<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Why user &amp;quot;localhost&amp;quot; install policies on the FW? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Why-user-quot-localhost-quot-install-policies-on-the-FW/m-p/234000#M39101</link>
    <description>&lt;P&gt;Just by pure logic, I would say thats not an actual user and here is why. So, if you think about it, ANY computer in the world can technically be "localhost" and we all know what IP is 127.0.0.1. I think&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;even has shirt about it lol&lt;/P&gt;
&lt;P&gt;Anyway, Im fairly positive this is simply default. system log, or, as you described it, normal in this instance. As Phoneboy had said, desktop policy is related to remote access clients.&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 28 Nov 2024 00:49:59 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-11-28T00:49:59Z</dc:date>
    <item>
      <title>Why user "localhost" install policies on the FW?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Why-user-quot-localhost-quot-install-policies-on-the-FW/m-p/233997#M39098</link>
      <description>&lt;P&gt;Hi, Folks.&lt;/P&gt;&lt;P&gt;Do you know why the user "localhost" is installing policies on the firewall? Recently, i identified on the FW logs this activity,&amp;nbsp;I leave a sample of the log:&lt;/P&gt;&lt;P&gt;"Nov 11 12:09:50 x.x.x.x 1 2024-11-11T15:09:48Z FW - [action:"Accept"; flags:"xxx"; ifdir:"outbound"; loguid:"{xxx}"; origin:"x.x.x.x"; originsicname:"xxxx"; sequencenum:"1"; time:"1731337788"; version:"x"; &lt;STRONG&gt;additional_info:"Desktop Policy : policy_name&lt;/STRONG&gt;"; &lt;STRONG&gt;administrator:"localhost"&lt;/STRONG&gt;; audit_status:"Success"; &lt;STRONG&gt;client_ip:"127.0.0.1"&lt;/STRONG&gt;; &lt;STRONG&gt;machine:"localhost"&lt;/STRONG&gt;; objectname:"xxxx"; objecttable:"applications"; objecttype:"dtps_application"; &lt;STRONG&gt;operation:"Install Policy"&lt;/STRONG&gt;; operation_number:"7"; product:"SmartConsole"; subject:"Policy Installation"; uid:"{xxxxx}"]"&lt;/P&gt;&lt;P&gt;The policy installed is "Desktop Policy",&amp;nbsp;This activity can be "normal" or as part of policy program updates?&lt;/P&gt;&lt;P&gt;I would greatly appreciate your support.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Victor.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 27 Nov 2024 20:08:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Why-user-quot-localhost-quot-install-policies-on-the-FW/m-p/233997#M39098</guid>
      <dc:creator>VicOropeza420</dc:creator>
      <dc:date>2024-11-27T20:08:27Z</dc:date>
    </item>
    <item>
      <title>Re: Why user "localhost" install policies on the FW?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Why-user-quot-localhost-quot-install-policies-on-the-FW/m-p/233999#M39100</link>
      <description>&lt;P&gt;Desktop Policy is used by Remote Access clients.&lt;BR /&gt;Normally, this is pushed as part of the regular Access Policy.&lt;BR /&gt;Not sure why "localhost" is doing this...might be worth a TAC case.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 00:29:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Why-user-quot-localhost-quot-install-policies-on-the-FW/m-p/233999#M39100</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-28T00:29:21Z</dc:date>
    </item>
    <item>
      <title>Re: Why user "localhost" install policies on the FW?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Why-user-quot-localhost-quot-install-policies-on-the-FW/m-p/234000#M39101</link>
      <description>&lt;P&gt;Just by pure logic, I would say thats not an actual user and here is why. So, if you think about it, ANY computer in the world can technically be "localhost" and we all know what IP is 127.0.0.1. I think&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;even has shirt about it lol&lt;/P&gt;
&lt;P&gt;Anyway, Im fairly positive this is simply default. system log, or, as you described it, normal in this instance. As Phoneboy had said, desktop policy is related to remote access clients.&lt;/P&gt;
&lt;P&gt;Hope that helps.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 28 Nov 2024 00:49:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Why-user-quot-localhost-quot-install-policies-on-the-FW/m-p/234000#M39101</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-28T00:49:59Z</dc:date>
    </item>
  </channel>
</rss>

