<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP Account Unit in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207198#M65827</link>
    <description>&lt;P&gt;Wow I didn't know that! Really thanks a lot for all of your time it helped me a lot!&lt;/P&gt;</description>
    <pubDate>Mon, 26 Feb 2024 17:27:26 GMT</pubDate>
    <dc:creator>Unon</dc:creator>
    <dc:date>2024-02-26T17:27:26Z</dc:date>
    <item>
      <title>LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207092#M65807</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Recently I started messing around with identity awareness with Identity Collector.&lt;/P&gt;&lt;P&gt;I've seen in the admin guide that ldap account unit is required, but when I created an object for it I didn't find how to associate it with the gateway. On other deployment done before me I can see the ldap account unit used within the gateway and that's what I'm trying to understand. Can you please help?&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2024 10:28:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207092#M65807</guid>
      <dc:creator>Unon</dc:creator>
      <dc:date>2024-02-25T10:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207095#M65808</link>
      <description>&lt;P&gt;Is this not in the wizard when you enable Identity blade under the gateway object?&lt;/P&gt;
&lt;P&gt;From my mind you have to connect with ad there correct?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2024 11:19:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207095#M65808</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-02-25T11:19:59Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207096#M65809</link>
      <description>&lt;P&gt;In the wizard there is a part where you configure what AD you query and it uses the account unit. Yet when I want to see where the account unit is used I see nothing. In the other deployment when you view where it's used you can see it used in the identity aware fw&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2024 12:32:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207096#M65809</guid>
      <dc:creator>Unon</dc:creator>
      <dc:date>2024-02-25T12:32:46Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207100#M65810</link>
      <description>&lt;P&gt;You created already LDAP account unit? If so, can you fetch the branches?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2024 15:29:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207100#M65810</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-25T15:29:25Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207113#M65811</link>
      <description>&lt;P&gt;No I can't but still the account unit should be associated with the gateway isn't it? And moreover let's say I want to get identities from multiple ADs how can I associate more than one if I can only add via the identity awareness wizard?&lt;/P&gt;&lt;P&gt;Essentially I try to find an easy way to associate ldap account unit to a gateway. I wanted to start from the easiest part and than try more harder scenarios.&lt;/P&gt;&lt;P&gt;But thanks you helped me understand some things&lt;/P&gt;</description>
      <pubDate>Sun, 25 Feb 2024 18:53:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207113#M65811</guid>
      <dc:creator>Unon</dc:creator>
      <dc:date>2024-02-25T18:53:51Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207116#M65812</link>
      <description>&lt;P&gt;Yes, 100% is HAS TO BE associated with the gateway. Put it this way...identity collector changes how the gateway will "get" the users, so its via the logs instead of WMI, BUT, it still has to pull the groups via LDAP account unit, regardless if you use IC or not.&lt;/P&gt;
&lt;P&gt;Makes sense?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 00:10:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207116#M65812</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-26T00:10:05Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207123#M65813</link>
      <description>&lt;P&gt;It does make sense and now I understand more but I'm still confused about why I can't see the ldap account unit associated with the gateway and now that I know it is supposed to be associated via the identity awareness wizard I don't understand how to associate multiple ldap account unit with the same gateway?&lt;/P&gt;&lt;P&gt;I would believe that it's more simple than I imagine but currently I can't find how to do it.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 08:46:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207123#M65813</guid>
      <dc:creator>Unon</dc:creator>
      <dc:date>2024-02-26T08:46:14Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207135#M65814</link>
      <description>&lt;P&gt;Relevant FW object -&amp;gt; Identity Awareness -&amp;gt; Identity Collector Settings -&amp;gt; Settings -&amp;gt; Specific (in here you can select what account unit this firewall can read).&lt;BR /&gt;Default is all, so ALL configured account units.&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 12:10:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207135#M65814</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-02-26T12:10:38Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207143#M65815</link>
      <description>&lt;P&gt;Ok, lets take step back. Please confirm.&lt;/P&gt;
&lt;P&gt;1) Is LDAP account unit created?&lt;/P&gt;
&lt;P&gt;2) If so, do you have all servers configured needed?&lt;/P&gt;
&lt;P&gt;and&amp;nbsp;&lt;/P&gt;
&lt;P&gt;3) If yes to both 1 and 2, can you fetch the branches?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 12:39:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207143#M65815</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-26T12:39:32Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207145#M65816</link>
      <description>&lt;P&gt;Yes to 1 and 2 no on the 3 maybe because I missed something in the server configuration or networking problems I'm gonna fix later. Is that the problem? shouldn't the ldap account unit be associated with the gateway anyway wether it works or not? When I say associate I mean that if I see where it's used&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 12:47:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207145#M65816</guid>
      <dc:creator>Unon</dc:creator>
      <dc:date>2024-02-26T12:47:15Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207146#M65817</link>
      <description>&lt;P&gt;Well, if thats the case, it will never work sadly. Can you communicate with the server from the fw itself? Did you make sure rule allows it? See, if unit is there, thats fantastic, BUT, if the communication is failing, then its not very useful. The only time fetching the branches would not work is if you use S1C instance, because thats expected, otherwise, if its on-prem, it has to work, for sure. Can you ping the fw from the AD at all?&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 12:52:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207146#M65817</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-26T12:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207147#M65818</link>
      <description>&lt;P&gt;No currently I have networking problems so I wanted to start by first configure everything on the gateway side and than tackling the problems. I understand from you that it's impossible to do it that way so I will work to fix these issues and see if things are improving&lt;/P&gt;&lt;P&gt;Thanks a lot for your help!&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 12:59:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207147#M65818</guid>
      <dc:creator>Unon</dc:creator>
      <dc:date>2024-02-26T12:59:06Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207149#M65819</link>
      <description>&lt;P&gt;No problem at all. By the way, as a side note, I would NOT use ad query, opt out for AD instead. See great discussion in below post.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/New-IA-Implementation/m-p/185851#M34184" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/New-IA-Implementation/m-p/185851#M34184&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 13:22:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207149#M65819</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-26T13:22:21Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207190#M65820</link>
      <description>&lt;P&gt;Thanks for the reference!&lt;/P&gt;&lt;P&gt;I read it a bit and I have a question out of curiosity. Let's say I want to implement identity awareness by using an Identity collector. Am I required to create ldap account unit? From what you cited seems like it's not a necessity but in some documentations it's seems like it is for reading logs. I'm trying to understand how to properly implement IA according to the best practice&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 16:37:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207190#M65820</guid>
      <dc:creator>Unon</dc:creator>
      <dc:date>2024-02-26T16:37:20Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207191#M65821</link>
      <description>&lt;P&gt;ldap account unit has to be there...thats how groups are pulled. You can uncheck ad query setting and simply have ic on.&lt;/P&gt;
&lt;P&gt;I will send you screenshot later.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 16:42:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207191#M65821</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-26T16:42:07Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207192#M65822</link>
      <description>&lt;P&gt;Ok thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 16:52:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207192#M65822</guid>
      <dc:creator>Unon</dc:creator>
      <dc:date>2024-02-26T16:52:49Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207194#M65823</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24644i8787DDDF528BE1A8/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 16:53:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207194#M65823</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-26T16:53:15Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207195#M65824</link>
      <description>&lt;P&gt;Btw, when you enable IA blade, you dont even need to go through wizard, just enable the blade, cancel the screen and then save, go back and simply enable IC option, configure settings there, save, install policy, test.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 17:27:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207195#M65824</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-26T17:27:02Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207196#M65825</link>
      <description>&lt;P&gt;Really? Than how I associate the ldap account unit object with the gateway?&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 17:21:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207196#M65825</guid>
      <dc:creator>Unon</dc:creator>
      <dc:date>2024-02-26T17:21:43Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP Account Unit</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207197#M65826</link>
      <description>&lt;P&gt;NO : - ). That is not how you associate it. You need to have ldap acccount unit there, thats it. AD query does NOT need to be enabled in the wizard. We have many customers who have ldap account unit and dont even have IA blade enabled, its fine. Only downside is that without ia blade on, you cannot use access roles, which is helpful. Otherwise, logs will have usernames contained in them, it works fine even without ia blade enabled.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 26 Feb 2024 17:24:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-Account-Unit/m-p/207197#M65826</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-26T17:24:56Z</dc:date>
    </item>
  </channel>
</rss>

