- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Greetings everyone!
I want to know if it is possible to get a notification when the MAC address associated to an AD user changes. We're dealing with R81.10 with Remote Access.
In the conversation above @Timothy_Hall mentions that L2 header gets stripped off by the time the packet reaches the INSPECT engine. However, in the same conversation there is a mention of an RFE for an External Tag. I tried to google about this, but to no avail so far.
I thought about a script that will read pep and pdp logs and make a notification when MAC of a user changes, but it looks like it would be quite resource heavy as our network activity is very high. On the other hand, I'm completely open to using 3rd party resources to gather that kind of information.
Thank you!
The feature mentioned in the thread is called Identity Tags: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide...
The tags are assigned by Cisco ISE or a SAML provider.
In any case, Identity Awareness does not track Layer 2 information, at least not in a way that would be easy to query.
Therefore, you'd have to use an external system (the identity provider itself) to get this information.
The feature mentioned in the thread is called Identity Tags: https://sc1.checkpoint.com/documents/R81.20/WebAdminGuides/EN/CP_R81.20_IdentityAwareness_AdminGuide...
The tags are assigned by Cisco ISE or a SAML provider.
In any case, Identity Awareness does not track Layer 2 information, at least not in a way that would be easy to query.
Therefore, you'd have to use an external system (the identity provider itself) to get this information.
Thank you @PhoneBoy. It was really helpful clarifying the possibilities within Identity Awareness.
Though I was reading about SmartEvent and started wondering if it can help me in this context. Apparently it can provide a wide variety of information, but I'm not sure if MAC changes of AD users is within its scope.
Edit: I will, of course, resort to Cisco ISE or a SAML if need be. But, I want to be able to solve this without using any service other than CheckPoint if possible.
We don't use MAC addresses in policy decisions, so there's not really a mechanism designed to track this in the product.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 4 | |
| 3 | |
| 2 | |
| 2 | |
| 1 | |
| 1 | |
| 1 | |
| 1 | |
| 1 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY