<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can I implement Identity Awareness without using a PDP/PEP Broker? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Can-I-implement-Identity-Awareness-without-using-a-PDP-PEP/m-p/260794#M44118</link>
    <description>&lt;P&gt;Interesting sources:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk86441" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk86441 ATRG: Identity Awareness&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Identity-Awareness-Best-Practices-October-2025-Video-and-Slides/m-p/259579" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Tech Talk Identity Awareness Best Practices&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 24 Oct 2025 10:05:13 GMT</pubDate>
    <dc:creator>Alex-</dc:creator>
    <dc:date>2025-10-24T10:05:13Z</dc:date>
    <item>
      <title>Can I implement Identity Awareness without using a PDP/PEP Broker?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Can-I-implement-Identity-Awareness-without-using-a-PDP-PEP/m-p/260777#M44115</link>
      <description>&lt;P data-start="159" data-end="188"&gt;Hi everyone,&lt;/P&gt;
&lt;P data-start="190" data-end="291"&gt;I’m working on an Identity Awareness deployment on Check Point and I’d like some clarification.&lt;/P&gt;
&lt;P data-start="293" data-end="471"&gt;I understand that in large or complex environments, the PDP/PEP Broker is used to centralize identities and share them across multiple gateways. What I’m not sure about is:&lt;/P&gt;
&lt;UL data-start="473" data-end="864"&gt;
&lt;LI data-start="473" data-end="580"&gt;
&lt;P data-start="475" data-end="580"&gt;Is it possible to configure Identity Awareness directly on the gateway without relying on a Broker?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="581" data-end="730"&gt;
&lt;P data-start="583" data-end="730"&gt;In which scenarios is it sufficient to enable IA using methods like AD Query, Identity Collector, or Captive Portal directly on the firewall?&lt;/P&gt;
&lt;/LI&gt;
&lt;LI data-start="731" data-end="864"&gt;
&lt;P data-start="733" data-end="864"&gt;When is an Identity Broker actually required (e.g. multi-gateway environments, distributed clusters, or multiple AD domains)?&lt;/P&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P data-start="866" data-end="1061"&gt;I’d like to confirm whether, in a relatively simple setup (a single cluster and one AD domain), everything can be done without a Broker, or if there are hidden limitations I should be aware of.&lt;/P&gt;
&lt;P data-start="1063" data-end="1124"&gt;Thanks in advance.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2025 06:57:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Can-I-implement-Identity-Awareness-without-using-a-PDP-PEP/m-p/260777#M44115</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2025-10-24T06:57:39Z</dc:date>
    </item>
    <item>
      <title>Re: Can I implement Identity Awareness without using a PDP/PEP Broker?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Can-I-implement-Identity-Awareness-without-using-a-PDP-PEP/m-p/260782#M44116</link>
      <description>&lt;P&gt;For a simple deployment with just a cluster and a single domain, you can use the Identity Collector and you don't need brokers or identity sharing. The Identity Collector doesn't require domain admin rights which is preferred. From there you can use other methods like Captive Portal for instance.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2025 07:29:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Can-I-implement-Identity-Awareness-without-using-a-PDP-PEP/m-p/260782#M44116</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2025-10-24T07:29:43Z</dc:date>
    </item>
    <item>
      <title>Re: Can I implement Identity Awareness without using a PDP/PEP Broker?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Can-I-implement-Identity-Awareness-without-using-a-PDP-PEP/m-p/260794#M44118</link>
      <description>&lt;P&gt;Interesting sources:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk86441" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk86441 ATRG: Identity Awareness&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Identity-Awareness-Best-Practices-October-2025-Video-and-Slides/m-p/259579" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;Tech Talk Identity Awareness Best Practices&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2025 10:05:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Can-I-implement-Identity-Awareness-without-using-a-PDP-PEP/m-p/260794#M44118</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2025-10-24T10:05:13Z</dc:date>
    </item>
    <item>
      <title>Re: Can I implement Identity Awareness without using a PDP/PEP Broker?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Can-I-implement-Identity-Awareness-without-using-a-PDP-PEP/m-p/260800#M44119</link>
      <description>&lt;P&gt;Hey bro,&lt;/P&gt;
&lt;P&gt;Yes, 100% you can use simple setup without a broker, works fine, no limitations at all.&lt;/P&gt;
&lt;P&gt;What&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/10384"&gt;@Alex-&lt;/a&gt;&amp;nbsp;gave are great references.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2025 12:08:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Can-I-implement-Identity-Awareness-without-using-a-PDP-PEP/m-p/260800#M44119</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-24T12:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: Can I implement Identity Awareness without using a PDP/PEP Broker?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Can-I-implement-Identity-Awareness-without-using-a-PDP-PEP/m-p/260824#M44124</link>
      <description>&lt;P&gt;One more reference.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_IdentityAwareness_AdminGuide/CP_R82_IdentityAwareness_AdminGuide.pdf" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82/WebAdminGuides/EN/CP_R82_IdentityAwareness_AdminGuide/CP_R82_IdentityAwareness_AdminGuide.pdf&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2025 18:27:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Can-I-implement-Identity-Awareness-without-using-a-PDP-PEP/m-p/260824#M44124</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-10-24T18:27:40Z</dc:date>
    </item>
    <item>
      <title>Re: Can I implement Identity Awareness without using a PDP/PEP Broker?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Can-I-implement-Identity-Awareness-without-using-a-PDP-PEP/m-p/260831#M44126</link>
      <description>&lt;P&gt;Identity Broker is used to achieve better&amp;nbsp;scalability reasons in larger environments.&lt;BR /&gt;It also enables certain use cases like one-way sharing of identity data as well as cross-SIC domain sharing.&lt;BR /&gt;For simple deployments with on-prem AD, Identity Collector is your best bet.&lt;BR /&gt;ADQuery is not recommended any longer due to security and scalability issues with WMI.&lt;/P&gt;</description>
      <pubDate>Fri, 24 Oct 2025 22:14:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Can-I-implement-Identity-Awareness-without-using-a-PDP-PEP/m-p/260831#M44126</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-10-24T22:14:33Z</dc:date>
    </item>
  </channel>
</rss>

