<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness not matching users behind proxy in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26528#M5416</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can't you just add the custom services?&lt;/P&gt;&lt;P&gt;Or are you saying that doesn't appear to work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70797_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 21 Sep 2018 14:37:05 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-09-21T14:37:05Z</dc:date>
    <item>
      <title>Identity Awareness not matching users behind proxy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26518#M5406</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We configured security policy layers to detect users behind proxies:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70227_policy_layer.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Some systems use an explicit caching Squid proxy which is configured to send requests to the Check Point security gateway's proxy interface:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 12px; font-family: 'courier new', courier, monospace;"&gt;acl local-servers dst 10.0.0.0/8 100.64.0.0/10 172.16.0.0/12 192.168.0.0/16&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;SPAN style="font-size: 12px; font-family: 'courier new', courier, monospace;"&gt;always_direct allow local-servers&lt;BR /&gt;always_direct deny all&lt;BR /&gt;never_direct deny local-servers&lt;BR /&gt;never_direct allow all&lt;BR /&gt;cache_peer 100.127.254.1 parent 3128 0 no-query no-digest&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Check Point security gateway is configured accordingly:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;IMG alt="" class="image-2 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70228_cp_proxy.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Users can only browse when we allow unauthenticated access from the Squid proxy's IP address. We temporarily changed the workstation to explicitly use the Check Point security gateway's proxy interface, navigated to &lt;A href="https://fwcp1.lair.co.za/connect"&gt;https://fwcp1.lair.co.za/connect&lt;/A&gt;,&amp;nbsp; authenticated and thereafter changed the proxy settings back to using Squid. Reviewing log entries shows the security gateway correctly identifying the IP of the workstation behind the Squid proxy but the IP is not associated with the authenticated user for that IP:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-3 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70229_log_record.jpg" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2018 21:25:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26518#M5406</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2018-09-12T21:25:04Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not matching users behind proxy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26519#M5407</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my experience using caching proxies these days causes more issues than it solves. Website contents have become so dynamic that caching website contents brings you much less than in the early days of the internet with static websites.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2018 22:37:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26519#M5407</guid>
      <dc:creator>Danny</dc:creator>
      <dc:date>2018-09-12T22:37:27Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not matching users behind proxy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26520#M5408</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you enable XFF on the gateway as well?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG src="https://sc1.checkpoint.com/sc/SolutionsStatics/sk86441/XFF1707310505.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 12 Sep 2018 22:38:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26520#M5408</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-12T22:38:18Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not matching users behind proxy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26521#M5409</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;It is indeed:&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-2 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70244_pastedImage_2.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;network group object:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70243_proxy_network_group.jpg" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2018 07:09:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26521#M5409</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2018-09-13T07:09:40Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not matching users behind proxy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26522#M5410</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are based in South Africa and subsequently suffer from 160ms latency to Europe and 270ms latency to the USA. Using caching proxies when deploying Linux systems massively reduces deployment times so we wish to continue using them.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;PS: User LAN and WiFi traffic wouldn't be channeled through the caching proxies, which in turn direct their requests via the security gateway's proxy.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2018 07:13:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26522#M5410</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2018-09-13T07:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not matching users behind proxy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26523#M5411</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In my right in understanding that the authentication is occurring only with Captive Portal and not with, say, Identity Collector or ADQuery?&lt;/P&gt;&lt;P&gt;I'd also check with a tcpdump the proxy is actually sending the XFF header.&lt;/P&gt;&lt;P&gt;I suspect a TAC case is probably in order also.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2018 16:43:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26523#M5411</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-13T16:43:37Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not matching users behind proxy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26524#M5412</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Correct, we run Samba AD and still need to write our own ADQuery 'equivalent' to feed authentication events to Identity Awareness using the Identity Web API. We were however pleasantly surprised to discover that captive portal and Kerberos authentication events survive policy installs, unlike AD Query Identity Awareness association events on classic Windows AD environments.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;XFF is definitely working, as evident on the sample log entry in the original post where the record contains 'Proxied Source IP 192.168.5.12'.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll log a case with TAC, wanted to make sure I wasn't missing something first...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2018 22:14:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26524#M5412</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2018-09-13T22:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not matching users behind proxy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26525#M5413</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Wonder if you can hook up Samba to RADIUS Accounting?&lt;/P&gt;&lt;P&gt;I know you can hook up Samba to a RADIUS server for VPN authentication:&amp;nbsp;&lt;A class="link-titled" href="https://wiki.samba.org/index.php/VPN_Single_SignOn_with_Samba_AD" title="https://wiki.samba.org/index.php/VPN_Single_SignOn_with_Samba_AD"&gt;VPN Single SignOn with Samba AD - SambaWiki&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Not sure if that's easier than writing an IDA API connector, but another avenue to consider.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 13 Sep 2018 23:44:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26525#M5413</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-13T23:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not matching users behind proxy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26526#M5414</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We actually already use FreeRADIUS to authenticate support staff to AD using security group memberships, to return relevant authorisation tokens.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Samba 4.7 and later supports Security Event logging natively (&lt;A class="link-titled" href="https://wiki.samba.org/index.php/Setting_up_Audit_Logging" title="https://wiki.samba.org/index.php/Setting_up_Audit_Logging"&gt;Setting up Audit Logging - SambaWiki&lt;/A&gt;), so we could drop our custom patches to send logon/logoff time summaries to the HR department. Legacy laws in South Africa require archaic sign in/out records for the government's worker compensation fund, with hefty penalties on non-compliance...&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Anyway, debugging ADQuery a while back showed me how the Security Event logs are processed by SQL-esque queries, so I believe I can write a fairly simple event log Samba event log processor. Just need to investigate whether or not Web API Identity Awareness associations are cleared at policy install, the way ADQuery associations are. If not a boot script could tell the processor to search back for the last hour's events, the same way ADQuery does.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is getting really off topic but I see great value in implementing &lt;SPAN style="color: #58585a;"&gt;WPA2-Enterprise&lt;/SPAN&gt;&amp;nbsp;(802.1x) for AD based WiFi authentication using RADIUS, which could then inform Identity Awareness when users connect to WiFi networks instead of replying on captive portal authentication every day.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Time, time, time...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Sep 2018 04:16:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26526#M5414</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2018-09-14T04:16:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not matching users behind proxy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26527#M5415</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We had another problem whereby application policies were not granting accessing to users when directing traffic via the security gateway proxy service, whilst they worked perfectly when sending requests directly. This most probably has to do with pre-defined applications being set with fixed port associations:&lt;/P&gt;&lt;P style="padding-left: 30px;"&gt;&lt;IMG __jive_id="70793" alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70793_teamviewer.jpg" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'll log a feature request for HTTP_proxy and HTTPS_proxy service ports to track the security gateway's custom proxy port setting.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;XFF unfortunately still doesn't work when we leave the Check Point security gateway on the default 8080 port assignment and update Squid to forward requests there.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2018 11:23:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26527#M5415</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2018-09-21T11:23:35Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not matching users behind proxy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26528#M5416</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Can't you just add the custom services?&lt;/P&gt;&lt;P&gt;Or are you saying that doesn't appear to work?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70797_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2018 14:37:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26528#M5416</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-21T14:37:05Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not matching users behind proxy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26529#M5417</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;This is locked down by the global policy on the MDS environment. I could clone the policy, change the proxy port and assign it to the relevant domain but it may be preferable to have the proxy port automatically track the associated security gateway's proxy port setting:&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/70808_app_control.jpg" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2018 15:25:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26529#M5417</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2018-09-21T15:25:02Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness not matching users behind proxy</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26530#M5418</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tracking the gateways explicit proxy port would definitely be an RFE.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 21 Sep 2018 15:42:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-not-matching-users-behind-proxy/m-p/26530#M5418</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-09-21T15:42:08Z</dc:date>
    </item>
  </channel>
</rss>

