity-based-rules-for-non-AD-devices-users/m-p/200342#M33446</guid>
      <dc:creator>Kryten</dc:creator>
      <dc:date>2023-12-12T15:10:22Z</dc:date>
    </item>
    <item>
      <title>Re: Device or Identity based rules for non-AD devices/users</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Device-or-Identity-based-rules-for-non-AD-devices-users/m-p/200346#M33448</link>
      <description>&lt;P&gt;Does the WiFi authenticate users against something like Cisco ISE or Aruba Clearpass or is it much simpler?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Dec 2023 15:29:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Device-or-Identity-based-rules-for-non-AD-devices-users/m-p/200346#M33448</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-12-12T15:29:19Z</dc:date>
    </item>
    <item>
      <title>Re: Device or Identity based rules for non-AD devices/users</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Device-or-Identity-based-rules-for-non-AD-devices-users/m-p/201269#M33556</link>
      <description>&lt;P&gt;Sadly not...the only thing they authenticate against is and MDM running on VMWare (workspace one I guess). I am not sure if it is possible to get usable accounting data from that...&lt;/P&gt;&lt;P&gt;Another idea just came up though: When they get their IP assigned from DHCP, DNS entries are created for the internal domain. Would it be possible to create domain objects for these DNS names and use them as source in the rulebase?&lt;/P&gt;</description>
      <pubDate>Thu, 21 Dec 2023 10:30:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Device-or-Identity-based-rules-for-non-AD-devices-users/m-p/201269#M33556</guid>
      <dc:creator>Kryten</dc:creator>
      <dc:date>2023-12-21T10:30:17Z</dc:date>
    </item>
    <item>
      <title>Re: Device or Identity based rules for non-AD devices/users</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Device-or-Identity-based-rules-for-non-AD-devices-users/m-p/201409#M33570</link>
      <description>&lt;P&gt;As long as the gateway can resolve the DNS names, that's one option.&lt;/P&gt;</description>
      <pubDate>Fri, 22 Dec 2023 23:30:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Device-or-Identity-based-rules-for-non-AD-devices-users/m-p/201409#M33570</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-22T23:30:01Z</dc:date>
    </item>
  </channel>
</rss>

