<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic sending Radius accounting data to Checkpoint Identity Awareness in ZoneDirector</title>
    <link>https://community.ruckuswireless.com/t5/ZoneDirector/sending-Radius-accounting-data-to-Checkpoint-Identity-Awareness/m-p/13546#M2976</link>
    <description>Hi,&lt;BR /&gt;&lt;BR /&gt;we are using Checkpoint's Identity Awareness feature to keep track of users to allow internet access. This basically maps IP addresses to AD accounts. One way to update this system is using Radius accounting which is ideal for WiFi.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We have our Zonedirector set up to send accounting packets to Checkpoint and this works well giving the user access to the internet seamlessly.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;However .... &amp;nbsp;when a user roams to another AP the Indentity Awareness looses the association between IP and username. As neither has changed this can only be because Zonedirector has sent a packet to Checkpoint to say that the user has left that AP and not sent another to tell the user it has reassociated to the new AP.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Is there anything I can do to fix this behaviour ?&lt;BR /&gt;&lt;BR /&gt;Thanks for reading&lt;BR /&gt;&lt;BR /&gt;Bruce</description>
    <pubDate>Wed, 15 Jun 2016 14:49:15 GMT</pubDate>
    <dc:creator>bruce_richards1</dc:creator>
    <dc:date>2016-06-15T14:49:15Z</dc:date>
    <item>
      <title>sending Radius accounting data to Checkpoint Identity Awareness</title>
      <link>https://community.ruckuswireless.com/t5/ZoneDirector/sending-Radius-accounting-data-to-Checkpoint-Identity-Awareness/m-p/13546#M2976</link>
      <description>Hi,&lt;BR /&gt;&lt;BR /&gt;we are using Checkpoint's Identity Awareness feature to keep track of users to allow internet access. This basically maps IP addresses to AD accounts. One way to update this system is using Radius accounting which is ideal for WiFi.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;We have our Zonedirector set up to send accounting packets to Checkpoint and this works well giving the user access to the internet seamlessly.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;However .... &amp;nbsp;when a user roams to another AP the Indentity Awareness looses the association between IP and username. As neither has changed this can only be because Zonedirector has sent a packet to Checkpoint to say that the user has left that AP and not sent another to tell the user it has reassociated to the new AP.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;Is there anything I can do to fix this behaviour ?&lt;BR /&gt;&lt;BR /&gt;Thanks for reading&lt;BR /&gt;&lt;BR /&gt;Bruce</description>
      <pubDate>Wed, 15 Jun 2016 14:49:15 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ZoneDirector/sending-Radius-accounting-data-to-Checkpoint-Identity-Awareness/m-p/13546#M2976</guid>
      <dc:creator>bruce_richards1</dc:creator>
      <dc:date>2016-06-15T14:49:15Z</dc:date>
    </item>
    <item>
      <title>Re: sending Radius accounting data to Checkpoint Identity Awareness</title>
      <link>https://community.ruckuswireless.com/t5/ZoneDirector/sending-Radius-accounting-data-to-Checkpoint-Identity-Awareness/m-p/13547#M2977</link>
      <description>Update: packet captures show that the accounting packets are going out in this order&lt;BR /&gt;&lt;BR /&gt;User Connects to AP1: Start Packet&amp;nbsp;&lt;BR /&gt;User roams to AP2: Start Packet,&amp;nbsp;Stop Packet.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;If you look at the Session IDs for the packets then you can see that the Stop relates to AP1, but Checkpoint is ignoring Session ID and breaking the connection on Stop.&amp;nbsp;</description>
      <pubDate>Mon, 20 Jun 2016 11:09:38 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ZoneDirector/sending-Radius-accounting-data-to-Checkpoint-Identity-Awareness/m-p/13547#M2977</guid>
      <dc:creator>bruce_richards1</dc:creator>
      <dc:date>2016-06-20T11:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: sending Radius accounting data to Checkpoint Identity Awareness</title>
      <link>https://community.ruckuswireless.com/t5/ZoneDirector/sending-Radius-accounting-data-to-Checkpoint-Identity-Awareness/m-p/13548#M2978</link>
      <description>This might take some help from CheckPoint Bruce...</description>
      <pubDate>Tue, 21 Jun 2016 23:33:30 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ZoneDirector/sending-Radius-accounting-data-to-Checkpoint-Identity-Awareness/m-p/13548#M2978</guid>
      <dc:creator>michael_brado</dc:creator>
      <dc:date>2016-06-21T23:33:30Z</dc:date>
    </item>
    <item>
      <title>Re: sending Radius accounting data to Checkpoint Identity Awareness</title>
      <link>https://community.ruckuswireless.com/t5/ZoneDirector/sending-Radius-accounting-data-to-Checkpoint-Identity-Awareness/m-p/13549#M2979</link>
      <description>Agreed, I'm asking the same questions of both parties and getting similar responses. I think that Ruckus are on higher ground as Checkpoint are ignoring the Session IDs but introducing a fraction of a second delay on the Start packets does fix the issue.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;At the moment I'm working round the issue by using FreeRADIUS to introduce a 0.5 sec delay on the start packets.&amp;nbsp;</description>
      <pubDate>Wed, 22 Jun 2016 07:57:25 GMT</pubDate>
      <guid>https://community.ruckuswireless.com/t5/ZoneDirector/sending-Radius-accounting-data-to-Checkpoint-Identity-Awareness/m-p/13549#M2979</guid>
      <dc:creator>bruce_richards1</dc:creator>
      <dc:date>2016-06-22T07:57:25Z</dc:date>
    </item>
  </channel>
</rss>

