Question about identity conciliation. I was under the impression that a PDP can only have two identities associated with an IP address under certain circumstances (e.g. Terminal Server). I am running some tests in our lab. Background:
Gateway/management R80.20 with JHFA 134
Identity Collector: v80.97.0000 (using ActiveDirectory as identity source)
I also have RADIUS server set up as an identity source for a test user.
I log on to the (virtual) desktop, the identity collector correctly sees my logon and appropriate AccessRole is applied. I test the rule where this AccessRole is used and traffic goes through.
I then open up a Captive Portal window and log on with a different username and authenticate against the RADIUS server. The AccessRole for this user is applied. I test the rule where this AccessRole is used, and traffic goest through.
Here's the kicker: traffic for the AccessRole based in the identity collector based role is also allowed. Traffic based on both identities is allowed. The traffic is matching the corresponding rules for each identity. My understanding was that once I authenticated to Captive Portal (against RADIUS) this would "overwrite" the identity association based on the Identity Collector. Is that actually occurring, and then the Identity Collector is re-mapping my AD based identity, and then combining the two? Is that what is occurring?
On a side note, though the R80.40 IA guide has a section about identity conciliation and references "Confidence, Locality" etc. as parameters to determine how identities are reconciled on a single IP, more information about this process, e.g. what has most confidence, would be appreciated.
Dave