<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Agent vs Identitiy Collector -- AD Query in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233561#M39019</link>
    <description>&lt;P&gt;The gateway (the PDP specifically) makes the LDAP query based on the configured LDAP Account Unit(s).&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 22 Nov 2024 14:47:31 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-11-22T14:47:31Z</dc:date>
    <item>
      <title>Identity Agent vs Identitiy Collector -- AD Query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233437#M38990</link>
      <description>&lt;P&gt;Hello,&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I was trying to find out what is exactly how does the Identity agent send the info to the ID Awareness Server.&amp;nbsp;&lt;BR /&gt;Could not find exactly an SK that tell me directly what happened on the Agent side.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I already installed and configured the ID Agent on the Gateway (Identity source). I see that the Identity source when users connect with the identity Agent .. Although, in how does the Gateway learn the AD Groups that user in?&amp;nbsp;&lt;BR /&gt;Does the Agent collect this information from the user and send it to the PDP ? In this case, any changes in the AD should be followed with &lt;EM&gt;gpupdate&lt;/EM&gt; on the client side, so the agent learns those changes ?&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;And in this scale of 3000 users, is it ok to keep the Agent or recommended moving to Collector?&amp;nbsp;&lt;BR /&gt;Which one is better for AD traffic ? I don't want to send many request to AD. Although the Agent gets them from user PC which already make the connection to the AD. But the collector is up-to-date.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;I could not find much info regarding this subject on the Checkpoint site...&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 15:57:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233437#M38990</guid>
      <dc:creator>ShadowNif</dc:creator>
      <dc:date>2024-11-21T15:57:09Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent vs Identitiy Collector -- AD Query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233440#M38991</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/70663"&gt;@ShadowNif&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Frist have a look at on the best practices:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk88520" target="_blank" rel="noopener"&gt;https://support.checkpoint.com/results/sk/sk88520&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I have exprience with&amp;nbsp; 2000 user and they use Identity Agent. No problem, works fine.&lt;/P&gt;
&lt;P&gt;I would push you to the IA Collector way in a large environment. Easier to keep up to date the version, no need to change/update agents&amp;nbsp; on the endpoints (where a lot of agent have already installed on the machines).&lt;/P&gt;
&lt;P&gt;It would be enough to handle the Terminal server agent on the jumphosts etc.&lt;/P&gt;
&lt;P&gt;What is under the hood in IA? The answer:&amp;nbsp;&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk86441" target="_self"&gt;ATRG: Identity Awareness&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;
&lt;P&gt;ps.: i will search for detailed explanation of the IA agent.&lt;/P&gt;
&lt;P&gt;update i:&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics/Identity-Agent-for-Endpoint-Computer.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics/Identity-Agent-for-Endpoint-Computer.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 16:22:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233440#M38991</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-11-21T16:22:00Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent vs Identitiy Collector -- AD Query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233450#M38995</link>
      <description>&lt;P&gt;Have a look at this discussion, I believe it will help you lots.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/New-IA-Implementation/m-p/185851#M34184" target="_blank" rel="noopener"&gt;https://community.checkpoint.com/t5/Security-Gateways/New-IA-Implementation/m-p/185851#M34184&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 17:25:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233450#M38995</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-21T17:25:01Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent vs Identitiy Collector -- AD Query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233458#M38999</link>
      <description>&lt;P&gt;On the gateway object i would recommend idc. 2 servers would be the best. It is not a ‘cluster’ then but it helps if something happens on one server. You don’t need to run a separate server special for idc it can share the server with other stuff &lt;span class="lia-unicode-emoji" title=":grinning_face_with_big_eyes:"&gt;😃&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Most customers do not want idc on their dc tho. Also do not enable adquery on gateway object only idc. Just make a ldap account unit in SmartConsole&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 19:14:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233458#M38999</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2024-11-21T19:14:42Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent vs Identitiy Collector -- AD Query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233468#M39002</link>
      <description>&lt;P&gt;The most accurate way to obtain identity is via the agent as it is closest to the user.&lt;BR /&gt;All identity methods (except SAML ones) get groups via an LDAP Query via the relevant Active Directory server.&lt;/P&gt;</description>
      <pubDate>Thu, 21 Nov 2024 21:58:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233468#M39002</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-21T21:58:14Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent vs Identitiy Collector -- AD Query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233487#M39009</link>
      <description>&lt;P&gt;Thnx for the answers,&amp;nbsp;&lt;BR /&gt;Although this still does not answer my question, &lt;SPAN&gt;how does the Gateway learn the AD Groups that the user has in the Identity Agent setup?&amp;nbsp;&lt;BR /&gt;Does the ID agent connect to AD, take the info and forward it to the Gateway/PDP ?&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 05:25:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233487#M39009</guid>
      <dc:creator>ShadowNif</dc:creator>
      <dc:date>2024-11-22T05:25:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent vs Identitiy Collector -- AD Query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233488#M39010</link>
      <description>&lt;P&gt;who makes the Query in case of the Identity Agent setup ? The ID agent ? Does the gateway need to connect the AD after that ?&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 05:27:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233488#M39010</guid>
      <dc:creator>ShadowNif</dc:creator>
      <dc:date>2024-11-22T05:27:47Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent vs Identitiy Collector -- AD Query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233489#M39011</link>
      <description>&lt;P&gt;Still does not explain how does the Agent optain the infos about user groups !&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 05:30:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233489#M39011</guid>
      <dc:creator>ShadowNif</dc:creator>
      <dc:date>2024-11-22T05:30:29Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent vs Identitiy Collector -- AD Query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233491#M39013</link>
      <description>&lt;P&gt;Ya ive gone through those article before i posted my question. but non of them says exactly what or how does the agent works.&amp;nbsp;&lt;BR /&gt;If i updated something in AD, should i do gpupdate on the client side so that the Agent knows the new changes, Or it connects to the AD and take the info and give it to the PDP. Although the agent System does not even know that there changes ... how does it exactly work!!?&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 05:33:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233491#M39013</guid>
      <dc:creator>ShadowNif</dc:creator>
      <dc:date>2024-11-22T05:33:41Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent vs Identitiy Collector -- AD Query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233500#M39015</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/70663"&gt;@ShadowNif&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Just open a TAC case, and ask them to give a resolution of IA working.&lt;/P&gt;
&lt;P&gt;They 100% have a detailed description of IA flow.&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 08:16:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233500#M39015</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-11-22T08:16:06Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent vs Identitiy Collector -- AD Query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233527#M39017</link>
      <description>&lt;P&gt;page 106&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/CP_R81_IdentityAwareness_AdminGuide.pdf" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/CP_R81_IdentityAwareness_AdminGuide.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 11:30:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233527#M39017</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-22T11:30:16Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent vs Identitiy Collector -- AD Query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233528#M39018</link>
      <description>&lt;P&gt;Also, see below what TAC sent me while back when I worked with client that mostly had MAC os in their company.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;*********************&lt;/P&gt;
&lt;P data-olk-copy-source="MessageBody"&gt;The MacOS identity agent would offer an alternative to AD Query, since the domain controller is not providing the proper events we need to do AD Query for the MacOS hosts. The agent would authenticate with the gateway, which would in turn authenticate against the AD. This should allow the gateway to enforce user-based identities for MacOS clients.&lt;/P&gt;
&lt;P aria-hidden="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The captive portal may also be another option should they not wish to install the Identity Agent on the MacOS hosts but, unlike the Agent, has difficulty distinguishing between multiple users behind the same IP address.&lt;/P&gt;
&lt;P&gt;******************************&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 11:35:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233528#M39018</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-11-22T11:35:16Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent vs Identitiy Collector -- AD Query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233561#M39019</link>
      <description>&lt;P&gt;The gateway (the PDP specifically) makes the LDAP query based on the configured LDAP Account Unit(s).&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 22 Nov 2024 14:47:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/233561#M39019</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-11-22T14:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent vs Identitiy Collector -- AD Query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/268204#M45066</link>
      <description>&lt;P&gt;Hi experts,&lt;/P&gt;&lt;P&gt;Sorry for replying to this older thread, but I’m really in need of some ideas to help resolve an ongoing issue.&lt;/P&gt;&lt;P&gt;The customer is running an R81.20 VSX environment. There are 5 VS instances with Identity Awareness (IC) enabled, and each VS is associated with two IDC Servers for redundancy. Each IDC Server, in turn, is connected to more than 40 Domain Controllers.&lt;/P&gt;&lt;P&gt;On the Security Gateway, running pep show pdp all shows that the number of users exceeds 40,000.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image_2026-01-22_16-51-07.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32862iCDC106E266E99A17/image-size/large?v=v2&amp;amp;px=999" role="button" title="Image_2026-01-22_16-51-07.png" alt="Image_2026-01-22_16-51-07.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The customer relies heavily on Access Roles to control Internet access, so the stability of Identity Awareness is critical. However, they frequently report that during morning peak hours, a small number of users—who should already be authorized by Access Roles—are unable to access the Internet.&lt;/P&gt;&lt;P&gt;When checking the logs, we found that for the affected users, there is often a delay of more than 30 minutes between the time their PCs connect to the network after booting and the time their Identity login is successfully completed.&lt;/P&gt;&lt;P&gt;Over the past two years, we have opened countless support cases, but we still cannot guarantee stable behavior.&lt;BR /&gt;Are there any other approaches or best practices that could help improve this situation?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2026 09:04:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/268204#M45066</guid>
      <dc:creator>Vanness_Chen</dc:creator>
      <dc:date>2026-01-22T09:04:33Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent vs Identitiy Collector -- AD Query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/268209#M45067</link>
      <description>&lt;P&gt;We worked with same amount of IA sessions as well, up to 50k simultaneous sessions. Reading your post there are several points coming into my mind. For exampe if ALL collected sessions are relevant for your use case internet access or do you see any options to filter out sessions. Reduced amount of sessions will reduce amount of load on the PEP. I speak from painful experience.&lt;BR /&gt;&lt;BR /&gt;In addition it would be helpful if you could share details of your IA configuration to better understand what is going on.&amp;nbsp;&lt;BR /&gt;&lt;BR /&gt;First idea:&lt;BR /&gt;&lt;BR /&gt;We only do IDC with an ISE and not with AD controllers, but we have experience with many sessions.&lt;BR /&gt;I would therefore recommend reducing the load on the PEPS, i.e. the VSX firewalls, when there are so many sessions.&lt;BR /&gt;I would therefore not connect the IDC directly to the PEP, but would set up an upstream PDP instance. The IDCs are then connected to these PDP devices. The sessions are then passed on to the VS via identity sharing. This should take a lot of load off the VS.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2026 09:48:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/268209#M45067</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2026-01-22T09:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Agent vs Identitiy Collector -- AD Query</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/268294#M45069</link>
      <description>&lt;P&gt;Worth noting that in the &lt;A href="https://support.checkpoint.com/results/sk/sk183506" target="_self"&gt;R82.10 release&lt;/A&gt;, we've made several improvements to resilience and scalability in Identity Awareness.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Jan 2026 16:54:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Agent-vs-Identitiy-Collector-AD-Query/m-p/268294#M45069</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2026-01-22T16:54:24Z</dc:date>
    </item>
  </channel>
</rss>

