<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness over VPN - Same user in different Domains in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-over-VPN-Same-user-in-different-Domains/m-p/118471#M8582</link>
    <description>&lt;P data-unlink="true"&gt;What version of client?&lt;BR /&gt;What authentication mechanism is being used?&lt;BR /&gt;I would think you could specify the full username (&lt;A href="mailto:user@sub.dom.ain" target="_blank"&gt;user@sub.dom.ain&lt;/A&gt;) as part of the authentication process.&lt;/P&gt;</description>
    <pubDate>Mon, 17 May 2021 04:11:33 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-05-17T04:11:33Z</dc:date>
    <item>
      <title>Identity Awareness over VPN - Same user in different Domains</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-over-VPN-Same-user-in-different-Domains/m-p/118352#M8581</link>
      <description>&lt;P&gt;Hello.&lt;BR /&gt;I have a case with a customer.&lt;BR /&gt;&lt;BR /&gt;We integrate Active Directory servers by creating LDAP account unit. Domain user authentication is done through a VPN Check Point mobile client.&lt;BR /&gt;When a client connects to a domain that is registered with Check Point, everything is normal. Their respective logs are generated in SmartConsole and everything is ok.&lt;/P&gt;&lt;P&gt;The problem arises, there are several users who have a user with the same name in one domain and registered with the same name in another subdomain.&lt;BR /&gt;For example:&lt;BR /&gt;JonhDoe@domain.com&lt;BR /&gt;JonhDoe@subdomain.domain.com&lt;/P&gt;&lt;P&gt;The priority of subdomain.domain.com is set to 1, and the priority of domain.com is set to 5.&lt;BR /&gt;When the user enters his username JonhDoe, he manages to access the domain.com that has lower priority, when he should access subdomain.domain.com&lt;/P&gt;&lt;P&gt;Is there a way that the user can choose which domain he wants to connect to from the VPN client?&lt;BR /&gt;For example, have the user enter JonhDoe@domain.com or&lt;BR /&gt;JonhDoe@subdomain.domain.com and from there it is determined which domain it will access?&lt;BR /&gt;&lt;BR /&gt;We have a SMS and Firewall cluster on R80.30 version&lt;BR /&gt;Regards.&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 15:00:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-over-VPN-Same-user-in-different-Domains/m-p/118352#M8581</guid>
      <dc:creator>israelsc</dc:creator>
      <dc:date>2021-05-14T15:00:55Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness over VPN - Same user in different Domains</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-over-VPN-Same-user-in-different-Domains/m-p/118471#M8582</link>
      <description>&lt;P data-unlink="true"&gt;What version of client?&lt;BR /&gt;What authentication mechanism is being used?&lt;BR /&gt;I would think you could specify the full username (&lt;A href="mailto:user@sub.dom.ain" target="_blank"&gt;user@sub.dom.ain&lt;/A&gt;) as part of the authentication process.&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 04:11:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Awareness-over-VPN-Same-user-in-different-Domains/m-p/118471#M8582</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-17T04:11:33Z</dc:date>
    </item>
  </channel>
</rss>

