> Source: [sk183074](https://support.checkpoint.com/results/sk/sk183074)

# sk183074 - Opening Identity Awareness Captive Portal immediately overrides all other existing identity sessions

| Property | Value |
|----------|-------|
| Solution ID | sk183074 |
| Date Created | 2025-02-06 |
| Last Modified | 2025-02-10 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R81 (EOS) |
| OS | Gaia |

## Symptoms

- Opening Identity Awareness Captive Portal immediately overrides all other existing identity sessions.

Example:


1. In the Identity Awareness Gateway object, an administrator enabled these Identity Sources - Browser-Based Authentication and AD Query (or Identity Collector).
2. A user logs in on a machine on the network.  
   At this time, the command "`pdp monitor ip <IP Address of Machine>`" on the Identity Awareness Gateway shows "`LogUsername: <Expected Username>`".
3. AD Query (or Identity Collector) report this authenticated session to the Identity Awareness Gateway.
4. The same user on the same machine connects to the Identity Awareness Captive Portal.
5. Even without entering the credentials in Captive Portal, the Identity Awareness Gateway disconnects the current authenticated session from AD Query (or Identity Collector).   
   As a result, the user cannot connect to the Internet anymore.   
   During this issue, the command "`pdp monitor ip <IP Address of Machine>`" on the Identity Awareness Gateway shows "`LogUsername: unauthenticated_guest`".

## Cause

The PDP Identity Conciliation mechanism overrides all other existing identity sessions when it detects a Browser-Based Authentication session.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
