Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Cesar_Santos
Explorer
Jump to solution

Logs with multiple source users

Hi CheckMates,

I'm seeing a strange behaviour on the logs of my gateway cluster (R80.30). Basically, I'm seeing multiple users on the source username column of the traffic logs. 

Screenshot 2020-11-17 at 18.42.46.png

 

The problem with this is that the rules are not properly applied, because we're using access roles to manage the permissions. We're using the Identity Collector to see all the logon and logoff events in our microsoft AD. 

So, anyone knows a possible root cause for this? How can I solve this issue?

Regards

 

0 Kudos
1 Solution

Accepted Solutions
Wolfgang
Authority
Authority

@Cesar_Santos 

I thought as much. If you use the "switch user" function you have two logged in user on this host. The same applies to "run as" feature. From Check Points identity view this is expected behaviour. You can solve this with defining your hosts as multiuser hosts like Terminal- or Citrixserver. For this you have to install the MUH-agent on these hosts.

Have a look at Identity Agent Incorrectly Assigns Users To IP When Using The "Switch User" Function On Windows Clie... 

and for MUH2 agent  Terminal Server Agent v2 (MUH2) - FAQ 

regards

Wolfgang

View solution in original post

0 Kudos
6 Replies
Wolfgang
Authority
Authority

Is the source host a terminal- or Citrixserver with more then one user logged in?

Did you exclude all service accounts on your Identity collectors? Are there any software running on the source host with specific user accounts?

There are some possibilities that more then one user logged in on a host at the same time.

Wolfgang

0 Kudos
Cesar_Santos
Explorer

Hi,

This an host terminal. We're are talking about a medical center in our national healthcare system. So, we've multiple machines in medical rooms that are used by multiple users, not at the same time, but one at a time. The end users, let say multiple doctors, they may or may not end their windows sessions. So, when the next doctor comes up to the end machine, they could have another user account logged in. So, this doctor will use the "Switch User Account" option on Windows to login in his session. From the Administrator point of view, we will have multiple sessions in the state of "Disconnected" and one session as in "Active" state. How will the Identity collector handle this? Will he use only the last logged in user, with the active session? That, at least, is what I expect. 

We've excluded all the service accounts from the Identity collectors. Regarding software running with specific user accounts, let's say that a Domain admin goes to one of these machines to install a new software. Instead of disconnect the session on the end user, the domain admin click the right button and uses the "Run as Administrator" feature to install the software. The Identity collector will send te new IP/user mapping to the gateways. The problem is that this is not a real new login event. So, these kind of events should be ignored. If they don't, we will have multiple access roles that are not properly applied. With that, we will have users with permissions to use some Apps or to access to some URLS that they shouldn't.

 

Regards   

0 Kudos
Wolfgang
Authority
Authority

@Cesar_Santos 

I thought as much. If you use the "switch user" function you have two logged in user on this host. The same applies to "run as" feature. From Check Points identity view this is expected behaviour. You can solve this with defining your hosts as multiuser hosts like Terminal- or Citrixserver. For this you have to install the MUH-agent on these hosts.

Have a look at Identity Agent Incorrectly Assigns Users To IP When Using The "Switch User" Function On Windows Clie... 

and for MUH2 agent  Terminal Server Agent v2 (MUH2) - FAQ 

regards

Wolfgang

0 Kudos
Cesar_Santos
Explorer

Hi Wolfgang,

Thanks a lot for your help. I've really appreciated.

Regards

0 Kudos
Cesar_Santos
Explorer

Hi Wolfgang,

So, I've forgotten to ask you something. The MUH-Agent only works for Windows Server, right? Ate least that is my understanding of the documentation https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut....

Regards 

0 Kudos
Wolfgang
Authority
Authority

Yes Cesar,

the agents are available only for Windows.

Wolfgang

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events