<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Identity Awareness/ Terminal Server Agent Question in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-Terminal-Server-Agent-Question/m-p/20603#M3804</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anybody have a solution for sharing identities learned from a terminal services agent across gateways in different domains?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The Check Point Identity Agent can only send the identities to&amp;nbsp;a single gateway.&amp;nbsp;&amp;nbsp; And&amp;nbsp;you can not share identities&amp;nbsp;across gateways that are in different domains, even when they are managed by the same Management Domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use Identity Collector servers&amp;nbsp;for&amp;nbsp;capturing&amp;nbsp;the Active Directory login event, and it&amp;nbsp;works great for sharing identities across gateways in different domains..&amp;nbsp;&amp;nbsp;&amp;nbsp;I don't understand why Check Point wouldn't make it so that the Terminal Server Agent had the ability to send its learned identities to their own identity Collector server, instead of only to a single&amp;nbsp;gateway.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 20 Aug 2018 18:54:26 GMT</pubDate>
    <dc:creator>Scott_Bily</dc:creator>
    <dc:date>2018-08-20T18:54:26Z</dc:date>
    <item>
      <title>Identity Awareness/ Terminal Server Agent Question</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-Terminal-Server-Agent-Question/m-p/20603#M3804</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anybody have a solution for sharing identities learned from a terminal services agent across gateways in different domains?&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The Check Point Identity Agent can only send the identities to&amp;nbsp;a single gateway.&amp;nbsp;&amp;nbsp; And&amp;nbsp;you can not share identities&amp;nbsp;across gateways that are in different domains, even when they are managed by the same Management Domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We use Identity Collector servers&amp;nbsp;for&amp;nbsp;capturing&amp;nbsp;the Active Directory login event, and it&amp;nbsp;works great for sharing identities across gateways in different domains..&amp;nbsp;&amp;nbsp;&amp;nbsp;I don't understand why Check Point wouldn't make it so that the Terminal Server Agent had the ability to send its learned identities to their own identity Collector server, instead of only to a single&amp;nbsp;gateway.&amp;nbsp; &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 20 Aug 2018 18:54:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-Terminal-Server-Agent-Question/m-p/20603#M3804</guid>
      <dc:creator>Scott_Bily</dc:creator>
      <dc:date>2018-08-20T18:54:26Z</dc:date>
    </item>
  </channel>
</rss>

