<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD Query vs Identity Collector in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-vs-Identity-Collector/m-p/245652#M47862</link>
    <description>&lt;P&gt;To add, here are the pro's of the IDC:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Reduced load on the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Clients-AG/Identity-Collector.htm?tocpath=Identity%20Collector%7C_____0#" data-mc-state="closed" data-aria-describedby="c60c94eb-2a72-4fc0-9c28-ba70a1da3a33" target="_blank"&gt;Security Gateway -&amp;nbsp;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;I&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ida_collector variable"&gt;dentity Collector&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;does the queries instead of the&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN&gt;Reduced load on the Domain Controller (DC) - the native Windows API consumes fewer resources&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Lower permissions required -&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ida_collector variable"&gt;Identity Collector&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;requires read-only access to the domain security logs&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;No changes are required in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_active_directory variable"&gt;Active Directory&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(AD) schema.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;One&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ida_collector variable"&gt;Identity Collector&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;can serve multiple&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgates variable"&gt;Security Gateways&lt;/SPAN&gt;, even from a different&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_dmss variable"&gt;Domain Management Servers&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_mds variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Clients-AG/Identity-Collector.htm?tocpath=Identity%20Collector%7C_____0#" data-mc-state="closed" data-aria-describedby="c11cb361-d463-467f-93f3-4cc452ebefcc" target="_blank"&gt;Multi-Domain Server&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ida_collector variable"&gt;Identity Collector&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;can communicate with a maximum of up to 35&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_active_directory variable"&gt;Active Directory&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(AD) servers.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ida_collector variable"&gt;Identity Collector&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;can process a maximum of 1900&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_active_directory variable"&gt;Active Directory&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(AD) events per second.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Thu, 03 Apr 2025 21:09:09 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2025-04-03T21:09:09Z</dc:date>
    <item>
      <title>AD Query vs Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-vs-Identity-Collector/m-p/245541#M47847</link>
      <description>&lt;P&gt;Hello guys&lt;/P&gt;&lt;P&gt;AD Query has this limitation:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;P&gt;&lt;SPAN class=""&gt;Many user accounts connected from the same IP address&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;-&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;AD Query&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;cannot detect when a user logs out. Therefore, more than one user can have open sessions from the same IP address. When this occurs, the permissions for each account stay active until their&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class=""&gt;User/IP association timeout&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;occurs. In this scenario, there is a risk that currently connected users can get access to network resources, for which they do not have permissions.&lt;/P&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Does Identity Collector share this limitation? If not, how does it solve this?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 07:32:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-vs-Identity-Collector/m-p/245541#M47847</guid>
      <dc:creator>shauls</dc:creator>
      <dc:date>2025-04-03T07:32:54Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query vs Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-vs-Identity-Collector/m-p/245555#M47853</link>
      <description>&lt;P&gt;IDC also has the same limitation, stemming from the same place - there's no 'log out' event in AD for us to read. To know when a session has ended, we need to be reading from an agent on the machine, either the multi-user host agent on terminal servers or the regular agent on PCs.&lt;/P&gt;
&lt;P&gt;This can be mitigated on single-user PCs by enabling the 'assume one user per host' option that will end the user association to an IP address when a new user is associated with it.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 11:07:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-vs-Identity-Collector/m-p/245555#M47853</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-04-03T11:07:05Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query vs Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-vs-Identity-Collector/m-p/245556#M47854</link>
      <description>&lt;P&gt;See if below discussion helps, lots of things were discussed here.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/New-IA-Implementation/m-p/185851#M34184" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/New-IA-Implementation/m-p/185851#M34184&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 11:09:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-vs-Identity-Collector/m-p/245556#M47854</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-04-03T11:09:32Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query vs Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-vs-Identity-Collector/m-p/245558#M47855</link>
      <description>&lt;P&gt;In general there are certain scenarios that can only be solved entirely with the Identity Agent, with that said Identity Collector is preferred over the legacy ADquery method for several reasons.&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 11:11:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-vs-Identity-Collector/m-p/245558#M47855</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2025-04-03T11:11:43Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query vs Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-vs-Identity-Collector/m-p/245561#M47856</link>
      <description>&lt;P&gt;I see this option.&lt;/P&gt;&lt;P&gt;I have this option on both Security Gateway and Security Management Server, what are the differences?&lt;/P&gt;</description>
      <pubDate>Thu, 03 Apr 2025 11:47:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-vs-Identity-Collector/m-p/245561#M47856</guid>
      <dc:creator>shauls</dc:creator>
      <dc:date>2025-04-03T11:47:44Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query vs Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-vs-Identity-Collector/m-p/245652#M47862</link>
      <description>&lt;P&gt;To add, here are the pro's of the IDC:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;
&lt;P&gt;Reduced load on the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Clients-AG/Identity-Collector.htm?tocpath=Identity%20Collector%7C_____0#" data-mc-state="closed" data-aria-describedby="c60c94eb-2a72-4fc0-9c28-ba70a1da3a33" target="_blank"&gt;Security Gateway -&amp;nbsp;&lt;/A&gt;&lt;/SPAN&gt;&lt;SPAN&gt;I&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ida_collector variable"&gt;dentity Collector&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;does the queries instead of the&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgate variable"&gt;Security Gateway&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN&gt;Reduced load on the Domain Controller (DC) - the native Windows API consumes fewer resources&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;Lower permissions required -&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ida_collector variable"&gt;Identity Collector&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;requires read-only access to the domain security logs&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;No changes are required in the&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_active_directory variable"&gt;Active Directory&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(AD) schema.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;One&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ida_collector variable"&gt;Identity Collector&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;can serve multiple&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_sgates variable"&gt;Security Gateways&lt;/SPAN&gt;, even from a different&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_dmss variable"&gt;Domain Management Servers&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;on a&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_mds variable"&gt;&lt;A class="MCTextPopup MCTextPopupHotSpot MCTextPopupHotSpot_ #text MCTextPopup_Closed" role="button" href="https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Clients-AG/Identity-Collector.htm?tocpath=Identity%20Collector%7C_____0#" data-mc-state="closed" data-aria-describedby="c11cb361-d463-467f-93f3-4cc452ebefcc" target="_blank"&gt;Multi-Domain Server&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ida_collector variable"&gt;Identity Collector&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;can communicate with a maximum of up to 35&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_active_directory variable"&gt;Active Directory&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(AD) servers.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;
&lt;P&gt;&lt;SPAN class="mc-variable Vars_BladesFeatures.tp_ida_collector variable"&gt;Identity Collector&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;can process a maximum of 1900&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mc-variable Vars_Other.tp_active_directory variable"&gt;Active Directory&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;(AD) events per second.&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Thu, 03 Apr 2025 21:09:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-vs-Identity-Collector/m-p/245652#M47862</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2025-04-03T21:09:09Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query vs Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-vs-Identity-Collector/m-p/245663#M47866</link>
      <description>&lt;P&gt;Not sure if you meant to add a screenshot or something there, which option are you referring to?&lt;/P&gt;</description>
      <pubDate>Fri, 04 Apr 2025 03:34:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-vs-Identity-Collector/m-p/245663#M47866</guid>
      <dc:creator>emmap</dc:creator>
      <dc:date>2025-04-04T03:34:34Z</dc:date>
    </item>
  </channel>
</rss>

