<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness and smart cards in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-and-smart-cards/m-p/22089#M4175</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Identity Awareness uses associations of User Identity (combination of user auth details with some sort of authentication techniques, such as AS, LDAP, etc and machine identity for managed PCs) and IP associated with the identified endpoint. FW uses IP to enforced rules associated with User Roles.&lt;/P&gt;&lt;P&gt;I suggest you to look into&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;sk86441 for the best scenario.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 27 Aug 2018 12:22:22 GMT</pubDate>
    <dc:creator>_Val_</dc:creator>
    <dc:date>2018-08-27T12:22:22Z</dc:date>
    <item>
      <title>Identity Awareness and smart cards</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-and-smart-cards/m-p/22085#M4171</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need to implement Identity Awareness on checkpoint R77.30 for a client. The client would like to use smart cards to authenticate users on the GW.&amp;nbsp; (Smart cards&amp;nbsp;contain SSL certificate and are already used to authenticate users on the network and to unlock their PCs).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please tell me if there is any documentation&amp;nbsp;of how to implement IDawareness&amp;nbsp;based on smart cards on checkpoint?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;identity awareness‌&amp;nbsp; identity agent‌ authentication‌ #smart card&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Aug 2018 09:39:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-and-smart-cards/m-p/22085#M4171</guid>
      <dc:creator>Oussama_Kadim1</dc:creator>
      <dc:date>2018-08-27T09:39:40Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and smart cards</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-and-smart-cards/m-p/22086#M4172</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;According to sk86441, Identity Awareness gets identities from these identity sources. You must enable them on the Gateway, from the Identity Awareness page of the Gateway object:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Active Directory (AD) Query&lt;/LI&gt;&lt;LI&gt;Browser-Based Authentication&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Identity Agents (installed on the Endpoint)&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Terminal Servers Agents&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Radius Accounting&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Remote Access&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;Identity Collector&lt;/LI&gt;&lt;LI&gt;Web API&lt;/LI&gt;&lt;/UL&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Aug 2018 11:01:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-and-smart-cards/m-p/22086#M4172</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-08-27T11:01:47Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and smart cards</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-and-smart-cards/m-p/22087#M4173</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Any means of authentication against AD should work for you, if you are using AD Query and/or Identity Collectors.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Please elaborate of the exact scenario. It is unclear if you mean "on the PC" auth or a direct auth on the GW. If latter, please tell us how you see it.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Aug 2018 11:06:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-and-smart-cards/m-p/22087#M4173</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-27T11:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and smart cards</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-and-smart-cards/m-p/22088#M4174</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Currently users use the smart card to authenticate themselves on their workstations.&lt;BR /&gt;Once authenticated, users access the company network.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Access threading between users and applications is done via checkpoints, and this filtering is based only on source/destination IPs and the tcp/Udp port.&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;We wish then to put more security and traceability by setting up the blade IDawareness.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The customer does not wish to use AD query, Log collector etc., asked me to do a study on the possibility to use the smart card and to use the certificate it contains in order to identify users and use access control type filtering.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Aug 2018 12:11:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-and-smart-cards/m-p/22088#M4174</guid>
      <dc:creator>Oussama_Kadim1</dc:creator>
      <dc:date>2018-08-27T12:11:04Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and smart cards</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-and-smart-cards/m-p/22089#M4175</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Identity Awareness uses associations of User Identity (combination of user auth details with some sort of authentication techniques, such as AS, LDAP, etc and machine identity for managed PCs) and IP associated with the identified endpoint. FW uses IP to enforced rules associated with User Roles.&lt;/P&gt;&lt;P&gt;I suggest you to look into&amp;nbsp;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;sk86441 for the best scenario.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 27 Aug 2018 12:22:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-and-smart-cards/m-p/22089#M4175</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2018-08-27T12:22:22Z</dc:date>
    </item>
  </channel>
</rss>

