<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness - LDAP Account Creation in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-LDAP-Account-Creation/m-p/57280#M12591</link>
    <description>&lt;P&gt;The information i've got from PS and support is the account should be an admin account for identity awareness setup. I'm looking for a document from checkpoint that supports this requirement&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 02 Jul 2019 18:37:10 GMT</pubDate>
    <dc:creator>Enyi_Ajoku</dc:creator>
    <dc:date>2019-07-02T18:37:10Z</dc:date>
    <item>
      <title>Identity Awareness - LDAP Account Creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-LDAP-Account-Creation/m-p/57250#M12587</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I am trying to enable identity awareness, the server team needs to create a LDAP account for the firewall.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Should the LDAP account be an admin account or a user account?&lt;/P&gt;&lt;P&gt;If it has to be an admin account, is there a documentation i can reference to, which i can provide to the server team?&lt;/P&gt;&lt;P&gt;greatly appreciate the help&lt;/P&gt;&lt;P&gt;Thank You&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 14:37:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-LDAP-Account-Creation/m-p/57250#M12587</guid>
      <dc:creator>Enyi_Ajoku</dc:creator>
      <dc:date>2019-07-02T14:37:56Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - LDAP Account Creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-LDAP-Account-Creation/m-p/57257#M12588</link>
      <description>&lt;P&gt;Of course there is a very detailed reference :&amp;nbsp;Identity Awareness Administration Guide R80.20&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;! And for further information we have the&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk86441&amp;amp;partition=Advanced&amp;amp;product=Identity" target="_blank"&gt;sk86441: ATRG: &lt;STRONG&gt;Identity&lt;/STRONG&gt;&lt;STRONG&gt;Awareness&lt;/STRONG&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN class="Apple-converted-space"&gt;,&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk149255&amp;amp;partition=Advanced&amp;amp;product=Identity" target="_blank"&gt;sk149255: &lt;STRONG&gt;Identity&lt;/STRONG&gt;&lt;STRONG&gt;Awareness&lt;/STRONG&gt;- &lt;STRONG&gt;Identity&lt;/STRONG&gt;Sharing&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN class="Apple-converted-space"&gt;&amp;nbsp;and&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk88520&amp;amp;partition=General&amp;amp;product=Identity" target="_blank"&gt;sk88520: Best Practices - &lt;STRONG&gt;Identity&lt;/STRONG&gt;&lt;STRONG&gt;Awareness&lt;/STRONG&gt;Large Scale Deployment&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 14:55:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-LDAP-Account-Creation/m-p/57257#M12588</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2019-07-02T14:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - LDAP Account Creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-LDAP-Account-Creation/m-p/57263#M12589</link>
      <description>&lt;P&gt;Thank You for your feedback. I dont see anywhere on the documentation where it states the LDAP account has to be an administrator account except sk108235 - Identity Collector: Technical Overview which we are not deploying in my environment.&lt;/P&gt;&lt;P&gt;I would appreciate if you can direct me to where its stated on any of the sks.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 16:42:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-LDAP-Account-Creation/m-p/57263#M12589</guid>
      <dc:creator>Enyi_Ajoku</dc:creator>
      <dc:date>2019-07-02T16:42:03Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - LDAP Account Creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-LDAP-Account-Creation/m-p/57265#M12590</link>
      <description>&lt;P&gt;I think this may be what you're looking for if you don't want admin accounts:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk93938&amp;amp;partition=General&amp;amp;product=Identity" target="_self"&gt;Using Identity Awareness AD Query without Active Directory Administrator privileges on Windows Server 2008 and above&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 16:51:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-LDAP-Account-Creation/m-p/57265#M12590</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2019-07-02T16:51:15Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - LDAP Account Creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-LDAP-Account-Creation/m-p/57280#M12591</link>
      <description>&lt;P&gt;The information i've got from PS and support is the account should be an admin account for identity awareness setup. I'm looking for a document from checkpoint that supports this requirement&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 18:37:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-LDAP-Account-Creation/m-p/57280#M12591</guid>
      <dc:creator>Enyi_Ajoku</dc:creator>
      <dc:date>2019-07-02T18:37:10Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - LDAP Account Creation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-LDAP-Account-Creation/m-p/57282#M12592</link>
      <description>&lt;P&gt;I think the closest thing I can find is in the Identity Awareness R80.20 Admin guide where it says:&lt;/P&gt;
&lt;P&gt;"Enter the Active Directory credentials and click&lt;STRONG class="menuoptions"&gt; Connect&lt;/STRONG&gt; to verify the credentials. &lt;BR /&gt;&lt;STRONG class="bold"&gt;Important&lt;/STRONG&gt; - For AD Query you must enter domain administrator credentials. For Browser-Based Authentication standard credentials are sufficient."&lt;/P&gt;
&lt;P&gt;So, I would read that to mean the default requirement is an admin (or domain admin) account unless you wanted to create a user with custom permissions (without domain admin) as illustrated in the sk article I referenced.&lt;/P&gt;
&lt;P&gt;Here's a &lt;A href="https://sc1.checkpoint.com/documents/R80.20_GA/WebAdminGuides/EN/CP_R80.20_IdentityAwareness_AdminGuide/html_frameset.htm" target="_self"&gt;direct link&lt;/A&gt; to that portion of the admin guide for your AD administrator's reference. It should be under the section titled "Enabling Identity Awareness on the Log Server for Identity Logging"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 02 Jul 2019 18:48:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-LDAP-Account-Creation/m-p/57282#M12592</guid>
      <dc:creator>Daniel_Taney</dc:creator>
      <dc:date>2019-07-02T18:48:59Z</dc:date>
    </item>
  </channel>
</rss>

