We have an R80.40 Gateway Cluster with Identity Awareness. The identity sources are AD Query and Remote Access. Mobile Access Office Mode is enabled. User-based access roles work fine for VPN users, but the same can't be said for an access role that defines the machines.
The AD Query is working fine for the other contexts, but it's not applied to VPN connection.
In PDPd and PEPd logs I can see the AD connection for the machine in the VPN, but I think it's not processed by the identity Awareness.
[28237 4059047744]@CPFW01[25 Feb 14:01:17] [TRACKER]: #3326304 -> INCOMING -> ADQUERY_ASSOCIATION ->
Association
ip: 10.18.172.130
user:
machine: dxx-55375
domain: xxx.jus.br
reason:
Is there a way for the Remote Access and AD Query to work together to get the machine identification? What I'm trying to achieve here is to have identified domain machines hit a different rule/layer compared to a machine that remotely connects and is not identified.
Thanks in advance!