<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Forescout NAC Identity Awareness API in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forescout-NAC-Identity-Awareness-API/m-p/122747#M17564</link>
    <description>&lt;P&gt;Not yet, i have a ticket open with Support now and sent them PDP and PEP logs. Here i dont have much of a log to go off of, but this is in smart console:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Failed to get users groups for the domain.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Verify that this domain name is configured in your LDAP Account Unit.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Domain: DOMAIN&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Our Domain in the ldap account unit is DOMAIN.EXMAPLE.COM and the domain on the forescout side is sending just DOMAIN.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 01 Jul 2021 16:49:05 GMT</pubDate>
    <dc:creator>Jonathan_Langle</dc:creator>
    <dc:date>2021-07-01T16:49:05Z</dc:date>
    <item>
      <title>Forescout NAC Identity Awareness API</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forescout-NAC-Identity-Awareness-API/m-p/122410#M17540</link>
      <description>&lt;P&gt;We have the Check Point intergration to Forescout so we can add users to Access Roles in our security Policy. This is mostly working outside of one piece, the IP To User Mapping. It would appear Forescout is sending the EXAMPLE\Username instead of what our LDAP Account Unit is configured for which would be EXAMPLE.Domain.com as an example.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has anyone else used this integration and run into this? I tried changing the UserLoginAttr on the gateway object to UserPrincipalName&amp;nbsp; but no dice. The error i am seeing is the following:Failed to get users groups for the domain. Verify that this domain name is configured in your LDAP Account Unit. Domain: EXAMPLE&lt;/P&gt;</description>
      <pubDate>Mon, 28 Jun 2021 20:46:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forescout-NAC-Identity-Awareness-API/m-p/122410#M17540</guid>
      <dc:creator>Jonathan_Langle</dc:creator>
      <dc:date>2021-06-28T20:46:49Z</dc:date>
    </item>
    <item>
      <title>Re: Forescout NAC Identity Awareness API</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forescout-NAC-Identity-Awareness-API/m-p/122642#M17541</link>
      <description>&lt;P&gt;Have you approached Forescout related to this?&lt;BR /&gt;Can you include a (redacted) log card as well as version/JHF level?&lt;/P&gt;</description>
      <pubDate>Wed, 30 Jun 2021 21:17:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forescout-NAC-Identity-Awareness-API/m-p/122642#M17541</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-06-30T21:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: Forescout NAC Identity Awareness API</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forescout-NAC-Identity-Awareness-API/m-p/122747#M17564</link>
      <description>&lt;P&gt;Not yet, i have a ticket open with Support now and sent them PDP and PEP logs. Here i dont have much of a log to go off of, but this is in smart console:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Failed to get users groups for the domain.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Verify that this domain name is configured in your LDAP Account Unit.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Domain: DOMAIN&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Our Domain in the ldap account unit is DOMAIN.EXMAPLE.COM and the domain on the forescout side is sending just DOMAIN.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Jul 2021 16:49:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forescout-NAC-Identity-Awareness-API/m-p/122747#M17564</guid>
      <dc:creator>Jonathan_Langle</dc:creator>
      <dc:date>2021-07-01T16:49:05Z</dc:date>
    </item>
    <item>
      <title>Re: Forescout NAC Identity Awareness API</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forescout-NAC-Identity-Awareness-API/m-p/191297#M35314</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/25962"&gt;@Jonathan_Langle&lt;/a&gt;&amp;nbsp;where you able to implement this successfully?&lt;/P&gt;&lt;P&gt;we are trying the integration to send forescout identified device classifications to checkpoint access roles to be used in the policy. Your insight will be helpful.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Sep 2023 02:52:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Forescout-NAC-Identity-Awareness-API/m-p/191297#M35314</guid>
      <dc:creator>Kirupa_Shankar_</dc:creator>
      <dc:date>2023-09-01T02:52:33Z</dc:date>
    </item>
  </channel>
</rss>

