<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Microsoft DirectAccess, Proxy &amp; Identity Awareness in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Microsoft-DirectAccess-Proxy-Identity-Awareness/m-p/31837#M6679</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are using Microsoft DirectAccess and we are trying to implement CheckPoint Proxy with HTTPS Inspection. We have managed to get Proxy &amp;amp; URL Filtering working via DirectAccess, however the logs do not show the originating computer/user, it just shows the VPN Server as the source.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is obviously a problem when troubleshooting a specific user's problem or when we need to generate reports based on usage etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 Feb 2018 10:41:56 GMT</pubDate>
    <dc:creator>Matt_Parfitt</dc:creator>
    <dc:date>2018-02-23T10:41:56Z</dc:date>
    <item>
      <title>Microsoft DirectAccess, Proxy &amp; Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Microsoft-DirectAccess-Proxy-Identity-Awareness/m-p/31837#M6679</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are using Microsoft DirectAccess and we are trying to implement CheckPoint Proxy with HTTPS Inspection. We have managed to get Proxy &amp;amp; URL Filtering working via DirectAccess, however the logs do not show the originating computer/user, it just shows the VPN Server as the source.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is obviously a problem when troubleshooting a specific user's problem or when we need to generate reports based on usage etc.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Does anyone have any ideas?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Feb 2018 10:41:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Microsoft-DirectAccess-Proxy-Identity-Awareness/m-p/31837#M6679</guid>
      <dc:creator>Matt_Parfitt</dc:creator>
      <dc:date>2018-02-23T10:41:56Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft DirectAccess, Proxy &amp; Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Microsoft-DirectAccess-Proxy-Identity-Awareness/m-p/31838#M6680</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you enabled this option, by chance?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63312_pastedImage_1.png" style="width: 620px; height: 193px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Feb 2018 18:54:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Microsoft-DirectAccess-Proxy-Identity-Awareness/m-p/31838#M6680</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-02-23T18:54:48Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft DirectAccess, Proxy &amp; Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Microsoft-DirectAccess-Proxy-Identity-Awareness/m-p/31839#M6681</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have the first two checkboxes enabled on that Proxy Settings page.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Feb 2018 08:58:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Microsoft-DirectAccess-Proxy-Identity-Awareness/m-p/31839#M6681</guid>
      <dc:creator>Matt_Parfitt</dc:creator>
      <dc:date>2018-02-26T08:58:22Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft DirectAccess, Proxy &amp; Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Microsoft-DirectAccess-Proxy-Identity-Awareness/m-p/31840#M6682</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately, you won't be able to identify your users when they are connected behind a Direct Access server. Indeed, the remote machines IP address is NATed by the DA server. As Checkpoint Identity Awareness maps a user to an IP address it won't work. Moreover, installing an IA agent doesn't help, as it cannot work through a DA server.&lt;/P&gt;&lt;P&gt;The only solution is to do NTLM/Kerberos authentication with an web proxy. This way, the user identity is carried by the browser request and not impacted by the IP address translation, allowing the proxy to identity the users.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 26 Feb 2018 15:07:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Microsoft-DirectAccess-Proxy-Identity-Awareness/m-p/31840#M6682</guid>
      <dc:creator>David_GOURANTON</dc:creator>
      <dc:date>2018-02-26T15:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: Microsoft DirectAccess, Proxy &amp; Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Microsoft-DirectAccess-Proxy-Identity-Awareness/m-p/31841#M6683</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks David. That sounds like a viable solution, is it possible to only apply the browser request on computers that are accessing the Internet via DirectAccess?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Feb 2018 09:10:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Microsoft-DirectAccess-Proxy-Identity-Awareness/m-p/31841#M6683</guid>
      <dc:creator>Matt_Parfitt</dc:creator>
      <dc:date>2018-02-27T09:10:51Z</dc:date>
    </item>
  </channel>
</rss>

