<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD UPN Suffix in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-UPN-Suffix/m-p/197721#M36935</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I do realise that this reply is almost 4 years in the making but this nuance continues to plague us. We managed to work around the issue but have a situation where this work around unfortunately doesn't work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem with using Identity Collector is that it exclusively retrieves events from AD servers. We wish to use RADIUS with PacketFence or Aruba ClearPass, integrating with CheckPoint via either RADIUS accounting or Identity Awareness API. In those cases the user identity lands on the gateway, especially when using EAP-TLS which doesn't need to interact with AD at all when validating the validity of the presented certificate.&lt;BR /&gt;&lt;BR /&gt;Our work around up until now has been to strip the realm from the username before it's sent, CheckPoint submits this to AD for group membership queries and authentication but this causes a problem when a username is longer than 20 characters. In that case AD matches the account against the pre-Windows 2000 username, which is often just the truncated version of the UPN.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;What is the recommended method by which one can facilitate UPN suffix aliases in Active Directory?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;David Herselman&lt;/P&gt;</description>
    <pubDate>Fri, 10 Nov 2023 15:47:42 GMT</pubDate>
    <dc:creator>David_Herselman</dc:creator>
    <dc:date>2023-11-10T15:47:42Z</dc:date>
    <item>
      <title>AD UPN Suffix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-UPN-Suffix/m-p/79453#M11436</link>
      <description>&lt;P&gt;We have Identity Awareness configured and working with AD Query, Captive Portal (including Kerberos SSO), Terminal Services MuH and RADIUS for Enterprise WiFi (Packet Fence).&lt;/P&gt;&lt;P&gt;We however have problems with user accounts where their Active Directory UPN Suffix was changed as this then no longer matches the domain in the LDAP Account Unit.&lt;/P&gt;&lt;P&gt;What is the official way to configure additional UPN Suffixes?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What we've done so far:&lt;/P&gt;&lt;P&gt;Created additional LDAP Account Units, referencing the same AD servers, credentials and LDAP branch as the one for the AD realm but then unset 'User management' and 'AD Query'.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Problem is that RDS (Terminal Services) MuH agent uses Kerberos to identify users and identifies the person as user@upnsuffix2 but then doesn't resolve group memberships.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The account is technically party of the main/original LDAP Account Unit, is there no way to configure UPN suffix aliases?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;adlogconfig a gives an option relating to 'add domain' but I'm unable to locate documentation relating to this...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;David Herselman&lt;/P&gt;</description>
      <pubDate>Tue, 24 Mar 2020 06:17:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-UPN-Suffix/m-p/79453#M11436</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2020-03-24T06:17:14Z</dc:date>
    </item>
    <item>
      <title>Re: AD UPN Suffix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-UPN-Suffix/m-p/79629#M11437</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;any idea?&lt;/P&gt;</description>
      <pubDate>Wed, 25 Mar 2020 04:11:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-UPN-Suffix/m-p/79629#M11437</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-25T04:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: AD UPN Suffix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-UPN-Suffix/m-p/80112#M11438</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/9832"&gt;@David_Herselman&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Generally, I will recommend using Identity Collector and not AD Query&lt;/P&gt;
&lt;P&gt;You can read about the differences in sk108235.&lt;/P&gt;
&lt;P&gt;In Identity Collector, you also have "alias" feature to replace domain suffixes easily.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I hope it helps!&lt;/P&gt;
&lt;P&gt;Royi Priov&lt;/P&gt;
&lt;P&gt;Identity Awareness R&amp;amp;D&lt;/P&gt;</description>
      <pubDate>Sun, 29 Mar 2020 14:35:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-UPN-Suffix/m-p/80112#M11438</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2020-03-29T14:35:03Z</dc:date>
    </item>
    <item>
      <title>Re: AD UPN Suffix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-UPN-Suffix/m-p/149801#M24052</link>
      <description>&lt;P&gt;&lt;SPAN&gt;sk87200&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 31 May 2022 08:36:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-UPN-Suffix/m-p/149801#M24052</guid>
      <dc:creator>gardazishvili</dc:creator>
      <dc:date>2022-05-31T08:36:20Z</dc:date>
    </item>
    <item>
      <title>Re: AD UPN Suffix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-UPN-Suffix/m-p/175863#M32116</link>
      <description>&lt;P&gt;This worked for me.&lt;BR /&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Thu, 23 Mar 2023 07:29:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-UPN-Suffix/m-p/175863#M32116</guid>
      <dc:creator>Henrik_J</dc:creator>
      <dc:date>2023-03-23T07:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: AD UPN Suffix</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-UPN-Suffix/m-p/197721#M36935</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I do realise that this reply is almost 4 years in the making but this nuance continues to plague us. We managed to work around the issue but have a situation where this work around unfortunately doesn't work.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The problem with using Identity Collector is that it exclusively retrieves events from AD servers. We wish to use RADIUS with PacketFence or Aruba ClearPass, integrating with CheckPoint via either RADIUS accounting or Identity Awareness API. In those cases the user identity lands on the gateway, especially when using EAP-TLS which doesn't need to interact with AD at all when validating the validity of the presented certificate.&lt;BR /&gt;&lt;BR /&gt;Our work around up until now has been to strip the realm from the username before it's sent, CheckPoint submits this to AD for group membership queries and authentication but this causes a problem when a username is longer than 20 characters. In that case AD matches the account against the pre-Windows 2000 username, which is often just the truncated version of the UPN.&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;What is the recommended method by which one can facilitate UPN suffix aliases in Active Directory?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;
&lt;P&gt;David Herselman&lt;/P&gt;</description>
      <pubDate>Fri, 10 Nov 2023 15:47:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-UPN-Suffix/m-p/197721#M36935</guid>
      <dc:creator>David_Herselman</dc:creator>
      <dc:date>2023-11-10T15:47:42Z</dc:date>
    </item>
  </channel>
</rss>

