<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to access remote site's LDPA server via VPN for Local site CheckPoint's identity awareness ? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/127656#M18533</link>
    <description>&lt;P&gt;I even try to have a rule any source to any destination permit and still not works for me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also check the KB seems the 1500 series not supports having local connection to AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But seems using another Gateway Managed by the same SMS (We are Smart 1- Cloud) to share the AD is ok.&lt;/P&gt;&lt;P&gt;Might I know if you manipulate it also? Would like to knows the steps on how to configure it.&lt;/P&gt;</description>
    <pubDate>Mon, 23 Aug 2021 01:02:04 GMT</pubDate>
    <dc:creator>MTS</dc:creator>
    <dc:date>2021-08-23T01:02:04Z</dc:date>
    <item>
      <title>How to access remote site's LDPA server via VPN for Local site CheckPoint's identity awareness ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/126580#M18326</link>
      <description>&lt;P&gt;Hello and thank you in advance.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We got trouble that we have CheckPoint are now managed by the same cloud.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Let says we got CheckPoint A and B now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The AD (LDAP) server is located on A site now.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;A and B sites just had a VPN community connection and we did confirm no communication error between sites.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At least, those Site B hosts can access the Site A LDAP for Domain authentication at the moment.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We set up the "identity awareness" on Site A Checkpoint and nothing outstanding, everything works well.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We then try to use the same configuration for the Site B&amp;nbsp;Checkpoint to connect to the same AD over the VPN.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And it reported a connectivity issue and said the Site B&amp;nbsp;Checkpoint NO connection to the remote site Server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Why?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Topology.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13175i98BBBF26394FFF12/image-size/large?v=v2&amp;amp;px=999" role="button" title="Topology.JPG" alt="Topology.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 14:58:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/126580#M18326</guid>
      <dc:creator>MTS</dc:creator>
      <dc:date>2021-08-11T14:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: How to access remote site's LDPA server via VPN for Local site CheckPoint's identity awareness ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/126620#M18331</link>
      <description>&lt;P&gt;Version/JHF level?&lt;BR /&gt;Do you have identity sharing enabled between the gateways?&lt;BR /&gt;How are identities acquired? (AQ Query, Identity Collector, or?)&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 22:59:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/126620#M18331</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-11T22:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: How to access remote site's LDPA server via VPN for Local site CheckPoint's identity awareness ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/126628#M18334</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Version/JHF level?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;the latest&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;Do you have identity sharing enabled between the gateways?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Should be no.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;How are identities acquired? (AQ Query, Identity Collector, or?)&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Just want to find an AD user name from the log.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Below the error message FYI.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture2.PNG" style="width: 637px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/13180i2E0F9550833CC364/image-size/large?v=v2&amp;amp;px=999" role="button" title="Capture2.PNG" alt="Capture2.PNG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 01:01:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/126628#M18334</guid>
      <dc:creator>MTS</dc:creator>
      <dc:date>2021-08-12T01:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: How to access remote site's LDPA server via VPN for Local site CheckPoint's identity awareness ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/126633#M18337</link>
      <description>&lt;P&gt;This requires configuring Identity Awareness, which you are apparently trying to do.&lt;BR /&gt;For this to work, you must be running R80.20 and above and configure one of the gateways as an Active Directory proxy.&lt;/P&gt;
&lt;P&gt;See: &lt;A href="https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_IdentityAwareness_AdminGuide/Topics-IDAG/Identity-Awareness-Config-as-Active-Directory-Proxy.htm?Highlight=Ad%20proxy" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_IdentityAwareness_AdminGuide/Topics-IDAG/Identity-Awareness-Config-as-Active-Directory-Proxy.htm?Highlight=Ad%20proxy&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 03:39:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/126633#M18337</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-12T03:39:51Z</dc:date>
    </item>
    <item>
      <title>Re: How to access remote site's LDPA server via VPN for Local site CheckPoint's identity awareness ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/126730#M18340</link>
      <description>&lt;P&gt;The same AD and&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;Identity Awareness are just working for my 192.168.1.1 site.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;For the 192.168.10.X checkpoint is not working... I have no idea how to let the 192.168.10.X checkpoint using the right route and source interface to access back the AD...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Based on the route debug and traceroute, I find it go outside the internet but not VPN to the AD...&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 12:38:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/126730#M18340</guid>
      <dc:creator>MTS</dc:creator>
      <dc:date>2021-08-12T12:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: How to access remote site's LDPA server via VPN for Local site CheckPoint's identity awareness ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/126739#M18344</link>
      <description>&lt;P&gt;Note that even though you did not explicitly configure it, the gateway is always included in the Encryption Domain.&lt;BR /&gt;However, you need to ensure the rules permit this traffic.&lt;BR /&gt;The traffic will probably come from the gateway's external IP, which is expected.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Aug 2021 13:25:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/126739#M18344</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-12T13:25:30Z</dc:date>
    </item>
    <item>
      <title>Re: How to access remote site's LDPA server via VPN for Local site CheckPoint's identity awareness ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/127656#M18533</link>
      <description>&lt;P&gt;I even try to have a rule any source to any destination permit and still not works for me.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also check the KB seems the 1500 series not supports having local connection to AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;But seems using another Gateway Managed by the same SMS (We are Smart 1- Cloud) to share the AD is ok.&lt;/P&gt;&lt;P&gt;Might I know if you manipulate it also? Would like to knows the steps on how to configure it.&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 01:02:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/127656#M18533</guid>
      <dc:creator>MTS</dc:creator>
      <dc:date>2021-08-23T01:02:04Z</dc:date>
    </item>
    <item>
      <title>Re: How to access remote site's LDPA server via VPN for Local site CheckPoint's identity awareness ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/127657#M18534</link>
      <description>&lt;P&gt;You can't use an SMB gateway as an AD proxy.&lt;BR /&gt;That is an RFE.&lt;BR /&gt;If you have a non-SMB gateway that is managed by the same AD server that also has access, you configure it per the docs I linked above.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 01:10:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/127657#M18534</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-23T01:10:39Z</dc:date>
    </item>
    <item>
      <title>Re: How to access remote site's LDPA server via VPN for Local site CheckPoint's identity awareness ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/127658#M18535</link>
      <description>&lt;P&gt;So, there is no way for 1570 to connect the AD via VPN / Proxy now?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 01:13:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/127658#M18535</guid>
      <dc:creator>MTS</dc:creator>
      <dc:date>2021-08-23T01:13:00Z</dc:date>
    </item>
    <item>
      <title>Re: How to access remote site's LDPA server via VPN for Local site CheckPoint's identity awareness ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/127659#M18536</link>
      <description>&lt;P&gt;Correct, there is no way to do it with just SMB gateways.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 01:16:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/127659#M18536</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-23T01:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to access remote site's LDPA server via VPN for Local site CheckPoint's identity awareness ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/127660#M18537</link>
      <description>&lt;P&gt;Sorry, seems I missing one thing.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are using 6000 formal Gaia OS gateway for&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;A site.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Only B site uses the 1570.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Any chance has AD connected for this case?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 01:19:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/127660#M18537</guid>
      <dc:creator>MTS</dc:creator>
      <dc:date>2021-08-23T01:19:25Z</dc:date>
    </item>
    <item>
      <title>Re: How to access remote site's LDPA server via VPN for Local site CheckPoint's identity awareness ?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/127661#M18538</link>
      <description>&lt;P&gt;The AD proxy is needed so Smart-1 Cloud can query your on-premise AD server.&lt;BR /&gt;Like I said previously, you need to configure Identity Sharing between the two gateways.&lt;BR /&gt;Please review the documentation I linked above.&lt;/P&gt;
&lt;P&gt;Can your AD server accept LDAP requests on port 389?&lt;BR /&gt;If not, that also is a known limitation:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk159772" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk159772&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 23 Aug 2021 01:44:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-access-remote-site-s-LDPA-server-via-VPN-for-Local-site/m-p/127661#M18538</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-08-23T01:44:56Z</dc:date>
    </item>
  </channel>
</rss>

