<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness captive portal and identity conciliation in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-captive-portal-and-identity-conciliation/m-p/246570#M41197</link>
    <description>&lt;P&gt;I may try this setting, but it looks like these commands allow for multiple user identities from the same acquisition method be allowed. My particular case is that identity is acquired via Identity Collector, then&amp;nbsp;&lt;STRONG&gt;simply opening Identity Awareness captive portal page&lt;/STRONG&gt; deletes the identity acquired via the IC.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
    <pubDate>Tue, 15 Apr 2025 18:34:39 GMT</pubDate>
    <dc:creator>David_C1</dc:creator>
    <dc:date>2025-04-15T18:34:39Z</dc:date>
    <item>
      <title>Identity Awareness captive portal and identity conciliation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-captive-portal-and-identity-conciliation/m-p/246545#M41190</link>
      <description>&lt;P&gt;As described in sk183074, simply connected to the Identity Awareness captive portal from a host immediately overwrites any existing identity sessions on the host. Can someone explain the logic for this behavior to me? I don't necessary want the technical reason why this happens, but what are the security or functional reasons that this behavior was implemented? Does this not prevent any type of identity conciliation if merely connecting to a portal kills the existing session?&amp;nbsp; Am I missing something?&lt;/P&gt;
&lt;P&gt;FWIW, this is one of a number of reasons why we can't get rid of old school client authentication...&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 15:47:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-captive-portal-and-identity-conciliation/m-p/246545#M41190</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2025-04-15T15:47:41Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness captive portal and identity conciliation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-captive-portal-and-identity-conciliation/m-p/246562#M41194</link>
      <description>&lt;P&gt;It sounds like you need to enable the option to allow multiple users to connect from the same IP.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk105889" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk105889&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 17:15:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-captive-portal-and-identity-conciliation/m-p/246562#M41194</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-04-15T17:15:48Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness captive portal and identity conciliation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-captive-portal-and-identity-conciliation/m-p/246570#M41197</link>
      <description>&lt;P&gt;I may try this setting, but it looks like these commands allow for multiple user identities from the same acquisition method be allowed. My particular case is that identity is acquired via Identity Collector, then&amp;nbsp;&lt;STRONG&gt;simply opening Identity Awareness captive portal page&lt;/STRONG&gt; deletes the identity acquired via the IC.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 18:34:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-captive-portal-and-identity-conciliation/m-p/246570#M41197</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2025-04-15T18:34:39Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness captive portal and identity conciliation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-captive-portal-and-identity-conciliation/m-p/246580#M41200</link>
      <description>&lt;P&gt;Hi David,&lt;/P&gt;
&lt;P&gt;The reason is the design in Identity Awareness side.&lt;/P&gt;
&lt;P&gt;Once the gateway opens/redirects the browser to the captive portal, the PDP is "waiting" for the end user's input for credentials. Once this flow is triggered, we are clearing the current session saved for this IP, and creates a placeholder for the new credentials to be received. It means, even if the user will not enter credentials in the portal, the fact that this client IP initiate a traffic to the portal, clears the existing session.&lt;/P&gt;
&lt;P&gt;I will add and say, that in case you have configured an automatic redirection to the portal, this redirection will happen only if the PDP doesn't have any information for the end user IP.&lt;/P&gt;
&lt;P&gt;I hope it helps.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 18:50:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-captive-portal-and-identity-conciliation/m-p/246580#M41200</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2025-04-15T18:50:12Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness captive portal and identity conciliation</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-captive-portal-and-identity-conciliation/m-p/246581#M41201</link>
      <description>&lt;P&gt;That does help, though in my case it is not a redirect, but a manual action by the user to open the portal page. We are trying to implement this as a "step-up" authentication, allowing access to sensitive systems only when needed. And like I mentioned, the automatic clearing of the current session prevents any sort of identity conciliation. It certainly could also be disruptive to a user's work if they accidentally open the portal and suddenly any access granted via their current identity session is dropped. It would be beneficial to allow the customer to decide if/how this happens.&lt;/P&gt;
&lt;P&gt;It looks like client authentication will be sticking around in our environment for the time being.&lt;/P&gt;
&lt;P&gt;Dave&lt;/P&gt;</description>
      <pubDate>Tue, 15 Apr 2025 19:16:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-captive-portal-and-identity-conciliation/m-p/246581#M41201</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2025-04-15T19:16:28Z</dc:date>
    </item>
  </channel>
</rss>

