<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic VPN Cert Auth -  Read OU for User Groups in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/VPN-Cert-Auth-Read-OU-for-User-Groups/m-p/100532#M19539</link>
    <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We are implementing certificate authentication for remote VPN without LDAP and AD. ISE is identity store and we are using ISE`s CA feature.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The authentication is working fine, as auth is going internally in firewall but we also need user groups for policy management.&lt;/P&gt;&lt;P&gt;I wonder is it possible to configre CP to read OU from cert and add users to groups based on OU?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Thu, 29 Oct 2020 10:44:40 GMT</pubDate>
    <dc:creator>OrkhanRustamli</dc:creator>
    <dc:date>2020-10-29T10:44:40Z</dc:date>
    <item>
      <title>VPN Cert Auth -  Read OU for User Groups</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Cert-Auth-Read-OU-for-User-Groups/m-p/100532#M19539</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We are implementing certificate authentication for remote VPN without LDAP and AD. ISE is identity store and we are using ISE`s CA feature.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The authentication is working fine, as auth is going internally in firewall but we also need user groups for policy management.&lt;/P&gt;&lt;P&gt;I wonder is it possible to configre CP to read OU from cert and add users to groups based on OU?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Thu, 29 Oct 2020 10:44:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Cert-Auth-Read-OU-for-User-Groups/m-p/100532#M19539</guid>
      <dc:creator>OrkhanRustamli</dc:creator>
      <dc:date>2020-10-29T10:44:40Z</dc:date>
    </item>
    <item>
      <title>Re: VPN Cert Auth -  Read OU for User Groups</title>
      <link>https://community.checkpoint.com/t5/General-Topics/VPN-Cert-Auth-Read-OU-for-User-Groups/m-p/100816#M19570</link>
      <description>&lt;P&gt;I believe we can only retrieve groups from LDAP.&lt;BR /&gt;However, if you're integrating with Cisco ISE, you should be able to use Identity Tags as a group source.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/Policy-Management/How-to-use-Identity-Awareness-Tags-in-R80-20-M1/m-p/17246" target="_blank"&gt;https://community.checkpoint.com/t5/Policy-Management/How-to-use-Identity-Awareness-Tags-in-R80-20-M1/m-p/17246&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Nov 2020 05:23:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/VPN-Cert-Auth-Read-OU-for-User-Groups/m-p/100816#M19570</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-11-02T05:23:42Z</dc:date>
    </item>
  </channel>
</rss>

