<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Is it possible to create an alert when the MAC address associated to an AD user changes? in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-create-an-alert-when-the-MAC-address/m-p/200698#M4263</link>
    <description>&lt;P&gt;Greetings everyone!&lt;BR /&gt;&lt;BR /&gt;I want to know if it is possible to get a notification when the MAC address associated to an AD user changes. We're dealing with R81.10 with Remote Access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Identity-awareness-Access-role-based-on-MAC-address/td-p/7725" target="_blank"&gt;https://community.checkpoint.com/t5/Management/Identity-awareness-Access-role-based-on-MAC-address/td-p/7725&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the conversation above&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;mentions that L2 header gets stripped off by the time the packet reaches the INSPECT engine. However, in the same conversation there is a mention of an RFE for an External Tag. I tried to google about this, but to no avail so far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought about a script that will read pep and pdp logs and make a notification when MAC of a user changes, but it looks like it would be quite resource heavy as our network activity is very high. On the other hand, I'm completely open to using 3rd party resources to gather that kind of information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 15 Dec 2023 08:53:42 GMT</pubDate>
    <dc:creator>kamilazat</dc:creator>
    <dc:date>2023-12-15T08:53:42Z</dc:date>
    <item>
      <title>Is it possible to create an alert when the MAC address associated to an AD user changes?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-create-an-alert-when-the-MAC-address/m-p/200698#M4263</link>
      <description>&lt;P&gt;Greetings everyone!&lt;BR /&gt;&lt;BR /&gt;I want to know if it is possible to get a notification when the MAC address associated to an AD user changes. We're dealing with R81.10 with Remote Access.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Management/Identity-awareness-Access-role-based-on-MAC-address/td-p/7725" target="_blank"&gt;https://community.checkpoint.com/t5/Management/Identity-awareness-Access-role-based-on-MAC-address/td-p/7725&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In the conversation above&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/597"&gt;@Timothy_Hall&lt;/a&gt;&amp;nbsp;mentions that L2 header gets stripped off by the time the packet reaches the INSPECT engine. However, in the same conversation there is a mention of an RFE for an External Tag. I tried to google about this, but to no avail so far.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I thought about a script that will read pep and pdp logs and make a notification when MAC of a user changes, but it looks like it would be quite resource heavy as our network activity is very high. On the other hand, I'm completely open to using 3rd party resources to gather that kind of information.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 08:53:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-create-an-alert-when-the-MAC-address/m-p/200698#M4263</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2023-12-15T08:53:42Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create an alert when the MAC address associated to an AD user changes?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-create-an-alert-when-the-MAC-address/m-p/200761#M4264</link>
      <description>&lt;P&gt;The feature mentioned in the thread is called Identity Tags:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide/Content/Topics-IDAG/Configuring-Identity-Awareness-Using-Identity-Tags-in-Access-Role-Matching.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide/Content/Topics-IDAG/Configuring-Identity-Awareness-Using-Identity-Tags-in-Access-Role-Matching.htm&lt;/A&gt;&lt;BR /&gt;The tags are assigned by Cisco ISE or a SAML provider.&lt;/P&gt;
&lt;P&gt;In any case, Identity Awareness does not track Layer 2 information, at least not in a way that would be easy to query.&lt;BR /&gt;Therefore, you'd have to use an external system (the identity provider itself) to get this information.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 15 Dec 2023 18:30:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-create-an-alert-when-the-MAC-address/m-p/200761#M4264</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-15T18:30:34Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create an alert when the MAC address associated to an AD user changes?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-create-an-alert-when-the-MAC-address/m-p/200818#M4265</link>
      <description>&lt;P&gt;Thank you&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;. It was really helpful clarifying the possibilities within Identity Awareness.&lt;/P&gt;&lt;P&gt;Though I was reading about SmartEvent and started wondering if it can help me in this context. Apparently it can provide a wide variety of information, but I'm not sure if MAC changes of AD users is within its scope.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Edit: I will, of course, resort to Cisco ISE or a SAML if need be. But,&amp;nbsp;I want to be able to solve this without using any service other than CheckPoint if possible.&lt;/P&gt;</description>
      <pubDate>Sun, 17 Dec 2023 09:56:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-create-an-alert-when-the-MAC-address/m-p/200818#M4265</guid>
      <dc:creator>kamilazat</dc:creator>
      <dc:date>2023-12-17T09:56:39Z</dc:date>
    </item>
    <item>
      <title>Re: Is it possible to create an alert when the MAC address associated to an AD user changes?</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-create-an-alert-when-the-MAC-address/m-p/200891#M4266</link>
      <description>&lt;P&gt;We don't use MAC addresses in policy decisions, so there's not really a mechanism designed to track this in the product.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2023 13:35:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Is-it-possible-to-create-an-alert-when-the-MAC-address/m-p/200891#M4266</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-12-18T13:35:09Z</dc:date>
    </item>
  </channel>
</rss>

