- CheckMates
- :
- Products
- :
- General Topics
- :
- Identity Collector Users unable to browse to inter...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Identity Collector Users unable to browse to internet
Hi,
We successfully implement Identity Collector and working on R80.30. But we encounter an problem, the user is connected thru the WiFi and able to browse the internet but when the user disconnect to WiFi then connect thru LAN cable the user unable to browse the internet. By the way, the network of the WiFi is different to the LAN. Our workaround is login thru captive portal or restart the laptop.
Is there a solution for this issue? Or is this a limitation of the Identity Collector?
Appreciate your answers,
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
When fast roaming between wired/wireless is required, the recommended way is to use the identity agent, this will constantly update the user/IP asssociation.
Also, another workaround aside from restarting the laptop would be locking/unlocking it, that should generate an AD login event.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Is Admin account required for the Identity Agent implementation or like on the Identity Collector that a domain user can be used?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Usually these are deployed centrally by some form of software management tool or GPO.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
you should enable browser based authentication to avoid this kind of behavior but it require additional configuration steps for make it work
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As others already pointed out then would need the Agent installed.
One thing that is also possibly though waiting for it to happen is if you are using a NAC like Cisco ICE or HPE ClearPass where can use these as a Source for the Identity Collector.
That way as you move from Wired to Wirelss then the NAC has the log entry for you that the Identity Collector can take to update.
Useful if rolling out something like that but obviously probably easier to roll out the Agent if not rolling out the NAC anyway.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
I appreciate your reply on this issue, and we already raise this to TAC.
But unfortunately, as we try to replicate the issue the users was still able to access the internet. We are still investigating for the possible cause of this scenario. As checked on the logs for Identity Collector Server located on the C:\Windows\Temp\ia_ag.log, the Wireless IP of the User was changed to Wire IP which could indicate that the AD capture the change of the user's IP.
Thank you,
