<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness for dynamic environments in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36936#M7771</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From what I understand it subscribes to more logs than that. Let me confirm&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 22 Mar 2018 16:31:28 GMT</pubDate>
    <dc:creator>Kaspars_Zibarts</dc:creator>
    <dc:date>2018-03-22T16:31:28Z</dc:date>
    <item>
      <title>Identity Awareness for dynamic environments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36931#M7766</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi, all.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I was taking a look at the Identity Awareness documentation looking for answers to possible questions on this subject and I couldn't find anything on this:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;What happens to user-to-ip mapping when a user logs in to their laptop using a wired connection but then disconnects from it and stays connected only to wifi? Since the user hasn't logged out and logged in again, I believe AD Query won't be useful. Does Check Point have something like "client probing" or any other identity acquisition method for this kind of scenario?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 18:51:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36931#M7766</guid>
      <dc:creator>Carlos_Machado1</dc:creator>
      <dc:date>2018-03-21T18:51:56Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness for dynamic environments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36932#M7767</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Aside login events, the next events are read as well, so if SSO is in use AD query still might be useful:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P style="margin-bottom: 12.0pt;"&gt;&lt;SPAN style="font-size: 11.0pt; color: black;"&gt;4768: A Kerberos authentication ticket (TGT) was requested.&lt;BR /&gt; *4769: A Kerberos service ticket was requested.&lt;BR /&gt; *4770: A Kerberos service ticket was renewed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="margin-bottom: 12.0pt;"&gt;&lt;SPAN style="font-size: 11.0pt; color: black;"&gt;You may also consider to add Captive Portal to major allow rules&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 20:05:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36932#M7767</guid>
      <dc:creator>Mark_Gurevich</dc:creator>
      <dc:date>2018-03-21T20:05:57Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness for dynamic environments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36933#M7768</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are not using AD query but identity collector (IDC) instead. Much more efficient solution for larger scale. No issues with users jumping between WiFi and LAN. IDC subscribes to AD logs and gets updated, not instantly but fairly quickly.&lt;/P&gt;&lt;P&gt;One down side is that you can have only one username per IP with IDC. I know r&amp;amp;d are working on allowing more but not too sure when it's coming out.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 21 Mar 2018 20:36:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36933#M7768</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-03-21T20:36:04Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness for dynamic environments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36934#M7769</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Kaspars,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Which build of IDC you've got installed?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 09:19:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36934#M7769</guid>
      <dc:creator>Mark_Gurevich</dc:creator>
      <dc:date>2018-03-22T09:19:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness for dynamic environments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36935#M7770</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for your reply, Kaspars.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But if the IDC is subscribing to the AD logs, wouldn't it still need to "wait" for a session log out and session re-log in in order to map the user to their new ip? I mean, if the user jumps from LAN to wifi without re-logging in, there won't be a security log to read the new information from, right?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 13:43:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36935#M7770</guid>
      <dc:creator>Carlos_Machado1</dc:creator>
      <dc:date>2018-03-22T13:43:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness for dynamic environments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36936#M7771</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;From what I understand it subscribes to more logs than that. Let me confirm&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 16:31:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36936#M7771</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-03-22T16:31:28Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness for dynamic environments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36937#M7772</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Identity Agent (loaded on Client IP) will provide the quickest update to user/IP association.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 22 Mar 2018 18:14:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36937#M7772</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-03-22T18:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness for dynamic environments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36938#M7773</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I believe it's this one (4769: A Kerberos service ticket was requested) but let me check next week when I'm in a position to confirm both firewall and DC logs&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2018 07:53:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36938#M7773</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-03-23T07:53:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness for dynamic environments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36939#M7774</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Now we're talking. Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Mar 2018 16:10:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36939#M7774</guid>
      <dc:creator>Carlos_Machado1</dc:creator>
      <dc:date>2018-03-23T16:10:41Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness for dynamic environments</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36940#M7775</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Here you go, confirmed. When I unplugged network cable:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;[ 137060 137000]@xxxxxxxxx[27 Mar 12:47:01] &amp;nbsp;[GatheringManager (TD::Important)] NAC::IDCOLLECTOR::GatheringManager::processEvent: processEvent process EventRecordID: 3542097560 &lt;SPAN style="text-decoration: underline;"&gt;&lt;STRONG style="color: #ff0000; text-decoration: underline;"&gt;; EventID 4769&lt;/STRONG&gt;&lt;/SPAN&gt;, entity: , machine: xxxxxxx, IP: xxxxxxxxx, domain: xxxxxxxx.com&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;According to my sources:&amp;nbsp;&lt;EM&gt;Usually other applications (e.g. Outlook) cause background authentication to the user with the new IP after this roaming&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 27 Mar 2018 11:00:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-for-dynamic-environments/m-p/36940#M7775</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-03-27T11:00:32Z</dc:date>
    </item>
  </channel>
</rss>

