<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: CheckPoint integration with ClearPass via API - Gateway is not using ClearPass roles in API / CLI Discussion</title>
    <link>https://community.checkpoint.com/t5/API-CLI-Discussion/CheckPoint-integration-with-ClearPass-via-API-Gateway-is-not/m-p/129808#M6255</link>
    <description>&lt;P&gt;In R80.40 and above, you can adjust this via the Identity Conciliation feature.&lt;BR /&gt;It's described here:&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk146835&amp;amp;partition=Basic&amp;amp;product=Identity" target="_blank"&gt;&amp;nbsp;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk146835&amp;amp;partition=Basic&amp;amp;product=Identity&lt;/A&gt;&lt;BR /&gt;You will need to contact the TAC to get the exact procedure for your situation.&lt;/P&gt;</description>
    <pubDate>Mon, 20 Sep 2021 20:37:13 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-09-20T20:37:13Z</dc:date>
    <item>
      <title>CheckPoint integration with ClearPass via API - Gateway is not using ClearPass roles</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/CheckPoint-integration-with-ClearPass-via-API-Gateway-is-not/m-p/129113#M6227</link>
      <description>&lt;P&gt;I am trying to integrate CheckPoint gateway with Aruba ClearPass in order to use user roles in a CheckPoint GW sent by a ClearPass server.&lt;/P&gt;&lt;P&gt;In CheckPoint's pdp logs I see that CheckPoint GW is receiving authenticated user's roles, but the problem is that CheckPoint is not attaching these roles to users. If I try to create 'Access roles' in CheckPoint locally&amp;nbsp; then those roles are assigned to authenticated users regardless what ClearPass sends.&lt;/P&gt;&lt;P&gt;What am I missing? How should I make CheckPoint GW use roles that has been sent by a ClearPass?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;All of the configuration that I've done is from this guide:&amp;nbsp;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docId=a00091074en_us&amp;amp;docLocale=en_US" target="_blank"&gt;https://support.hpe.com/hpesc/public/docDisplay?docId=a00091074en_us&amp;amp;docLocale=en_US&lt;/A&gt;&amp;nbsp;.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 13:44:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/CheckPoint-integration-with-ClearPass-via-API-Gateway-is-not/m-p/129113#M6227</guid>
      <dc:creator>GLTomas</dc:creator>
      <dc:date>2021-09-10T13:44:51Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint integration with ClearPass via API - Gateway is not using ClearPass roles</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/CheckPoint-integration-with-ClearPass-via-API-Gateway-is-not/m-p/129115#M6228</link>
      <description>&lt;P&gt;The only thing the underlying API allows sending is the identity (user).&lt;BR /&gt;The Access Roles must still be defined on the Check Point side and verified e.g. with Active Directory.&lt;BR /&gt;That is mentioned in the documentation you provided in a few places, but this first one comes from page 10:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;When using the Check&lt;/SPAN&gt;&lt;SPAN&gt;Point Identity Awareness feature (RESTful API or RADIUS Accounting) the userID that &lt;/SPAN&gt;&lt;SPAN&gt;is received by the firewall typically has to be verifiable as a valid user. Check&lt;/SPAN&gt;&lt;SPAN&gt;Point will ensure th&lt;/SPAN&gt;&lt;SPAN&gt;e user exists &lt;/SPAN&gt;&lt;SPAN&gt;within an authoritative Identity Store, like Active Directory&lt;/SPAN&gt;&lt;SPAN&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 15:18:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/CheckPoint-integration-with-ClearPass-via-API-Gateway-is-not/m-p/129115#M6228</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-10T15:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint integration with ClearPass via API - Gateway is not using ClearPass roles</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/CheckPoint-integration-with-ClearPass-via-API-Gateway-is-not/m-p/129118#M6229</link>
      <description>&lt;P&gt;But how about page 6 where it is said that "User Role" attribute &lt;SPAN&gt;can be&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;pass&lt;/SPAN&gt;&lt;SPAN&gt;ed&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;from ClearPass&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;to Check &lt;/SPAN&gt;&lt;SPAN&gt;Point?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Also under "Appendix C –SQL Authorization Source" on page 34 - it even shows how to extract roles from a ClearPass in order to send them to CheckPoint firewall. Newer version of this document:&amp;nbsp;&lt;A href="https://support.hpe.com/hpesc/public/docDisplay?docId=a00101500en_us" target="_blank" rel="noopener"&gt;https://support.hpe.com/hpesc/public/docDisplay?docId=a00101500en_us&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;So as you said, I am&amp;nbsp;&lt;SPAN&gt;defining access roles on the CheckPoint side but those roles are being used automatically,- as far as I imagine, those roles should be picket and used only when ClearPass sends role names to a CheckPoint firewall, isn't it?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 15:49:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/CheckPoint-integration-with-ClearPass-via-API-Gateway-is-not/m-p/129118#M6229</guid>
      <dc:creator>GLTomas</dc:creator>
      <dc:date>2021-09-10T15:49:50Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint integration with ClearPass via API - Gateway is not using ClearPass roles</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/CheckPoint-integration-with-ClearPass-via-API-Gateway-is-not/m-p/129119#M6230</link>
      <description>&lt;P&gt;Even if you groups are passed (which I can see the API supports),&amp;nbsp;you still have to create the Access Roles on the Check Point side.&lt;BR /&gt;Page 11:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-30px"&gt;&lt;SPAN&gt;To&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;ensure&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;the identity will not be verified against Check&lt;/SPAN&gt;&lt;SPAN&gt;Point&lt;/SPAN&gt;&lt;SPAN&gt;’&lt;/SPAN&gt;&lt;SPAN&gt;s identity sources&lt;/SPAN&gt;&lt;SPAN&gt;,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;the &lt;/SPAN&gt;&lt;SPAN&gt;“&lt;/SPAN&gt;&lt;SPAN&gt;fetch&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;user&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;groups&lt;/SPAN&gt;&lt;SPAN&gt;” &lt;/SPAN&gt;&lt;SPAN&gt;and “&lt;/SPAN&gt;&lt;SPAN&gt;fetch&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;machine&lt;/SPAN&gt;&lt;SPAN&gt;-&lt;/SPAN&gt;&lt;SPAN&gt;groups&lt;/SPAN&gt;&lt;SPAN&gt;”&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;should be set to 0 (zero)&lt;/SPAN&gt;&lt;SPAN&gt;. &lt;/SPAN&gt;&lt;SPAN&gt;T&lt;/SPAN&gt;&lt;SPAN&gt;his is very important for Guest Users.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Obviously for &lt;/SPAN&gt;&lt;SPAN&gt;Guest users their &lt;/SPAN&gt;&lt;SPAN&gt;userIDs do not exist within &lt;/SPAN&gt;&lt;SPAN&gt;identity&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;stores like Active Directory &lt;/SPAN&gt;&lt;SPAN&gt;as they are transient users. &lt;/SPAN&gt;&lt;SPAN&gt;Some guest accounts could exist within a direc&lt;/SPAN&gt;&lt;SPAN&gt;tory but that is not usual. So&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;as &lt;/SPAN&gt;&lt;SPAN&gt;a &lt;/SPAN&gt;&lt;SPAN&gt;part of th&lt;/SPAN&gt;&lt;SPAN&gt;e integration,&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;identif&lt;/SPAN&gt;&lt;SPAN&gt;y these users &lt;/SPAN&gt;&lt;SPAN&gt;and link them to a user group (a configurable Check&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Point attribute called access role).&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 10 Sep 2021 15:50:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/CheckPoint-integration-with-ClearPass-via-API-Gateway-is-not/m-p/129119#M6230</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-10T15:50:32Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint integration with ClearPass via API - Gateway is not using ClearPass roles</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/CheckPoint-integration-with-ClearPass-via-API-Gateway-is-not/m-p/129798#M6254</link>
      <description>&lt;P&gt;Hello, we have an implementation where CheckPoint is integrated with an AD with an Identity Collector. But when we integrate our CheckPoint with third-party solution and at the same time get identity information from AD and from third party device via Assigning "0" to those values helped. But now I have different problem. W&lt;SPAN&gt;e have an implementation where CheckPoint is integrated with an AD with an Identity Collector. But when we integrate our CheckPoint with third-party solution, GW gets identity information from AD and from third party device via API at the same time,- as a result Checkpoint GW then has two blocks of information about same identity from two different sources (AD and 3rd party tool via API) which leads to a problem, because Access roles then are assigned incorrectly. How to make GW to pay attention only to identities learnt by 3rd party solutions via API?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 15:30:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/CheckPoint-integration-with-ClearPass-via-API-Gateway-is-not/m-p/129798#M6254</guid>
      <dc:creator>GLTomas</dc:creator>
      <dc:date>2021-09-20T15:30:12Z</dc:date>
    </item>
    <item>
      <title>Re: CheckPoint integration with ClearPass via API - Gateway is not using ClearPass roles</title>
      <link>https://community.checkpoint.com/t5/API-CLI-Discussion/CheckPoint-integration-with-ClearPass-via-API-Gateway-is-not/m-p/129808#M6255</link>
      <description>&lt;P&gt;In R80.40 and above, you can adjust this via the Identity Conciliation feature.&lt;BR /&gt;It's described here:&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk146835&amp;amp;partition=Basic&amp;amp;product=Identity" target="_blank"&gt;&amp;nbsp;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk146835&amp;amp;partition=Basic&amp;amp;product=Identity&lt;/A&gt;&lt;BR /&gt;You will need to contact the TAC to get the exact procedure for your situation.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Sep 2021 20:37:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/API-CLI-Discussion/CheckPoint-integration-with-ClearPass-via-API-Gateway-is-not/m-p/129808#M6255</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-09-20T20:37:13Z</dc:date>
    </item>
  </channel>
</rss>

