<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Collector is now GA in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3273#M174</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Phoneboy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the info, we've been discussing the collector on the CPX in Milan with Peter Elmer. We're acutally waiting for an additional feature for the last few years. As we'd like to replace the Client Auth Rules with Identity Based Rules (IA), we miss the opportunity to use/force strong authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ideas that came into my mind when we learned about the Identity Collector:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Make a web-based portal on the Indentity Collector quite similar to the one on the Firewall Module for Client Auth, so the user can use SecurID Tokens to authenticate.&lt;/LI&gt;&lt;LI&gt;The Identity Collector itself does note the quality of authentication of each identity (simple/plain auth learned from the AD, strong auth for those who used the portal on the Identity Collector). This information must be shared between all Identity Collectors.&lt;/LI&gt;&lt;LI&gt;The Firewall Module will learn the quality of the authentication along to the identity&lt;/LI&gt;&lt;LI&gt;In the firewall policy one can select per rule which quality of authentication is needed. (IA with plain auth/IA with strong auth)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know, what you guys think about that. For me, this will be a great addition to a new great solution from Check Point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Roger&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 21 May 2017 19:47:22 GMT</pubDate>
    <dc:creator>Doeschi</dc:creator>
    <dc:date>2017-05-21T19:47:22Z</dc:date>
    <item>
      <title>Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3268#M169</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Check Point Identity Collector is a Windows-based application which collects information about identities and their associated IP addresses, and sends it to the Check Point Firewalls for identity enforcement. The identities are collected from the following servers:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Microsoft Active Directory Domain Controllers.&lt;/LI&gt;&lt;LI&gt;Cisco Identity Services Engine (ISE) Servers, versions 2.0, 2.1 and 2.2 - see &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108235" style="color: #905690;" target="_blank"&gt;sk108235&lt;/A&gt;.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Identity Collector Key Benefits over Standard AD Query&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Reduces the load on the Security Gateway - the agent is doing the queries instead of the Security Gateway.&lt;/LI&gt;&lt;LI&gt;Reduces the load on the DCs - the native Windows API used consumes less resources.&lt;/LI&gt;&lt;LI&gt;The Identity Collector requires no administrator or administrator-like permissions. Only permission required is read-only access to the domain security logs.&lt;/LI&gt;&lt;LI&gt;One Identity Collector can serve multiple gateways, even from different CMA.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Identity Collector will be part of R80.10 GA. It can also be utilized on R77.30 and R77.20 with a hotfix that can be obtained through the TAC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For more details: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110155" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk110155"&gt;Identity Collector Technical Overview&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 04 May 2017 16:48:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3268#M169</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-05-04T16:48:38Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3269#M170</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Dameon for the update.&amp;nbsp; We have been using the AD Query Agent for the past 2 years which was in EA.&amp;nbsp; Do you know if the R77.20/R77.30 standalone hotfix will be integrated into a newer jumbo take?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 May 2017 11:54:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3269#M170</guid>
      <dc:creator>Raj_Khatri</dc:creator>
      <dc:date>2017-05-05T11:54:09Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3270#M171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;About time!&amp;nbsp;&amp;nbsp; I presume the hotfix is the same as required for vSec enforcer?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 May 2017 14:24:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3270#M171</guid>
      <dc:creator>Quinn_Yost</dc:creator>
      <dc:date>2017-05-05T14:24:56Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3271#M172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not sure what the plan is with respect to integrating with the Jumbo Hotfix. I believe it can be applied on top of current jumbo hotfixes, but check with the TAC to confirm.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 05 May 2017 18:42:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3271#M172</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2017-05-05T18:42:49Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3272#M173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;been using it for years now and working great, would love to see it integrated to general HFA for R77.30.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 May 2017 05:59:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3272#M173</guid>
      <dc:creator>Magnus_Holmberg</dc:creator>
      <dc:date>2017-05-21T05:59:33Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3273#M174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Phoneboy,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;thanks for the info, we've been discussing the collector on the CPX in Milan with Peter Elmer. We're acutally waiting for an additional feature for the last few years. As we'd like to replace the Client Auth Rules with Identity Based Rules (IA), we miss the opportunity to use/force strong authentication.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Ideas that came into my mind when we learned about the Identity Collector:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Make a web-based portal on the Indentity Collector quite similar to the one on the Firewall Module for Client Auth, so the user can use SecurID Tokens to authenticate.&lt;/LI&gt;&lt;LI&gt;The Identity Collector itself does note the quality of authentication of each identity (simple/plain auth learned from the AD, strong auth for those who used the portal on the Identity Collector). This information must be shared between all Identity Collectors.&lt;/LI&gt;&lt;LI&gt;The Firewall Module will learn the quality of the authentication along to the identity&lt;/LI&gt;&lt;LI&gt;In the firewall policy one can select per rule which quality of authentication is needed. (IA with plain auth/IA with strong auth)&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Let me know, what you guys think about that. For me, this will be a great addition to a new great solution from Check Point.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Roger&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 21 May 2017 19:47:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3273#M174</guid>
      <dc:creator>Doeschi</dc:creator>
      <dc:date>2017-05-21T19:47:22Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3274#M175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Good luck integrating IDC HF with vSEC HF... I was told it couldn't be done on 77.20... Both are integrated in 80.10...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 May 2017 02:48:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3274#M175</guid>
      <dc:creator>Brian_Deutmeyer</dc:creator>
      <dc:date>2017-05-22T02:48:46Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3275#M176</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the web-based portal is something we have asked R&amp;amp;D for the last 2 years we have been using the clients, not for strong auth but to make it easier for the linux/MAC guys. Currently they need to login to diffrente webpages depending in what country they are in.&lt;BR /&gt;And if we would have it on the IC server instead, then we could share the identity across the board on all CMA.&lt;BR /&gt;So thats something that would help very much.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Second part of agent is to understand the redundancy you get as there is really no HA, cluster etc.&lt;BR /&gt;Would be nice if you could get the Agents to atleast see eachother if they are up or not.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Agreeing with the strong auth as a BYOD senario would be easier to achive if the rules could demand strong auth based on 2 factor or similar on the webportal.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;BR /&gt;Magnus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 May 2017 05:06:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3275#M176</guid>
      <dc:creator>Magnus_Holmberg</dc:creator>
      <dc:date>2017-05-22T05:06:49Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3276#M177</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Magnus, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1. For Web based portal - Why not not log to a specific PDP portal and configure Identity Sharing to share info with the enforcing gateways?&lt;/P&gt;&lt;P&gt;2. For Cross CMA identity Sharing - We are not about to add everything but the kitchen sink to the identity collector just to overcome the cross CMA issues but to address them in the gateway level. There is an RFE being worked to provide PDP to PDP identity sharing over REST to overcome the SIC limitations.&lt;/P&gt;&lt;P&gt;3. Identity agents HA - We will add to the subsequent release a view of last reported time from each client. Our best practice guideline is to use an Active-Active formation - have two agents report the same information to the PDP's. &lt;/P&gt;&lt;P&gt;4. Our vision for authentication enforcement is to have as part of the access role to enable to choose the selected realm and identity source, but this is something in the longer term roadmap. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards, &lt;/P&gt;&lt;P&gt;Tzvi Katz - Identity Awareness and Access Clients R&amp;amp;D GM&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 May 2017 14:36:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3276#M177</guid>
      <dc:creator>Tzvi_Katz</dc:creator>
      <dc:date>2017-05-22T14:36:12Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3277#M178</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Roger, &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please find the answer I had provided Magnus om the same thread. &lt;/P&gt;&lt;P&gt;Essentially there is no need for a portal on the Identity Collector for that, but to enhance the gateway/management side. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently the Identity Awareness captive portal do support SecurID as a matter of fact. &lt;/P&gt;&lt;P&gt;As I had answered Roger we have a product vision to extend the authentication scheme to a unified one (see remote access client multi login options) to all of Check Point components are enforce the login option as part of the access role. &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 May 2017 14:53:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3277#M178</guid>
      <dc:creator>Tzvi_Katz</dc:creator>
      <dc:date>2017-05-22T14:53:19Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3278#M179</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tzvi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;1, 2: Sharing between gateways is about step number 2 or 3 that R&amp;amp;D always ask us to turn off.&lt;BR /&gt;Yes we have done sharing within CMA before between GW.&lt;BR /&gt;When we ask R&amp;amp;D about sharing between CMA they say ok its possible but hard to do and not recommended with the amount of users/objects we have.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you can cross share between domains with high number of users we would love to do that.&lt;BR /&gt;Second part why we would like it in the IC is that then we could possible have it from multiple domains as we recently was bought by another ISP and it will take years before all is integrated fully.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3: Sure but one comment i know we and other customers have had is the issue on seeing if it stops or not, it has been solved with monitoring on server side ofc.&lt;BR /&gt;But it would be nice to get a logentry saying: "lost identity collector" or similar. in the log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;4: Sure thing.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;But we will submit and RFC and then you guys can check if multiple customers wants the same to be added.&lt;BR /&gt;Just because checkpoint want you to do in a specific way its not always the way that the customers wants to have it.We see it as a great benefit if we can get all IA from one source and connect the citrix, portal etc to the agent as well.&lt;BR /&gt;&lt;BR /&gt;/Magnus&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 May 2017 15:04:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3278#M179</guid>
      <dc:creator>Magnus_Holmberg</dc:creator>
      <dc:date>2017-05-22T15:04:24Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3279#M180</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Tzvi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;First, thank you for the answer. Well, using the Identity Awareness Captive Portal doesn't solve the problem sharing the Identity over Cross CMA as well as handling multiple domains. Thus, it'll reduce the load on the gateways, if there's a possibility to "outsource" that feature to a system like the IC.&lt;/P&gt;&lt;P&gt;To my opinion, Magnus and I share the same idea of having 1 system (with possible HA solution) to collect the identities as well as the "used" authentication method and share it with all gateways independently of their Management Systems / Domains. Along with extending the IA access role with the auth scheme as you already "visioned", the solution would be perfect and a great benefit for all IA users.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Roger&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 May 2017 16:03:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3279#M180</guid>
      <dc:creator>Doeschi</dc:creator>
      <dc:date>2017-05-22T16:03:26Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3280#M181</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In regards to sharing between CMAs, I just set up a PDP for each CMA and had the IDC send identities to each PDP.&amp;nbsp; Those PDPs can then share the identities with all the gateways in each respective domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So if you have 2 domains, each domain will have its own PDP and the IDC will send the same identities to both PDPs to be shared.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 22 May 2017 17:37:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3280#M181</guid>
      <dc:creator>Brian_Deutmeyer</dc:creator>
      <dc:date>2017-05-22T17:37:23Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3281#M182</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;can we use the identity collector to aggregate identities from the terminal server's MUH agent for multiple gateways?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2018 06:39:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3281#M182</guid>
      <dc:creator>Dor_Marcovitch</dc:creator>
      <dc:date>2018-05-16T06:39:27Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3282#M183</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dor,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This is a good idea and goes along the ideas we raised a year ago. It would be great, if the identity collector would be the "single point of contact" regarding identities used for authorization within Check Point products. To achieve this, the identity collector should be capable to collect the identities from the AD and the ISE (as it works now) but also from the IA Agents and the MUH agents. And, it should also make a difference of people with weak authentication (like username / password on windows logon) and people with priviledged access that has to use strong authentication (2-factor auth) and mark the identities accordingly. Then on the security gateway the firewall admin can decide per rule, if no auth, weak auth or strong auth is needed to match the rule.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Roger&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2018 08:19:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3282#M183</guid>
      <dc:creator>Doeschi</dc:creator>
      <dc:date>2018-05-16T08:19:19Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3283#M184</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;As far as I know, not currently, though it sounds like a good idea.&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/45508"&gt;Tzvi Katz&lt;/A&gt;‌, maybe something to consider?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 May 2018 16:40:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3283#M184</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-05-16T16:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3284#M185</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The identity collector purpose is to collect identities from external sources. The PDP&amp;nbsp;should be the source of the logic.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So what&amp;nbsp;Roger had&amp;nbsp;essentially requested is to add to an access role the capability to specify the identity source or the realm used for authentication.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2018 08:41:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3284#M185</guid>
      <dc:creator>Tzvi_Katz</dc:creator>
      <dc:date>2018-05-22T08:41:40Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3285#M186</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dor,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The PDP can perform the identity sharing of MUH sessions, no need for the IDC to own such capability.&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2018 08:42:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3285#M186</guid>
      <dc:creator>Tzvi_Katz</dc:creator>
      <dc:date>2018-05-22T08:42:58Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3286#M187</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;why not consolidating the "collection role" of identities from external resources to one entity (IDC) instead of using identity sharing between all the FWs ?&lt;/P&gt;&lt;P&gt;then you can also change the update channel of identities from the FW to the IDC.. than you will get some kind of a Star topology for the identity sharing process and if you add the ability to have 2 different servers as the IDC you get even&lt;/P&gt;&lt;P&gt;&amp;nbsp;more redundancy (IDC installed on a VM server which can be redundant on multiple physical servers on multiple datacenters)&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2018 08:52:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3286#M187</guid>
      <dc:creator>Dor_Marcovitch</dc:creator>
      <dc:date>2018-05-22T08:52:04Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector is now GA</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3287#M188</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Not to mention the offload of the https sessions from the IA Agents to the IDC instead to the already busy firewalls in a large scale deployment. Thus identity sharing with the need of that ridiculous hide-nat configuration could be fully replaced by IDC... and even cross-CMA.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 22 May 2018 09:01:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector-is-now-GA/m-p/3287#M188</guid>
      <dc:creator>Doeschi</dc:creator>
      <dc:date>2018-05-22T09:01:20Z</dc:date>
    </item>
  </channel>
</rss>

