Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
David_C1
Advisor

Identity Awareness captive portal and identity conciliation

As described in sk183074, simply connected to the Identity Awareness captive portal from a host immediately overwrites any existing identity sessions on the host. Can someone explain the logic for this behavior to me? I don't necessary want the technical reason why this happens, but what are the security or functional reasons that this behavior was implemented? Does this not prevent any type of identity conciliation if merely connecting to a portal kills the existing session?  Am I missing something?

FWIW, this is one of a number of reasons why we can't get rid of old school client authentication...

Thanks,

Dave

0 Kudos
4 Replies
PhoneBoy
Admin
Admin

It sounds like you need to enable the option to allow multiple users to connect from the same IP.
See: https://support.checkpoint.com/results/sk/sk105889 

0 Kudos
David_C1
Advisor

I may try this setting, but it looks like these commands allow for multiple user identities from the same acquisition method be allowed. My particular case is that identity is acquired via Identity Collector, then simply opening Identity Awareness captive portal page deletes the identity acquired via the IC.

Dave

0 Kudos
(1)
Royi_Priov
Employee
Employee

Hi David,

The reason is the design in Identity Awareness side.

Once the gateway opens/redirects the browser to the captive portal, the PDP is "waiting" for the end user's input for credentials. Once this flow is triggered, we are clearing the current session saved for this IP, and creates a placeholder for the new credentials to be received. It means, even if the user will not enter credentials in the portal, the fact that this client IP initiate a traffic to the portal, clears the existing session.

I will add and say, that in case you have configured an automatic redirection to the portal, this redirection will happen only if the PDP doesn't have any information for the end user IP.

I hope it helps.

Thanks,
Royi Priov
R&D Group manager, Infinity Identity
0 Kudos
David_C1
Advisor

That does help, though in my case it is not a redirect, but a manual action by the user to open the portal page. We are trying to implement this as a "step-up" authentication, allowing access to sensitive systems only when needed. And like I mentioned, the automatic clearing of the current session prevents any sort of identity conciliation. It certainly could also be disruptive to a user's work if they accidentally open the portal and suddenly any access granted via their current identity session is dropped. It would be beneficial to allow the customer to decide if/how this happens.

It looks like client authentication will be sticking around in our environment for the time being.

Dave

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events