<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Machine Authentication &amp;amp; Identity Awareness in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/162424#M9362</link>
    <description>&lt;P&gt;Can you tell me what you actually did and how it resolved the issue?&lt;/P&gt;</description>
    <pubDate>Fri, 18 Nov 2022 07:35:54 GMT</pubDate>
    <dc:creator>Steffen_Appel</dc:creator>
    <dc:date>2022-11-18T07:35:54Z</dc:date>
    <item>
      <title>Machine Authentication &amp; Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/107371#M9355</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;&lt;P&gt;we are trying to enable machine authentication using AD machine enrollment, but we see two behaviours:&lt;/P&gt;&lt;P&gt;- the first one is the IP match with IA, after user logon on his laptop, we don't have the related event (that should be get from ADC), so all users rules based con Access Roles are not working&lt;/P&gt;&lt;P&gt;- the MA auth seems to work only with Legacy Login, this expose us to remove DynamicID from the authentication, so if some smart users change the type of login on the CP client can skip the 2FA&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any hints on the two problems?&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Sat, 09 Jan 2021 18:56:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/107371#M9355</guid>
      <dc:creator>stich86</dc:creator>
      <dc:date>2021-01-09T18:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Authentication &amp; Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/107379#M9356</link>
      <description>&lt;P&gt;To clarify your not seeing the AD/DC side security events for log-on &amp;amp; log-off vs un-lock is the auditing set correctly for the same?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Note these are the priorities of the different Identity Sources:&lt;BR /&gt;1. Remote Access (enabled by default)&lt;BR /&gt;2. Identity Agent, Terminal Servers Identity Agent&lt;BR /&gt;3. Captive Portal, Identity Collector, RADIUS Accounting, Identity Awareness API&lt;BR /&gt;4. AD Query&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 02:49:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/107379#M9356</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2021-01-11T02:49:10Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Authentication &amp; Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/107400#M9357</link>
      <description>&lt;P&gt;check this link:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk146835&amp;amp;partition=Basic&amp;amp;product=Identity" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk146835&amp;amp;partition=Basic&amp;amp;product=Identity&lt;/A&gt;&lt;/P&gt;&lt;P&gt;i think the problem is related to how the recoinciliation works. As i've understood the Remote VPN connector cannot be modified appending an ADQ.&lt;/P&gt;&lt;P&gt;Is it right?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Sun, 10 Jan 2021 18:29:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/107400#M9357</guid>
      <dc:creator>stich86</dc:creator>
      <dc:date>2021-01-10T18:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Authentication &amp; Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/157376#M9358</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/51282"&gt;@stich86&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am experiencing the same issue on R81.10 gateways.&lt;/P&gt;&lt;P&gt;Our machine certificate based remote access users are only being recognised by machine identity &amp;amp; not username.&lt;/P&gt;&lt;P&gt;Did you find out what causes this?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Sep 2022 23:48:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/157376#M9358</guid>
      <dc:creator>henryck</dc:creator>
      <dc:date>2022-09-15T23:48:25Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Authentication &amp; Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/162373#M9359</link>
      <description>&lt;P&gt;We have the same problem actually.&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 15:02:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/162373#M9359</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2022-11-17T15:02:25Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Authentication &amp; Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/162403#M9360</link>
      <description>&lt;P&gt;Stitch86 was on the money, its due to reconciliation.&lt;/P&gt;&lt;P&gt;Our configuration was changed on the gateways in pdp_session_conciliation.c with help from TAC&lt;/P&gt;</description>
      <pubDate>Thu, 17 Nov 2022 21:14:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/162403#M9360</guid>
      <dc:creator>henryck</dc:creator>
      <dc:date>2022-11-17T21:14:03Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Authentication &amp; Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/162419#M9361</link>
      <description>&lt;P&gt;Sorry for late response!&lt;/P&gt;
&lt;P&gt;i’m happy that you have solved the issue &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 06:52:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/162419#M9361</guid>
      <dc:creator>stich86</dc:creator>
      <dc:date>2022-11-18T06:52:09Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Authentication &amp; Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/162424#M9362</link>
      <description>&lt;P&gt;Can you tell me what you actually did and how it resolved the issue?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 07:35:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/162424#M9362</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2022-11-18T07:35:54Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Authentication &amp; Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/162427#M9363</link>
      <description>&lt;P&gt;You should open a ticket to the TAC, so they can give you the change needed on PDP reconciliation &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 18 Nov 2022 07:44:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/162427#M9363</guid>
      <dc:creator>stich86</dc:creator>
      <dc:date>2022-11-18T07:44:59Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Authentication &amp; Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/166892#M9364</link>
      <description>&lt;P&gt;TAC ticket is open but PDP change did not help.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Jan 2023 09:17:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/166892#M9364</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2023-01-06T09:17:32Z</dc:date>
    </item>
    <item>
      <title>Re: Machine Authentication &amp; Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/167244#M9365</link>
      <description>&lt;P&gt;Just to make sure, you use the machine tunnel before and after logon?&lt;/P&gt;
&lt;P&gt;Our supporter claims, that we have to turn the machine tunnel off after logon to get the user information correctly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Jan 2023 10:18:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Machine-Authentication-amp-Identity-Awareness/m-p/167244#M9365</guid>
      <dc:creator>Steffen_Appel</dc:creator>
      <dc:date>2023-01-10T10:18:10Z</dc:date>
    </item>
  </channel>
</rss>

