<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness - Identity Collector monitoring in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/125512#M22682</link>
    <description>&lt;P&gt;I found a way to do this without SNMP, by using the gaia_api run-script. You can run any expert command there, that includes pdp conn idc. Then I just need to handle it on the client side&lt;/P&gt;</description>
    <pubDate>Tue, 03 Aug 2021 00:21:12 GMT</pubDate>
    <dc:creator>Tiago_Cerqueira</dc:creator>
    <dc:date>2021-08-03T00:21:12Z</dc:date>
    <item>
      <title>Identity Awareness - Identity Collector monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/118131#M22675</link>
      <description>&lt;P&gt;Hello everyone,&lt;BR /&gt;&lt;BR /&gt;We're about to start using Identity Awareness with Identity Collectors (redundant and everything else), and one problem we're were noticing is that we did not see any ways to monitor Identity Collector .&lt;/P&gt;&lt;P&gt;Like the connection to AD servers, or connection to ISE servers&amp;nbsp; or even GW's .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you aware of any ways to achieve this ? or are there any MIB's for GW's through where we can get IA status and eventual errors ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;PS: there is another topic&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/monitoring-identity-awareness/td-p/23307" target="_blank" rel="noopener"&gt;IA Monitoring&lt;/A&gt;&amp;nbsp;that we will try in a similar way, but still&lt;/P&gt;</description>
      <pubDate>Tue, 11 May 2021 07:52:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/118131#M22675</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2021-05-11T07:52:19Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Identity Collector monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/118473#M22676</link>
      <description>&lt;P&gt;The identity collector itself? I don't think so.&lt;BR /&gt;That said if you're not seeing identities flow on the gateway, that would be a sign of an issue.&lt;BR /&gt;This SK suggests a possible MIB to query:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk139152&amp;amp;partition=Advanced&amp;amp;product=Identity" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk139152&amp;amp;partition=Advanced&amp;amp;product=Identity&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 04:24:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/118473#M22676</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-17T04:24:51Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Identity Collector monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/118488#M22677</link>
      <description>&lt;P&gt;Morning,&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P&gt;Currently we don't have any issues with the identity flow to the GW, but we are looking into a way to monitor this.&lt;/P&gt;&lt;P&gt;We are testing for now the SNMP monitoring of IA/IC through the GW, and that provides us with details on the sources connected to the IC (DC or pxGrid/ISE) . So we should be able to alert and take actions in case somethings shows up.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;(As example from similar SNMP implementation)&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/11694i74C0796896D90B91/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 06:51:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/118488#M22677</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2021-05-17T06:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Identity Collector monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/118573#M22678</link>
      <description>&lt;P&gt;There doesn't seem to be an obvious way to monitor this directly.&lt;BR /&gt;That said, you should see an active TCP connection on the gateway from the Identity Collector.&lt;BR /&gt;Maybe we need additional instrumentation here?&amp;nbsp;&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 17 May 2021 20:40:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/118573#M22678</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-05-17T20:40:48Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Identity Collector monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/118600#M22679</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/16983"&gt;@Sorin_Gogean&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;There are monitoring capabilities to IDC.&lt;/P&gt;
&lt;P&gt;Please check&amp;nbsp;sk108235, under "Monitoring capability" section - as&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;wrote above.&lt;/P&gt;
&lt;P&gt;The SNMP OIDs are mentioned in&amp;nbsp;&lt;SPAN&gt;$FWDIR/conf/identity_server.cps&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I suggest first to see the feature is working as needed with "&lt;EM&gt;pdp idc status" &lt;/EM&gt;command.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As for direct monitoring mechanism, there isn't. However, since IDC worth nothing without the PDP gateway getting the info from IDC, I personally don't think we need to add something to IDC itself.&lt;/P&gt;</description>
      <pubDate>Tue, 18 May 2021 07:20:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/118600#M22679</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2021-05-18T07:20:02Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Identity Collector monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/118752#M22680</link>
      <description>&lt;P&gt;Morning everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like Royi said, we are monitoring via SNMP from the PDP (our GW) that shows the sources detail received from IDC (sorry for the confusion) .&lt;/P&gt;&lt;P&gt;We're getting all the information from the table OID&amp;nbsp; .1.3.6.1.4.1.2620.1.38.53.... with all it's members&amp;nbsp; ("Identity Collector Sources") .&lt;/P&gt;&lt;P&gt;That covers our current needs .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you and have a nice week,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 05:28:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/118752#M22680</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2021-05-19T05:28:32Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Identity Collector monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/124801#M22681</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I'm also looking into this OID for monitoring, but I would like to monitor the total number of events sent from the IDC to the firewall. It seems like under the snmp branch&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;.1.3.6.1.4.1.2620.1.38 you can only monitor the connection between the IDC and the ADs (in our case), not the number of events being sent over from the IDC to the firewall itself, much like what you see on the "events in last hour" column ("Gateways" tab), on the IDC GUI.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Does anyone have any idea on how to monitor these? Thanks!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 24 Jul 2021 10:28:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/124801#M22681</guid>
      <dc:creator>Tiago_Cerqueira</dc:creator>
      <dc:date>2021-07-24T10:28:15Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Identity Collector monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/125512#M22682</link>
      <description>&lt;P&gt;I found a way to do this without SNMP, by using the gaia_api run-script. You can run any expert command there, that includes pdp conn idc. Then I just need to handle it on the client side&lt;/P&gt;</description>
      <pubDate>Tue, 03 Aug 2021 00:21:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/125512#M22682</guid>
      <dc:creator>Tiago_Cerqueira</dc:creator>
      <dc:date>2021-08-03T00:21:12Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Identity Collector monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/153260#M25706</link>
      <description>&lt;P&gt;Hi Sorin, I do not have any return on a snmpwalk to&amp;nbsp;&lt;SPAN&gt;.1.3.6.1.4.1.2620.1.38.53, how comes?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Jul 2022 14:39:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/153260#M25706</guid>
      <dc:creator>hemh</dc:creator>
      <dc:date>2022-07-18T14:39:33Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Identity Collector monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/153354#M25720</link>
      <description>&lt;P&gt;hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/40775"&gt;@hemh&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;maybe the planets didn't align, I don't know&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":beaming_face_with_smiling_eyes:"&gt;😁&lt;/span&gt;,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;(without knowing what you did and your environment, we can't answer)&lt;/P&gt;
&lt;P&gt;now on a serious note, were you following the SK&lt;SPAN&gt;108235 ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;did you enabled the Registry keys on the server that is hosting the IC ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;are you seeing in the GW's the DC and/or ISE servers when you try the below commands ?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;Via cpstat CLI:&amp;nbsp;&lt;EM&gt;cpstat identityServer -f idc&lt;/EM&gt;&lt;BR /&gt;- Via pdp CLI:&amp;nbsp;&lt;EM&gt;pdp idc status&lt;/EM&gt;&amp;nbsp;(available since R80.30)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;do an snmpwalk on the GW starting from&amp;nbsp;.1.3.6.1.4.1.2620.1.38 - you will see all the OID's under that root....&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;more details&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://oidref.com/1.3.6.1.4.1.2620.1.38" target="_blank"&gt;https://oidref.com/1.3.6.1.4.1.2620.1.38&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 19 Jul 2022 08:35:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/153354#M25720</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-07-19T08:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Identity Collector monitoring</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/210913#M39960</link>
      <description>&lt;P&gt;This below works for us, you can play with different branches of OID to suit your needs but I used .6 for 'Status' column of idc table, as shown in $FWDIR/conf/identity_server.cps:&lt;/P&gt;&lt;P&gt;-Add new custom poller 1.3.6.1.4.1.2620.1.38.53.1.6 (SNMP type GET TABLE) - to pull all IDC lines in one go&lt;/P&gt;&lt;P&gt;-Assign poller to gateways communicating with IDCs&lt;/P&gt;&lt;P&gt;-Alert trigger if row label = Status AND value != Connected&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Some SNMP walk on the OID tree can help you to shape what you are looking to achieve, you can go one level up to get the table or just look at events received if you like (use .5 instead of .6 works, just tested).&lt;/P&gt;</description>
      <pubDate>Wed, 10 Apr 2024 09:20:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-monitoring/m-p/210913#M39960</guid>
      <dc:creator>HusMo</dc:creator>
      <dc:date>2024-04-10T09:20:07Z</dc:date>
    </item>
  </channel>
</rss>

