I was wondering if anyone has come across this scenario and how they managed to overcome it.
Scenario:
Gateways are running Identity awareness via Identity collector servers. Laptop users VPN into corporate and so gws get user's ID and associated VPN IP. User now needs to go into office so they just close the laptop (do not logout). Laptop goes in “sleep” mode. User is now onsite, he opens his laptop, unlocks his screen, and now the laptop connects up to the corporate wireless network.
Issue:
Since the login, while onprem, occurs prior to the laptop connecting to the wireless network, the logon event is not captured on the corporate Domain controllers. (cached authentication on the laptop). Since no event is “seen” by Identity Collectors for this user, the gws do not see his new wireless IP tagged to his userid and so no PDP/PEP associations are done. Since the gw has Identity based rules for outbound internet, user is denied access from wireless connection due to no IP association in PDP/PEP.
Workaround:
User has to either lock and unlock laptop to retrigger a logon event so that it is “seen” by the gws. Does not always work or slow to get recognized. Another way is that user needs to reboot which is not convenient for folks like VPs who have a whole lot of application screens and docs opened prior to coming onsite.
Thoughts:
Would there be any better user experience by having identity agents on the laptop or some other method that would provide a more transparent and less impactful method of transition from home to onprem and likely vice versa?