<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Question about identiy broker in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281996#M46882</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/100677"&gt;@RemoteUser&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Identity and Trust (the new name for Infinity Identity) presents a different approach to identity flow in Quantum.&lt;/P&gt;
&lt;P&gt;You can think of Identity and Trust as a PDP-as-a-server, but more capable.&lt;/P&gt;
&lt;P&gt;However, as Vincent mentioned, it is a design question you should consider.&lt;/P&gt;
&lt;P&gt;If for one of the following questions, the answer is "yes", Identity and Trust is definitely your solution:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;You have an identity integration that works only with Identity and Trust - Entra ID &amp;amp; Intune or Defender, CrowdStrike Falcon, Check Point services such as SASE, Endpoint, Browse and Workforce AI.&lt;/LI&gt;
&lt;LI&gt;You want to use trust information (device or user posture) in the policy, alongside user, device, and group membership.&lt;/LI&gt;
&lt;LI&gt;You would like to reduce IDA deployment complexity.&lt;/LI&gt;
&lt;LI&gt;Have a centralized single source of truth for identity.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have questions, I'm here to answer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 09 Sep 2026 13:02:18 GMT</pubDate>
    <dc:creator>Royi_Priov</dc:creator>
    <dc:date>2026-09-09T13:02:18Z</dc:date>
    <item>
      <title>Question about identity broker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281980#M46870</link>
      <description>&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Hi Mates,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;I have a question regarding an Identity Broker setup.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;We have multiple CMAs managed by the same MDS, and we currently have a cluster acting as the Identity Broker for sharing identities between the different CMAs.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Would it be possible to move the Identity Broker cluster from CMA X to another CMA (CMA Y)?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;If so, could you please advise on the expected behavior and whether there are any specific considerations, limitations, or precautions we should take into account before performing the move?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks in advance&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2026 08:48:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281980#M46870</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-09-10T08:48:21Z</dc:date>
    </item>
    <item>
      <title>Re: Question about identiy broker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281985#M46874</link>
      <description>&lt;P dir="ltr"&gt;Hi,&lt;/P&gt;
&lt;P dir="ltr"&gt;Moving the broker cluster to another CMA is possible, no rocket science.&lt;/P&gt;
&lt;P dir="ltr"&gt;The good news: the actual publisher/subscriber relationships live in the identity_broker.C on the gateway itself, so they survive the move untouched. A few things don't, though:&lt;/P&gt;
&lt;UL dir="ltr"&gt;
&lt;LI&gt;The subscriber certificate is configured in the gateway object, so that setting lives in the CMA X database and needs to be set up again in CMA Y. If you re-use the same certificate, the publishers won't notice anything. If a new cert gets issued (e.g. because the old one came from CMA X's ICA), the publisher side may need updating too. If not, you may have to issue&amp;nbsp;BrokerCertFetcher &amp;lt;subscriber ip&amp;gt; to retrieve the cert and to be able to update the identity_broker.C in case cert is verified.&lt;/LI&gt;
&lt;LI&gt;Think about where the broker gets its own sessions from. Identity Collector and agents reconnect by IP, so if the IP stays the same you mainly need to redo the settings in the new gateway object. VPN clients are the tricky part I never used this identity source.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P dir="ltr"&gt;One more thing to keep in mind: before R82.10, classic PDP-to-PEP sharing only works within the same CMA, so any PEPs served by this PDP need to stay in CMA Y with it. If you're on R82.10 already, direct cross-domain PDP-to-PEP sharing might even let you simplify the whole setup.&lt;/P&gt;
&lt;P dir="ltr"&gt;Cheers&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 11:34:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281985#M46874</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2026-09-09T11:34:22Z</dc:date>
    </item>
    <item>
      <title>Re: Question about identiy broker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281986#M46875</link>
      <description>&lt;P&gt;Hi vincnet,&lt;BR /&gt;Thank you for the reply,&lt;BR /&gt;Could you explain that last sentence in more detail? We actullay running on R82.10 but on S1C not the GW's itself&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 11:56:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281986#M46875</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-09-09T11:56:50Z</dc:date>
    </item>
    <item>
      <title>Re: Question about identiy broker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281987#M46876</link>
      <description>&lt;P&gt;Sure,&lt;BR /&gt;what i was talking about is the new feature called "scaled identity sharing" allowing to share identities e.g from your broker gateway to a maximum of 300 PEP (enforcing firewalls) in same or different CMA.&lt;BR /&gt;This works well, I already tested this in lab environment.&lt;BR /&gt;&lt;BR /&gt;This is documented here:&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_IdentityAwareness_AdminGuide/Content/Topics-IDAG/Identity-Awareness-Config-Identity-Sharing-Scaled-Sharing.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_IdentityAwareness_AdminGuide/Content/Topics-IDAG/Identity-Awareness-Config-Identity-Sharing-Scaled-Sharing.htm&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 12:09:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281987#M46876</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2026-09-09T12:09:12Z</dc:date>
    </item>
    <item>
      <title>Re: Question about identiy broker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281988#M46877</link>
      <description>&lt;P&gt;Thank you, but the standard GW (PEP) also needs to be updated to version R82.10... If this configuration only required the PDP to be updated to version R82.10, I could simply ask the customer to update the PDP broker, but since we have to update many GWs, that takes a lot of time, too!&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 12:13:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281988#M46877</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-09-09T12:13:53Z</dc:date>
    </item>
    <item>
      <title>Re: Question about identiy broker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281990#M46878</link>
      <description>&lt;P dir="ltr"&gt;Fair point — upgrading many PEPs is indeed the price for scaled sharing, and we haven't migrated to R82.10 ourselves yet either, because it takes time to upgrade more than 300 devices.&lt;BR /&gt;I just mentioned it as it might be useful down the road.&lt;/P&gt;
&lt;P dir="ltr"&gt;Everything I wrote about moving the Identity Broker is independent of this anyway — that works on your current version as-is.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 12:29:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281990#M46878</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2026-09-09T12:29:00Z</dc:date>
    </item>
    <item>
      <title>Re: Question about identiy broker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281991#M46879</link>
      <description>&lt;P&gt;What do you think about the infinity idenitty? This, too, could be an alternative?&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 12:30:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281991#M46879</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-09-09T12:30:35Z</dc:date>
    </item>
    <item>
      <title>Re: Question about identiy broker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281994#M46880</link>
      <description>&lt;P dir="ltr"&gt;Phew. Infinity Identity could be an option, but honestly that's a design question rather than a quick swap.&lt;BR /&gt;To have an idea if it's an option, more details would be useful i guess and i am not experienced with infinity identity.&lt;BR /&gt;Anyway, I'd say it depends on where your identities come from (IDC/AD, ISE, cloud IdPs like Entra ID), how you use them in policy, and where your users and enforcement points sit.&lt;/P&gt;
&lt;P dir="ltr"&gt;Two things to keep in mind though: gateway integration with Infinity Identity is a recent addition (R82/R82.10), so you'd likely face the same upgrade effort you wanted to avoid with scaled sharing. If I am not wrong.&lt;/P&gt;
&lt;P dir="ltr"&gt;For your original question — just moving the broker to another CMA — you don't need any of this.&lt;BR /&gt;&lt;BR /&gt;Would evaluate Infinity Identity separately as a longer-term design topic in case it fit's your setup.&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 12:53:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281994#M46880</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2026-09-09T12:53:01Z</dc:date>
    </item>
    <item>
      <title>Re: Question about identiy broker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281996#M46882</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/100677"&gt;@RemoteUser&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Identity and Trust (the new name for Infinity Identity) presents a different approach to identity flow in Quantum.&lt;/P&gt;
&lt;P&gt;You can think of Identity and Trust as a PDP-as-a-server, but more capable.&lt;/P&gt;
&lt;P&gt;However, as Vincent mentioned, it is a design question you should consider.&lt;/P&gt;
&lt;P&gt;If for one of the following questions, the answer is "yes", Identity and Trust is definitely your solution:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;You have an identity integration that works only with Identity and Trust - Entra ID &amp;amp; Intune or Defender, CrowdStrike Falcon, Check Point services such as SASE, Endpoint, Browse and Workforce AI.&lt;/LI&gt;
&lt;LI&gt;You want to use trust information (device or user posture) in the policy, alongside user, device, and group membership.&lt;/LI&gt;
&lt;LI&gt;You would like to reduce IDA deployment complexity.&lt;/LI&gt;
&lt;LI&gt;Have a centralized single source of truth for identity.&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you have questions, I'm here to answer &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 13:02:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281996#M46882</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2026-09-09T13:02:18Z</dc:date>
    </item>
    <item>
      <title>Re: Question about identiy broker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281997#M46883</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;&amp;nbsp;Sorry to contradict you, but it’s not quite that universal. We also want to &lt;BR /&gt;reduce the complexity of IDA deployment.&lt;BR /&gt;But that’s not always possible. For example, in future we’ll only be using IDA for Cisco’s SGT, as there’s simply no identity and trust involved there (why do I always have to get used to new names?&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":grinning_face:"&gt;😀&lt;/span&gt; )&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 13:12:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281997#M46883</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2026-09-09T13:12:36Z</dc:date>
    </item>
    <item>
      <title>Re: Question about identiy broker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281998#M46884</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/16383"&gt;@Vincent_Bacher&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Identity and Trust does support Cisco SGT via Identity Collector.&lt;/P&gt;
&lt;P&gt;I was referring to reducing IDA sharing &amp;amp; Broker topology.&lt;/P&gt;
&lt;P&gt;Identity and Trust can scale up if needed, so customers don't need to deploy PDPs and change the environment configuration just to support more identities / different requirements.&lt;/P&gt;
&lt;P&gt;In addition, I&amp;amp;T is a single place for configuration - configure your directories, integrations, and filters once, and that's it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;As for the naming - I can't control it &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt; It was done as part of bigger CP branding, but I'm satisfied with the new name&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":smiling_face_with_heart_eyes:"&gt;😍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 13:19:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/281998#M46884</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2026-09-09T13:19:42Z</dc:date>
    </item>
    <item>
      <title>Re: Question about identiy broker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/282000#M46885</link>
      <description>&lt;P&gt;OK, makes sense, thanks for your explanation.&lt;BR /&gt;In our use case we already have a (we call it) identity backbone and it works so I will not change it.&amp;nbsp;&lt;BR /&gt;But in other environments it seem to be really feasible to have this as an option.&lt;BR /&gt;thanks,&amp;nbsp;&lt;BR /&gt;best,&lt;BR /&gt;Vince&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 13:24:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/282000#M46885</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2026-09-09T13:24:06Z</dc:date>
    </item>
    <item>
      <title>Re: Question about identiy broker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/282094#M46939</link>
      <description>&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;Hi Vincent, sorry to bother you again, but I just thought of another question.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P class="isSelectedEnd"&gt;&lt;SPAN&gt;If I move those PDP clusters (Identity Broker) to another CMA, what happens to the Identity Sharing relationship with the PEP Gateways that remain in the original CMA?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;More specifically, would moving the PDP to a different CMA cause the PEPs to lose access to the shared identities, or does Identity Sharing continue to work across different CMAs?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 09 Sep 2026 19:04:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/282094#M46939</guid>
      <dc:creator>RemoteUser</dc:creator>
      <dc:date>2026-09-09T19:04:32Z</dc:date>
    </item>
    <item>
      <title>Re: Question about identiy broker</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/282113#M46948</link>
      <description>&lt;P dir="ltr"&gt;No bother at all.&lt;/P&gt;
&lt;P dir="ltr"&gt;That's exactly the catch I hinted at earlier: classic PDP-to-PEP sharing does not cross CMA borders. So yes — the moment the broker PDP lives in CMA Y, the PEPs left behind in CMA X lose their identities. Nothing crashes, they just stop receiving sessions.&lt;/P&gt;
&lt;P dir="ltr"&gt;The classic way out: keep (or build) at least one PDP in CMA X and let your broker push the sessions to it as a subscriber. That local PDP then feeds the PEPs in CMA X the traditional way. Works fine, it's just one more box in the identity chain.&lt;/P&gt;
&lt;P dir="ltr"&gt;And this is where the R82.10 scaled identity sharing I mentioned becomes interesting after all — with that, a PDP can share directly to PEPs in a different CMA, so the extra PDP in the old CMA wouldn't be needed anymore. But as discussed, that requires the PEPs on R82.10 too, so for your current situation the subscriber PDP in CMA X is the way to go.&lt;/P&gt;
&lt;P dir="ltr"&gt;Cheers&lt;/P&gt;</description>
      <pubDate>Thu, 10 Sep 2026 06:22:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Question-about-identity-broker/m-p/282113#M46948</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2026-09-10T06:22:06Z</dc:date>
    </item>
  </channel>
</rss>

