<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Identity Awareness for the same user is working on one VS but not to another in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-for-the-same-user-is-working-on-one-VS-but/m-p/142695#M7140</link>
    <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;I am facing a very strange issue with Identity Awareness. I want to make a new implementation where a remote access user will have access to AWS through a site-to-site VPN. I am using Identity Collector.&lt;/P&gt;&lt;P&gt;The flow of the user is like this&amp;nbsp;&lt;/P&gt;&lt;P&gt;User --&amp;gt; External VS.1 (Identity Awareness Rule)--&amp;gt;&amp;nbsp;External VS.2 (Identity Awareness Rule) --&amp;gt; AWS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The site-to-site vpn is established on External VS.2.&lt;/P&gt;&lt;P&gt;The strange behavior is that the user matches the identity rule at&amp;nbsp;External VS.1 but not at the&amp;nbsp;External VS.2. As a result i am dropping at the drop rule and i cannot connect to my resources at AWS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any idea why identity awareness rules is matching only at one of my two VS;&lt;/P&gt;&lt;P&gt;I have Identity Awareness blade active on both firewalls&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
    <pubDate>Tue, 01 Mar 2022 14:43:07 GMT</pubDate>
    <dc:creator>Michalis89</dc:creator>
    <dc:date>2022-03-01T14:43:07Z</dc:date>
    <item>
      <title>Identity Awareness for the same user is working on one VS but not to another</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-for-the-same-user-is-working-on-one-VS-but/m-p/142695#M7140</link>
      <description>&lt;P&gt;Hi team,&lt;/P&gt;&lt;P&gt;I am facing a very strange issue with Identity Awareness. I want to make a new implementation where a remote access user will have access to AWS through a site-to-site VPN. I am using Identity Collector.&lt;/P&gt;&lt;P&gt;The flow of the user is like this&amp;nbsp;&lt;/P&gt;&lt;P&gt;User --&amp;gt; External VS.1 (Identity Awareness Rule)--&amp;gt;&amp;nbsp;External VS.2 (Identity Awareness Rule) --&amp;gt; AWS&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The site-to-site vpn is established on External VS.2.&lt;/P&gt;&lt;P&gt;The strange behavior is that the user matches the identity rule at&amp;nbsp;External VS.1 but not at the&amp;nbsp;External VS.2. As a result i am dropping at the drop rule and i cannot connect to my resources at AWS.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you have any idea why identity awareness rules is matching only at one of my two VS;&lt;/P&gt;&lt;P&gt;I have Identity Awareness blade active on both firewalls&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 14:43:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-for-the-same-user-is-working-on-one-VS-but/m-p/142695#M7140</guid>
      <dc:creator>Michalis89</dc:creator>
      <dc:date>2022-03-01T14:43:07Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness for the same user is working on one VS but not to another</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-for-the-same-user-is-working-on-one-VS-but/m-p/142699#M7141</link>
      <description>&lt;P&gt;Can you check pdp.elg and pep.elg on that VS and compare with working one? That may give us some ideas why its failing.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 01 Mar 2022 14:45:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-for-the-same-user-is-working-on-one-VS-but/m-p/142699#M7141</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-01T14:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness for the same user is working on one VS but not to another</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-for-the-same-user-is-working-on-one-VS-but/m-p/142756#M7142</link>
      <description>&lt;P&gt;Hi, thank you for your answer! We compare both outputs and are exactly the same.&lt;/P&gt;&lt;P&gt;One strange issue that we saw is that while at&amp;nbsp;&lt;SPAN&gt;External VS.1(which is the firewall where the identity rule is ok) and after issuing the command ''pdp monitor user x'' at the Groups section, the proper AD Group is appearing.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;When we issue the same command at External VS.2(which is the firewall where the identity rule is not matching)&amp;nbsp;at the Groups section, there is not the AD group of the user.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;So for some reason the firewall do not get the AD Group for this user...Any Idea;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 08:45:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-for-the-same-user-is-working-on-one-VS-but/m-p/142756#M7142</guid>
      <dc:creator>Michalis89</dc:creator>
      <dc:date>2022-03-02T08:45:32Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness for the same user is working on one VS but not to another</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-for-the-same-user-is-working-on-one-VS-but/m-p/142766#M7143</link>
      <description>&lt;P&gt;One quick thing I would try is disable/re-enable identity awareness blade on that fw, if you can...unless its referenced in lots of places. Have you tried command pdp update all? Can you reboot it? If none helps, then I would suggest debugs...I could send you debugs TAC gave me once for IA blade.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 10:59:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-for-the-same-user-is-working-on-one-VS-but/m-p/142766#M7143</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-02T10:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness for the same user is working on one VS but not to another</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-for-the-same-user-is-working-on-one-VS-but/m-p/142769#M7144</link>
      <description>&lt;P&gt;Unfortunately i can only issue the command pdp update user x because the Firewall is operational. Also Identity access rules can be matched by other accounts.&lt;/P&gt;&lt;P&gt;The only difference between the users that that matches the identity rules is the OU.&lt;/P&gt;&lt;P&gt;Do you believe that this can cause the problem;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 12:10:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-for-the-same-user-is-working-on-one-VS-but/m-p/142769#M7144</guid>
      <dc:creator>Michalis89</dc:creator>
      <dc:date>2022-03-02T12:10:34Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness for the same user is working on one VS but not to another</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-for-the-same-user-is-working-on-one-VS-but/m-p/142772#M7145</link>
      <description>&lt;P&gt;Wait a second...how is OU different?? Arent those exact same users? Yes, that would explain the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 12:28:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-for-the-same-user-is-working-on-one-VS-but/m-p/142772#M7145</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-02T12:28:14Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness for the same user is working on one VS but not to another</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-for-the-same-user-is-working-on-one-VS-but/m-p/142776#M7146</link>
      <description>&lt;P&gt;Yes the users that we have belongs to another OU from the users that they do not face any problem with the Identity rules.&lt;/P&gt;&lt;P&gt;My question is where can we distinguish which OU will match the Identity rules in a Checkpoint Firewall;&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 12:35:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-for-the-same-user-is-working-on-one-VS-but/m-p/142776#M7146</guid>
      <dc:creator>Michalis89</dc:creator>
      <dc:date>2022-03-02T12:35:02Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness for the same user is working on one VS but not to another</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-for-the-same-user-is-working-on-one-VS-but/m-p/142778#M7147</link>
      <description>&lt;P&gt;Thats all determined by access roles...if access roles are configured properly to reflect right OU in AD, then there is really no reason why it would fails. I pasted below the debug you can run. Do you have TAC case open for this?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(•)•) Identity awareness debugs&lt;BR /&gt;# cd $FWDIR/log&lt;BR /&gt;# rm pdpd.elg.*&lt;BR /&gt;# echo "=debug_start=" &amp;gt;&amp;gt; $FWDIR/log/pdpd.elg&lt;BR /&gt;(•) To turn pdp debug on:&lt;BR /&gt;# adlog a d on&lt;BR /&gt;# pdp debug on&lt;BR /&gt;# pep debug on&lt;BR /&gt;# pdp debug set all all&lt;BR /&gt;(•) Replicate the issue&lt;BR /&gt;(•) To turn them off:&lt;BR /&gt;# adlog a d off&lt;BR /&gt;# pdp debug unset all all&lt;BR /&gt;# pdp debug off&lt;BR /&gt;# pep debug off&lt;BR /&gt;# pdp d reset&lt;BR /&gt;# pep d unset all all&lt;BR /&gt;Collect debug:&lt;BR /&gt;$FWDIR/log/pdpd.elg&lt;BR /&gt;# tar zcvf pdpd_debugs.tgz pdpd.elg*&lt;BR /&gt;# tar zcvf pepd_debugs.tgz pepd.elg*&lt;/P&gt;</description>
      <pubDate>Wed, 02 Mar 2022 12:42:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-for-the-same-user-is-working-on-one-VS-but/m-p/142778#M7147</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-02T12:42:38Z</dc:date>
    </item>
  </channel>
</rss>

