<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Check Point Identity Collector - Windows Server firewall Permisoins in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Collector-Windows-Server-firewall/m-p/242664#M47142</link>
    <description>&lt;P&gt;I can agree. Just bc it is internal communication between DC and IC, any any policy with specified source and destination will do a job.&lt;/P&gt;</description>
    <pubDate>Fri, 28 Feb 2025 14:05:06 GMT</pubDate>
    <dc:creator>freeman91</dc:creator>
    <dc:date>2025-02-28T14:05:06Z</dc:date>
    <item>
      <title>Check Point Identity Collector - Windows Server firewall Permisoins</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Collector-Windows-Server-firewall/m-p/242638#M47129</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;I looked at all the threads related to Identity Collector, as well as the documentation for deploing Identity Collector and like other, I also have had a problem until I turned off firewall on windows server.&lt;/P&gt;&lt;P&gt;This is enough for me just to check if there is a connection issue to DC other then firewall. Now I want to turn on the firewall and allow only what is necessary.&amp;nbsp;&lt;BR /&gt;Are anyone here is willing to share setup of its windows firewall in case where its firewall is turned on, and connection with IC is green &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Far now, I allowed only those 7 DCOM 135 rules&amp;nbsp;&amp;nbsp;but it is not enough.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29748i1DB33E4B54EC239C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 10:11:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Collector-Windows-Server-firewall/m-p/242638#M47129</guid>
      <dc:creator>freeman91</dc:creator>
      <dc:date>2025-02-28T10:11:55Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Identity Collector - Windows Server firewall Permisoins</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Collector-Windows-Server-firewall/m-p/242644#M47131</link>
      <description>&lt;P&gt;HTTPS, DCOM, RPC, LDAP, DNS are needed depending on the server role.&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Clients-AG/Identity-Collector-Requirements.htm?tocpath=Identity%20Collector%7C_____1" target="_blank" rel="noopener"&gt;https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Clients-AG/Identity-Collector-Requirements.htm?tocpath=Identity%20Collector%7C_____1&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 11:36:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Collector-Windows-Server-firewall/m-p/242644#M47131</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-02-28T11:36:32Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Identity Collector - Windows Server firewall Permisoins</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Collector-Windows-Server-firewall/m-p/242656#M47137</link>
      <description>&lt;P&gt;Can you assist me how does this rule looks like in firewall policy:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;Add "Allow"&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A class="" href="https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Clients-AG/Identity-Collector-Requirements.htm?tocpath=Identity%20Collector%7C_____1#" target="_blank" rel="noopener"&gt;rule&lt;/A&gt;&lt;/P&gt;&lt;SPAN&gt;Remote Event Log Management &amp;gt; Remote Event Log Management (RPC)&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;</description>
      <pubDate>Fri, 28 Feb 2025 13:10:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Collector-Windows-Server-firewall/m-p/242656#M47137</guid>
      <dc:creator>freeman91</dc:creator>
      <dc:date>2025-02-28T13:10:54Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Identity Collector - Windows Server firewall Permisoins</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Collector-Windows-Server-firewall/m-p/242659#M47138</link>
      <description>&lt;P&gt;I just add a rule that says from fw to IC (bi-directionally), allow on any port, thats it.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 13:35:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Collector-Windows-Server-firewall/m-p/242659#M47138</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T13:35:27Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Identity Collector - Windows Server firewall Permisoins</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Collector-Windows-Server-firewall/m-p/242661#M47139</link>
      <description>&lt;P&gt;Ok, I can accept that as a good workaround solution.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 13:59:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Collector-Windows-Server-firewall/m-p/242661#M47139</guid>
      <dc:creator>freeman91</dc:creator>
      <dc:date>2025-02-28T13:59:27Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Identity Collector - Windows Server firewall Permisoins</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Collector-Windows-Server-firewall/m-p/242663#M47141</link>
      <description>&lt;P&gt;Glad we can help. Btw, since we all do IT security here, goes without saying ports should always be indicated whenever possible, but at the end of the day, this is just internal communication, so I dont find it would be a huge deal...just my 2 cents.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 14:01:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Collector-Windows-Server-firewall/m-p/242663#M47141</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T14:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Identity Collector - Windows Server firewall Permisoins</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Collector-Windows-Server-firewall/m-p/242664#M47142</link>
      <description>&lt;P&gt;I can agree. Just bc it is internal communication between DC and IC, any any policy with specified source and destination will do a job.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 14:05:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Collector-Windows-Server-firewall/m-p/242664#M47142</guid>
      <dc:creator>freeman91</dc:creator>
      <dc:date>2025-02-28T14:05:06Z</dc:date>
    </item>
    <item>
      <title>Re: Check Point Identity Collector - Windows Server firewall Permisoins</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Collector-Windows-Server-firewall/m-p/242665#M47143</link>
      <description>&lt;P&gt;Though you can always follow what Chris gave, its an official reference.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 28 Feb 2025 14:08:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Check-Point-Identity-Collector-Windows-Server-firewall/m-p/242665#M47143</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-02-28T14:08:19Z</dc:date>
    </item>
  </channel>
</rss>

