<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Identity Awareness - Shareing with own Application or 3. Party in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Shareing-with-own-Application-or-3-Party/m-p/105167#M9993</link>
    <description>&lt;P&gt;Hello, we use several CP Gateways and use IA on all of them. We have an Identity Collector instance for our AD and we use the Terminal Server Muh Agent , based on R80.20 infrastructure. Identity Sharing enabled between all systems.&lt;/P&gt;&lt;P&gt;Works great.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are in need of some help for the Identity Informations from our Terminal Servers. MUH Agent is enabled. PDP Monitor works..&lt;/P&gt;&lt;P&gt;Now to the question.&lt;/P&gt;&lt;P&gt;We have a two vendor strategy and we also need a way to publish Identity Informations to other prodcuts and services.&lt;/P&gt;&lt;P&gt;Is there a way we can share the infos with other systems or via a push information so we can store data in a database via an own service program(webapi, whatever)..&lt;/P&gt;&lt;P&gt;Or any other idea ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks so far&lt;/P&gt;&lt;P&gt;bye&lt;/P&gt;&lt;P&gt;roman&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 11 Dec 2020 17:14:01 GMT</pubDate>
    <dc:creator>Roman_Petry</dc:creator>
    <dc:date>2020-12-11T17:14:01Z</dc:date>
    <item>
      <title>Identity Awareness - Shareing with own Application or 3. Party</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Shareing-with-own-Application-or-3-Party/m-p/105167#M9993</link>
      <description>&lt;P&gt;Hello, we use several CP Gateways and use IA on all of them. We have an Identity Collector instance for our AD and we use the Terminal Server Muh Agent , based on R80.20 infrastructure. Identity Sharing enabled between all systems.&lt;/P&gt;&lt;P&gt;Works great.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are in need of some help for the Identity Informations from our Terminal Servers. MUH Agent is enabled. PDP Monitor works..&lt;/P&gt;&lt;P&gt;Now to the question.&lt;/P&gt;&lt;P&gt;We have a two vendor strategy and we also need a way to publish Identity Informations to other prodcuts and services.&lt;/P&gt;&lt;P&gt;Is there a way we can share the infos with other systems or via a push information so we can store data in a database via an own service program(webapi, whatever)..&lt;/P&gt;&lt;P&gt;Or any other idea ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thanks so far&lt;/P&gt;&lt;P&gt;bye&lt;/P&gt;&lt;P&gt;roman&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 17:14:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Shareing-with-own-Application-or-3-Party/m-p/105167#M9993</guid>
      <dc:creator>Roman_Petry</dc:creator>
      <dc:date>2020-12-11T17:14:01Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Shareing with own Application or 3. Party</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Shareing-with-own-Application-or-3-Party/m-p/105250#M9994</link>
      <description>&lt;P&gt;Gateways have an Identity Awareness API that can be queried for the identities it is aware of.&lt;BR /&gt;You can also use it to define identities as well.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/latest/IdentityAPIs/#ida_api_intro~v1" target="_blank"&gt;https://sc1.checkpoint.com/documents/latest/IdentityAPIs/#ida_api_intro~v1&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Due to how identity sharing works between gateways, you will most likely need to query all the gateways to get a clear picture of all identities used in the environment.&lt;/P&gt;</description>
      <pubDate>Sat, 12 Dec 2020 20:43:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Shareing-with-own-Application-or-3-Party/m-p/105250#M9994</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-12T20:43:08Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Shareing with own Application or 3. Party</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Shareing-with-own-Application-or-3-Party/m-p/105338#M9995</link>
      <description>&lt;P&gt;Hello and Thanks for this info. i was hoping that there is a better way then quering each server every 1-5 minutes 8-)..I think the load and the delay could be an issue with this approach..&lt;/P&gt;&lt;P&gt;I saw this API in my googling but as it is a pull and not a push technic , it´s not the best way in my opinion.&lt;/P&gt;&lt;P&gt;But i could be wrong..&lt;/P&gt;&lt;P&gt;Is there a way to register as a "identity" gateway sink ? or get a push notification or push way to do such a thing ? other the pulling the api..&lt;/P&gt;&lt;P&gt;thanks and bye roman&lt;/P&gt;</description>
      <pubDate>Mon, 14 Dec 2020 08:33:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Shareing-with-own-Application-or-3-Party/m-p/105338#M9995</guid>
      <dc:creator>Roman_Petry</dc:creator>
      <dc:date>2020-12-14T08:33:09Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Shareing with own Application or 3. Party</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Shareing-with-own-Application-or-3-Party/m-p/105352#M9996</link>
      <description>&lt;P&gt;Depends on how much effort you want to invest here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;You could do reverse engineering of Check Points pdpd-&amp;gt;pepd connection (tcp/15105) and create your own pepd implementation (only the identity receiving part) which would get identity updates pushed from all your pdpds. Good hints to get this working would be sk65404 (how to get the foreign SIC trust working, how to create foreign pepd object in your database) and sk149255 (switch from smart_pull to push for your pepd object).&lt;/P&gt;&lt;P&gt;Will you get support from Check Point for such an architecture? I guess not &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Maybe you could also leverage the more modern identity sharing solution from Check Point "Identity Broker" for that, I did not take a deeper look at it yet.&lt;/P&gt;&lt;P&gt;Any other ideas from the community (or CP staff) for the scenario of identity sharing with pushing identities from Check Point to 3rd party?&lt;/P&gt;</description>
      <pubDate>Mon, 14 Dec 2020 12:01:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Shareing-with-own-Application-or-3-Party/m-p/105352#M9996</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2020-12-14T12:01:01Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Shareing with own Application or 3. Party</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Shareing-with-own-Application-or-3-Party/m-p/105416#M9997</link>
      <description>&lt;P&gt;In general, our Identity Awareness was designed around being a consumer of identities, not necessarily a publisher of them, at least to anything other than a Check Point gateway.&lt;BR /&gt;I don't believe we have any published APIs to do precisely what you're asking in the manner you're asking for it to be done.&lt;BR /&gt;This is probably an RFE.&lt;BR /&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 14 Dec 2020 21:40:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Shareing-with-own-Application-or-3-Party/m-p/105416#M9997</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-12-14T21:40:36Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Shareing with own Application or 3. Party</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Shareing-with-own-Application-or-3-Party/m-p/109169#M14795</link>
      <description>&lt;P&gt;Maybe a system that triggers an action on http/s based server when event (login/logout in this case) occurs. Competitors already have something like that.&lt;/P&gt;</description>
      <pubDate>Thu, 28 Jan 2021 11:08:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Shareing-with-own-Application-or-3-Party/m-p/109169#M14795</guid>
      <dc:creator>Alejandro_Ferna</dc:creator>
      <dc:date>2021-01-28T11:08:29Z</dc:date>
    </item>
  </channel>
</rss>

