<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: VPN User and Identity Awareness in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-User-and-Identity-Awareness/m-p/197887#M4386</link>
    <description>&lt;P&gt;yes, i have already checked that.&lt;/P&gt;</description>
    <pubDate>Tue, 14 Nov 2023 06:57:44 GMT</pubDate>
    <dc:creator>Leitner_EA</dc:creator>
    <dc:date>2023-11-14T06:57:44Z</dc:date>
    <item>
      <title>VPN User and Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-User-and-Identity-Awareness/m-p/197827#M4384</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we do have a problem, where access roles are not applied to VPN users. All our company users do have the Identity Agent installed and this seems to be working fine.&lt;/P&gt;&lt;P&gt;But we do also have some external users (contractors etc..) which do have their own equipment and do need a VPN connection for accessing some services. Currently we have the legacy user access for them working. I wanted to switch this to access roles. So i created a access role and added the AD user into it, but it doesn't get recognized. When VPN login is done, i can see an identity awareness entry :&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-11-13 14_36_34-Log Details.png" style="width: 762px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23202i3C7ECB8216CD12C1/image-size/large?v=v2&amp;amp;px=999" role="button" title="2023-11-13 14_36_34-Log Details.png" alt="2023-11-13 14_36_34-Log Details.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;but it doesn't get matched to the access role:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2023-11-13 14_39_34-Access Role.png" style="width: 778px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23203i2A4C83EA8B16A8A3/image-size/large?v=v2&amp;amp;px=999" role="button" title="2023-11-13 14_39_34-Access Role.png" alt="2023-11-13 14_39_34-Access Role.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;any clue where could be the error?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Georg&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 14:09:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-User-and-Identity-Awareness/m-p/197827#M4384</guid>
      <dc:creator>Leitner_EA</dc:creator>
      <dc:date>2023-11-13T14:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: VPN User and Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-User-and-Identity-Awareness/m-p/197855#M4385</link>
      <description>&lt;P&gt;Is Remote Access set as one of your Identity Sources in the Gateway object in the Identity Awareness section?&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 13 Nov 2023 19:21:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-User-and-Identity-Awareness/m-p/197855#M4385</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-13T19:21:17Z</dc:date>
    </item>
    <item>
      <title>Re: VPN User and Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-User-and-Identity-Awareness/m-p/197887#M4386</link>
      <description>&lt;P&gt;yes, i have already checked that.&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 06:57:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-User-and-Identity-Awareness/m-p/197887#M4386</guid>
      <dc:creator>Leitner_EA</dc:creator>
      <dc:date>2023-11-14T06:57:44Z</dc:date>
    </item>
    <item>
      <title>Re: VPN User and Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-User-and-Identity-Awareness/m-p/197896#M4387</link>
      <description>&lt;P&gt;could it be the problem, that the users are authenticated via RADIUS Server (Entrust Identity) / External User Profile?&lt;/P&gt;&lt;P&gt;in the pepd.elg i can see only this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[21381 4057782144]@XXXXXXXX[14 Nov  8:06:25] [TRACKER]: #2721205 -&amp;gt; INCOMING -&amp;gt; IDP_ASSOCIATION -&amp;gt; 
Association
ip: XX.XXX.XX.XXX
user: XXXXXXXX@domain
realm: vpn
machine: 
domain: 
client-type: 3
[21381 4057782144]@XXXXXXXXX[14 Nov  8:06:25] [TRACKER]: #2721206 -&amp;gt; OUTGOING -&amp;gt; IDENTITY_UPDATE -&amp;gt; pep (v4): 127.0.0.1pep (v6): , identity: UpdateInformation dump:
Unique ID           : 4faeb2ea
Client type         : 3, (Remote Access)
Time to live        : 86430, 86400
Client ID           : XX.XXX.XX.XXX, 0
Username            : XXXXX@domain
Log Username        : XXXXX@domain

Log UserDistinguishName: 

User domain         : 
User groups         : All Users, VPN-Intranet
Identity Role       :
Client Type Array   : 3&lt;/LI-CODE&gt;&lt;HR /&gt;&lt;P&gt;i would have thought, that Identity Awareness would use the Username and then do a lookup via LDAP to fetch the missing userdata, so it can matcht the corresponding Identity Roles.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 14 Nov 2023 08:36:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-User-and-Identity-Awareness/m-p/197896#M4387</guid>
      <dc:creator>Leitner_EA</dc:creator>
      <dc:date>2023-11-14T08:36:53Z</dc:date>
    </item>
    <item>
      <title>Re: VPN User and Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-User-and-Identity-Awareness/m-p/197953#M4388</link>
      <description>&lt;P&gt;If LDAP is set up correctly, this is exactly what should happen.&lt;BR /&gt;See if the following helps:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk113363" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk113363&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 15 Nov 2023 00:27:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-User-and-Identity-Awareness/m-p/197953#M4388</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-15T00:27:21Z</dc:date>
    </item>
    <item>
      <title>Re: VPN User and Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-User-and-Identity-Awareness/m-p/198239#M4389</link>
      <description>&lt;P&gt;i checked with the GUIDBEdit tool, and the do_fetch_ldap was set to false. i have set it to true, saved and then pushed policy again to the gateway. did not help. i think i have to get in contact with support.&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 08:29:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-User-and-Identity-Awareness/m-p/198239#M4389</guid>
      <dc:creator>Leitner_EA</dc:creator>
      <dc:date>2023-11-17T08:29:05Z</dc:date>
    </item>
    <item>
      <title>Re: VPN User and Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-User-and-Identity-Awareness/m-p/199732#M4390</link>
      <description>&lt;P&gt;i wanted to update the thread with the solution:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we did use the "legacy" authentication via VPN. After creating new VPN Authentication profiles (the LDAP lookup can be specified in them) - Identity Awareness is working - though not cross domain e.g. users from domain A are in groups of domain B. in the access rule is only the group from domain B specified - not working. but this is a problem which do have multiple apps regarding multi domain. directly specifying the users in the Access Roles is working&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 12:28:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/VPN-User-and-Identity-Awareness/m-p/199732#M4390</guid>
      <dc:creator>Leitner_EA</dc:creator>
      <dc:date>2023-12-05T12:28:34Z</dc:date>
    </item>
  </channel>
</rss>

