<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: New IA Implementation in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185841#M34181</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Can you share me the SK or WEB from where I could download the Identity Collector, please.&lt;/P&gt;
&lt;P&gt;In addition to this, I understand that this application does not need to be installed in the same Windows Server we have, but in any station with privileges, certain ????&lt;/P&gt;
&lt;P&gt;When activating the AI blade in the Cluster object from my SmartConsole, in order to work with the Identity Collector, I must select the option that I show in the image, correct?&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IA.png" style="width: 861px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21680iC98664F4972C46D4/image-size/large?v=v2&amp;amp;px=999" role="button" title="IA.png" alt="IA.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;</description>
    <pubDate>Thu, 06 Jul 2023 17:31:55 GMT</pubDate>
    <dc:creator>Matlu</dc:creator>
    <dc:date>2023-07-06T17:31:55Z</dc:date>
    <item>
      <title>New IA Implementation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185789#M34165</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;One query, please.&lt;/P&gt;
&lt;P&gt;Due to customer need, we require to implement the AI blade.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The customer has a quite large network (More than 2000 users).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I understand that there are 2 ways to integrate the Windows Server AD, by the AD Query / Identity Collector (correct me if I am wrong please).&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I understand that the viable method for us would be to install some application in the same AD Windows Server.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I understand that this application is called IDENTITY COLLECTOR, right?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If my comment is true, downloading and installing this application, is it free or is it required to make a purchase from Checkpoint?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are end users going to have to be forced to install some application on their computers?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 12:56:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185789#M34165</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-06T12:56:36Z</dc:date>
    </item>
    <item>
      <title>Re: New IA Implementation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185797#M34167</link>
      <description>&lt;P&gt;Identity Collector can be installed on a Window machine in the same domain doesn't have to be the DC, no cost is involved specific to the collector.&lt;/P&gt;
&lt;P&gt;Identity agents for the client PCs are not mandatory but will operate more effectively in some scenarios.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 13:35:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185797#M34167</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-07-06T13:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: New IA Implementation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185806#M34171</link>
      <description>&lt;P&gt;Hi Matlu,&lt;/P&gt;
&lt;P&gt;Identity Collector is absolutely the way to go, AD Query is being deprecated, and in fact you have to jump through hoops to get that working nowadays.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You don't need to install it on a DC, a member server is fine.&amp;nbsp; An active support contract will entitle you to the download, there is no separate charge.&lt;/P&gt;
&lt;P&gt;There is an client that you can install on a client, but it should not be necessary from what I can see (in fact it's not necessary for the vast majority of use cases in my experience).&lt;/P&gt;
&lt;P&gt;Thanks,&lt;BR /&gt;Ruan&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 13:57:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185806#M34171</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2023-07-06T13:57:40Z</dc:date>
    </item>
    <item>
      <title>Re: New IA Implementation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185841#M34181</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Can you share me the SK or WEB from where I could download the Identity Collector, please.&lt;/P&gt;
&lt;P&gt;In addition to this, I understand that this application does not need to be installed in the same Windows Server we have, but in any station with privileges, certain ????&lt;/P&gt;
&lt;P&gt;When activating the AI blade in the Cluster object from my SmartConsole, in order to work with the Identity Collector, I must select the option that I show in the image, correct?&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IA.png" style="width: 861px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21680iC98664F4972C46D4/image-size/large?v=v2&amp;amp;px=999" role="button" title="IA.png" alt="IA.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 17:31:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185841#M34181</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-06T17:31:55Z</dc:date>
    </item>
    <item>
      <title>Re: New IA Implementation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185845#M34182</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;Once IA blade is enabled, dont even bother going through the wizard, just cancel it, make sure blade shows as on and you can download collected from below option, just make sure its checked.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21681i8D21FD98949A5160/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt; &lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/Identity-Sources-Identity-Collector.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/Identity-Sources-Identity-Collector.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 17:39:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185845#M34182</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-06T17:39:55Z</dc:date>
    </item>
    <item>
      <title>Re: New IA Implementation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185848#M34183</link>
      <description>&lt;P&gt;All the various Identity Awareness clients (including Collector) are linked here:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk134312" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk134312&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 17:59:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185848#M34183</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-06T17:59:15Z</dc:date>
    </item>
    <item>
      <title>Re: New IA Implementation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185851#M34184</link>
      <description>&lt;P&gt;Hi, Bro.&lt;/P&gt;
&lt;P&gt;The customer has serious doubts in implementing the agent.&lt;/P&gt;
&lt;P&gt;Is it still feasible to use the AD Query mode, for a number of approx. 4k users?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 18:22:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185851#M34184</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-06T18:22:44Z</dc:date>
    </item>
    <item>
      <title>Re: New IA Implementation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185852#M34185</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;You can do that, but please show them below. We had few customers with same concern and now they are so happy they went with collector and they are actually bit upset they had not done it sooner.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics/Identity-Collector.htm?Highlight=collector" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics/Identity-Collector.htm?Highlight=collector&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;These are the benefits of using Identity Collector instead of a standard AD QueryClosed:&lt;/P&gt;
&lt;P&gt;Reduced load on the Security Gateway - Identity Collector does the queries instead of the Security Gateway&lt;/P&gt;
&lt;P&gt;Reduced load on the Domain Controller (DC) - the native Windows API consumes fewer resources&lt;/P&gt;
&lt;P&gt;Lower permissions required - Identity Collector requires read-only access to the domain security logs&lt;/P&gt;
&lt;P&gt;No changes are required in the Active Directory (AD) schema.&lt;/P&gt;
&lt;P&gt;One Identity Collector can serve multiple Security Gateways, even from a different Domain Management Servers on a Multi-Domain ServerClosed.&lt;/P&gt;
&lt;P&gt;Identity Collector can communicate with a maximum of up to 35 Active Directory (AD) servers.&lt;/P&gt;
&lt;P&gt;Identity Collector can process a maximum of 1900 Active Directory (AD) events per second.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 18:31:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185852#M34185</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-06T18:31:56Z</dc:date>
    </item>
    <item>
      <title>Re: New IA Implementation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185854#M34186</link>
      <description>&lt;P&gt;Andy,&lt;/P&gt;
&lt;P&gt;I will try to persuade the client, even if he is a bit "inane", and well, I have not implemented the agent before, so I am "reading the documentation".&lt;/P&gt;
&lt;P&gt;Could you comment me, which is the option of the agent, that should be downloaded in our case, for a Windows Server 2019 to more, please????&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IA2.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/21682iC30A5AD044957A8D/image-size/large?v=v2&amp;amp;px=999" role="button" title="IA2.png" alt="IA2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;What leaves me doubts in the documentation, is if only enough to install the agent on the server and already, or is that I will have to install other agents separately, other agents on each machine of each user ...&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 18:39:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185854#M34186</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-06T18:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: New IA Implementation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185855#M34187</link>
      <description>&lt;P&gt;I would not do ANY new deployments with AD Query at this point.&lt;BR /&gt;First of all, AD Query causes additional load on the AD server.&lt;BR /&gt;With 4k users, this might be noticeable.&lt;BR /&gt;Second, due to various security vulnerabilities in WMI, Microsoft has and continues to make changes, some of which have broken AD Query.&lt;BR /&gt;Currently, using fully patched AD servers, AD Query can only be implemented using an account with Domain Admin credentials.&lt;/P&gt;
&lt;P&gt;Meanwhile, Identity Collector:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Is significantly more scalable&lt;/LI&gt;
&lt;LI&gt;Only requires an account that can read Security Logs from Active Directory&lt;/LI&gt;
&lt;LI&gt;Is the recommended solution&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 06 Jul 2023 18:42:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185855#M34187</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-06T18:42:14Z</dc:date>
    </item>
    <item>
      <title>Re: New IA Implementation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185856#M34188</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk134312" target="_self"&gt;The SK I referred to earlier&lt;/A&gt; explains what each agent is for.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 18:46:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185856#M34188</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-07-06T18:46:13Z</dc:date>
    </item>
    <item>
      <title>Re: New IA Implementation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185857#M34189</link>
      <description>&lt;P&gt;Just install the collector (first one in the list), though one I gave you from last screenshot works even on windows 11 (tried it myself in the lab). Then, once installed, I attached some screenshots of what you need to do.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 18:48:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185857#M34189</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-06T18:48:22Z</dc:date>
    </item>
    <item>
      <title>Re: New IA Implementation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185858#M34190</link>
      <description>&lt;P&gt;Btw,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;explained it PERFECTLY. And trust me, hes been around CP almost since the beginning, so if you should listen to anyone, its him...just saying : - )&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 18:50:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185858#M34190</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-06T18:50:45Z</dc:date>
    </item>
    <item>
      <title>Re: New IA Implementation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185873#M34193</link>
      <description>&lt;P&gt;Thank you for the clarification.&lt;/P&gt;
&lt;P&gt;I think the best option is to make a lab for this.&lt;/P&gt;
&lt;P&gt;I will try to replicate the scenario I need for our client.&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 21:59:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185873#M34193</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-07-06T21:59:46Z</dc:date>
    </item>
    <item>
      <title>Re: New IA Implementation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185874#M34194</link>
      <description>&lt;P&gt;Lab is always best bro &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 06 Jul 2023 22:22:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/New-IA-Implementation/m-p/185874#M34194</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-07-06T22:22:07Z</dc:date>
    </item>
  </channel>
</rss>

