<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IA with Identity Collector in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IA-with-Identity-Collector/m-p/147553#M23535</link>
    <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So we're progressing each day in our IA test/implementation.&lt;/P&gt;&lt;P&gt;After we clarified some ISE issues (psGrid 2.0 vs pxGrid 1.0), we've bumped into some new interesting information in regards to AD&amp;nbsp;&lt;SPAN&gt;Global Catalog&amp;nbsp;&lt;/SPAN&gt;from the &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk134292" target="_self"&gt;sk134292&lt;/A&gt;&amp;nbsp;and I wanted to ask, if it would be recommended to move from standard "LDAP Account Units" to LDAP AU but pointing it to&amp;nbsp;&lt;SPAN&gt;Global Catalog AD port.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We were thinking to go this path, as we have an big AD environment with several sub-domains, and therefore we were dealing with 10-15 LDAP AU's (5 per Cluster to address each subdomain). The expectations if we move to LDAP AU against Global Catalog, would be to get less failed log-ins (we've seen a lot of those for identities&amp;nbsp;sent from Cisco ISE without SGT's).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;That would reduce those 15 LDAP AU to 3 (as we look to have IA on 3 clusters) .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Would that bring any improvement?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PS: also while we looked into some problems, we failed to find a way we could check from GW cli, AD resolution for an machine or username. whatever documents are out-there are AD Query related. Any hints would be appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PS2: I was browsing last week/weekend the CheckMates portal, and I remember seeing somewhere that for user identities received from ISE (without SGT),&amp;nbsp; we have an CLI option to search those identities against AD also. Did I remember correctly or I'm going crazy&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;....&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 03 May 2022 15:15:53 GMT</pubDate>
    <dc:creator>Sorin_Gogean</dc:creator>
    <dc:date>2022-05-03T15:15:53Z</dc:date>
    <item>
      <title>IA with Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IA-with-Identity-Collector/m-p/147553#M23535</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So we're progressing each day in our IA test/implementation.&lt;/P&gt;&lt;P&gt;After we clarified some ISE issues (psGrid 2.0 vs pxGrid 1.0), we've bumped into some new interesting information in regards to AD&amp;nbsp;&lt;SPAN&gt;Global Catalog&amp;nbsp;&lt;/SPAN&gt;from the &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk134292" target="_self"&gt;sk134292&lt;/A&gt;&amp;nbsp;and I wanted to ask, if it would be recommended to move from standard "LDAP Account Units" to LDAP AU but pointing it to&amp;nbsp;&lt;SPAN&gt;Global Catalog AD port.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;We were thinking to go this path, as we have an big AD environment with several sub-domains, and therefore we were dealing with 10-15 LDAP AU's (5 per Cluster to address each subdomain). The expectations if we move to LDAP AU against Global Catalog, would be to get less failed log-ins (we've seen a lot of those for identities&amp;nbsp;sent from Cisco ISE without SGT's).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;That would reduce those 15 LDAP AU to 3 (as we look to have IA on 3 clusters) .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Would that bring any improvement?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thank you,&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PS: also while we looked into some problems, we failed to find a way we could check from GW cli, AD resolution for an machine or username. whatever documents are out-there are AD Query related. Any hints would be appreciated.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;PS2: I was browsing last week/weekend the CheckMates portal, and I remember seeing somewhere that for user identities received from ISE (without SGT),&amp;nbsp; we have an CLI option to search those identities against AD also. Did I remember correctly or I'm going crazy&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":face_with_rolling_eyes:"&gt;🙄&lt;/span&gt;....&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 May 2022 15:15:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IA-with-Identity-Collector/m-p/147553#M23535</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-05-03T15:15:53Z</dc:date>
    </item>
  </channel>
</rss>

