<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Sharing and Cisco ISE in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159323#M27872</link>
    <description>&lt;P&gt;For now the solution is to connect the Identity Collector to each gateway, effectively turning them into PDP so the broker would be a more complex way to do the same.&lt;/P&gt;&lt;P&gt;The idea is to have a low-end cluster serving as PDP for the ISE tags and sending them to all other gateways but it seems that nothing happens with tags when this is configured.&lt;/P&gt;</description>
    <pubDate>Wed, 12 Oct 2022 08:05:51 GMT</pubDate>
    <dc:creator>Alex-</dc:creator>
    <dc:date>2022-10-12T08:05:51Z</dc:date>
    <item>
      <title>Identity Sharing and Cisco ISE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159233#M27851</link>
      <description>&lt;P&gt;I'm successfully using Identity Collector and Cisco ISE to send tags to a pilot gateway.&lt;/P&gt;&lt;P&gt;I do not find however if I can use this setup along with Identity Sharing with other gateways of the SMS to share tags like it happens with accounts and the documentation isn't explicit on this.&lt;/P&gt;&lt;P&gt;Should it work?&lt;/P&gt;&lt;P&gt;Firewalls are R80.40 Take 173 with plans to go to R81.10 when the next hotfix is GA.&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 11:02:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159233#M27851</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2022-10-11T11:02:33Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Sharing and Cisco ISE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159248#M27858</link>
      <description>&lt;P&gt;You could use&amp;nbsp;&lt;SPAN&gt;Identity Broker, see:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk88520&amp;amp;partition=Basic&amp;amp;product=Identity" target="_blank"&gt;sk88520: Best Practices - &lt;STRONG&gt;Identity&lt;/STRONG&gt; &lt;STRONG&gt;Awareness&lt;/STRONG&gt; Large Scale Deployment&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk170765&amp;amp;partition=Advanced&amp;amp;product=Identity" target="_blank"&gt;sk170765: &lt;STRONG&gt;Identity&lt;/STRONG&gt; Awareness Scalable Design - &lt;STRONG&gt;Identity&lt;/STRONG&gt; Agent&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk86441&amp;amp;partition=Advanced&amp;amp;product=Identity" target="_blank"&gt;sk86441: ATRG: &lt;STRONG&gt;Identity&lt;/STRONG&gt; &lt;STRONG&gt;Awareness&lt;/STRONG&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;STRONG&gt;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk146835&amp;amp;partition=Basic&amp;amp;product=Identity" target="_blank"&gt;sk146835: Identity Session Conciliation&lt;/A&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Oct 2022 13:12:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159248#M27858</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-10-11T13:12:21Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Sharing and Cisco ISE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159323#M27872</link>
      <description>&lt;P&gt;For now the solution is to connect the Identity Collector to each gateway, effectively turning them into PDP so the broker would be a more complex way to do the same.&lt;/P&gt;&lt;P&gt;The idea is to have a low-end cluster serving as PDP for the ISE tags and sending them to all other gateways but it seems that nothing happens with tags when this is configured.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 08:05:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159323#M27872</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2022-10-12T08:05:51Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Sharing and Cisco ISE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159327#M27875</link>
      <description>&lt;P&gt;hey,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as we have deployed also IC in our environment, to grab identities from AD and ISE (TAGS), my recommendation is to have at least 2 IC's per GW/Cluster for redundancy. in our case, as we have 3 clusters, we have set 6 IC's, 2 per each region - so we have redundancy and independency.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;as for identity sharing, as I know you can configure a GW to share identities with all other GWs - so what is not working in your case ?&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18102i85B1176FBAAA4DFD/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you,&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 08:37:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159327#M27875</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-10-12T08:37:30Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Sharing and Cisco ISE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159328#M27876</link>
      <description>&lt;P&gt;I'm using 2 Identity Collectors for redundancy. I had to get a custom JAR file to ensure stability between them and the ISE but since then it works.&lt;/P&gt;&lt;P&gt;Whenever I enable Identity Sharing, tags don't seem to get exchanged. I'm just wondering if they should be or if this feature does not support ISE tags.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 08:46:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159328#M27876</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2022-10-12T08:46:26Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Sharing and Cisco ISE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159332#M27878</link>
      <description>&lt;P&gt;"&lt;SPAN&gt;I had to get a custom JAR file to ensure stability between them and the ISE but since then it works.&lt;/SPAN&gt;" - can you elaborate on this a bit more, as I have a problem with IC versions over R80.0119.000 (new ones uses pxGrid v2) and our ISE environment - looses communication after random periods.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In regards to the shared identity, I doubt it will share the ISE TAG, but I think it will share the identity group that the TAG was matched to.&lt;/P&gt;
&lt;P&gt;can you check that part, and have a rule with an identity ISE TAG base on an GW that gets identities from another gateway ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you,&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 09:31:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159332#M27878</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-10-12T09:31:23Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Sharing and Cisco ISE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159334#M27879</link>
      <description>&lt;P&gt;That was quite a long case with TAC about the ISE going to Disconnected mode in the Collector and not coming back up short of a reboot of the server, not just the service.&lt;/P&gt;&lt;P&gt;In the end, I got a custom JAR file to replace one in place which completely solved the issue.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 09:38:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159334#M27879</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2022-10-12T09:38:05Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Sharing and Cisco ISE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159336#M27880</link>
      <description>&lt;P&gt;So I see the same, with newer IC versions, the ISE connections go in Established and data is exchanged, but after 1 hour or 3 hours, they go Disconnected.&lt;/P&gt;
&lt;P&gt;In some cases if I restart the service it's coming back but the same will happen in couple of hours, or it's staying Disconnected.&lt;/P&gt;
&lt;P&gt;Is it possible to share the CheckPoint case so I can ask my support engineer look and see if there is any resemblance between them?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you,&lt;/P&gt;
&lt;P&gt;PS: were the versions I share behaving the same, or you don't remember the details ?&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 09:43:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159336#M27880</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-10-12T09:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Sharing and Cisco ISE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159341#M27881</link>
      <description>&lt;P&gt;I will send you the SR in a private message. What happened is that a message from the ISE wouldn't be accepted by the IC because of some unsupported content, after which the IC would disconnect the ISE and keep on sending keepalives without ever reconnecting. This could happen after an hour or a week, there was no definitive pattern.&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 10:21:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159341#M27881</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2022-10-12T10:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Sharing and Cisco ISE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159342#M27882</link>
      <description>&lt;P&gt;thank you,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;now on the Identity Sharing, check this and let us know how it goes...&lt;/P&gt;
&lt;P&gt;"In regards to the shared identity, I doubt it will share the ISE TAG, but I think it will share the identity group that the TAG was matched to.&lt;/P&gt;
&lt;P&gt;can you check that part, and have a rule with an identity ISE TAG base on an GW that gets identities from another gateway ?"&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;ty,&lt;/P&gt;</description>
      <pubDate>Wed, 12 Oct 2022 10:24:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159342#M27882</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-10-12T10:24:16Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Sharing and Cisco ISE</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159572#M27963</link>
      <description>&lt;P&gt;Once identities are acquired, they can be shared with other gateways.&lt;BR /&gt;That said, you might need to (manually) create the relevant identity tags on the Check Point side, but that's just a guess.&lt;/P&gt;</description>
      <pubDate>Fri, 14 Oct 2022 15:35:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Sharing-and-Cisco-ISE/m-p/159572#M27963</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-10-14T15:35:54Z</dc:date>
    </item>
  </channel>
</rss>

