<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: R80.20 Identity Awareness API in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Identity-Awareness-API/m-p/25094#M5022</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it's enabled in SmartConsole&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 18 Jan 2019 13:35:20 GMT</pubDate>
    <dc:creator>CP-NDA</dc:creator>
    <dc:date>2019-01-18T13:35:20Z</dc:date>
    <item>
      <title>R80.20 Identity Awareness API</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Identity-Awareness-API/m-p/25092#M5020</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I'm trying to implement IA API &amp;amp; clearpass however API URL is not responding and pdp API status returns Invalid colmand&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do we need to enable something on the gateway on top of SmartConsole config (IA source)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Jan 2019 19:58:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Identity-Awareness-API/m-p/25092#M5020</guid>
      <dc:creator>CP-NDA</dc:creator>
      <dc:date>2019-01-17T19:58:37Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Identity Awareness API</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Identity-Awareness-API/m-p/25093#M5021</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Nicolas,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Did you enable Identity Web API and allowed the specific hosts under Gateway's IA configuration??&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" height="283" src="https://community.checkpoint.com/legacyfs/online/checkpoint/77090_pastedImage_2.png" width="609" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2019 13:20:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Identity-Awareness-API/m-p/25093#M5021</guid>
      <dc:creator>KennyManrique</dc:creator>
      <dc:date>2019-01-18T13:20:43Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Identity Awareness API</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Identity-Awareness-API/m-p/25094#M5022</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes it's enabled in SmartConsole&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2019 13:35:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Identity-Awareness-API/m-p/25094#M5022</guid>
      <dc:creator>CP-NDA</dc:creator>
      <dc:date>2019-01-18T13:35:20Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Identity Awareness API</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Identity-Awareness-API/m-p/25095#M5023</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you set the allowed interfaces?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/77115_pastedImage_1.png" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For my first try, I forgot to do that.&lt;/P&gt;&lt;P&gt;Here's what I saw when I queried the API endpoint directly using curl from a Linux machine:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P class=""&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;curl --silent --insecure -XPOST &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://" rel="nofollow"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;gw-ip&amp;gt;/_IA_API/idasdk/show-identity -H "Content-Type: application/json" --data-binary "{}"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&amp;lt;!DOCTYPE html&amp;gt;&amp;lt;HTML&amp;gt;&amp;lt;HEAD&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&amp;lt;meta http-equiv="Content-Type" content="text/html; charset=utf-8"&amp;gt;&amp;lt;meta http-equiv="X-UA-Compatible" content="IE=EmulateIE9,EmulateIE8"&amp;gt;&amp;lt;meta name="others" content="WEBUI LOGIN PAGE"&lt;SPAN class=""&gt;&amp;nbsp; &lt;/SPAN&gt;/&amp;gt;&amp;lt;TITLE&amp;gt;Gaia&amp;lt;/TITLE&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&amp;lt;link rel="shortcut icon" href="https://community.checkpoint.com/login/fav.ico"&amp;gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&amp;lt;link rel="stylesheet" type="text/css" href="https://community.checkpoint.com/login/ext-all.css" /&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&amp;lt;link rel="stylesheet" type="text/css" href="https://community.checkpoint.com/login/login.css" /&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&amp;lt;STYLE TYPE="text/css"&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;.ext-ie .webui-login-fld{font-size: 11px;}&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&amp;lt;/STYLE&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&amp;lt;script type="text/javascript" src="/login/ext-base.js"&amp;gt;&amp;lt;/script&amp;gt;&amp;lt;script type="text/javascript" src="/login/ext-all.js"&amp;gt;&amp;lt;/script&amp;gt;&amp;lt;script type="text/javascript"&amp;gt;var errMsgText = "";var bannerMsgText = "";bannerMsgText += "This system is for authorized use only.";var hostname='';var version='R80.20';var formAction="/cgi-bin/home.tcl";&amp;lt;/script&amp;gt;&amp;lt;script type="text/javascript" src="/login/login.js"&amp;gt;&amp;lt;/script&amp;gt;&amp;lt;/HEAD&amp;gt;&amp;lt;BODY&amp;gt;&amp;lt;noscript&amp;gt;&amp;lt;div style='font-size:20px;position:relative;top:100px;'&amp;gt;For full functionality of this site it is necessary to enable JavaScript.&amp;lt;/div&amp;gt;&amp;lt;/noscript&amp;gt;&amp;lt;/BODY&amp;gt;&amp;lt;/HTML&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This tells me MultiPortal believes the connection should go to the Gaia portal, which is the default.&lt;/P&gt;&lt;P&gt;After setting the allowed interfaces for the IDA API as shown above, I got a different message when querying the API:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;&lt;STRONG style="font-family: 'courier new', courier, monospace;"&gt;&lt;SPAN&gt;curl --silent --insecure -XPOST &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://" rel="nofollow"&gt;https://&lt;/A&gt;&lt;SPAN&gt;&amp;lt;gw-ip&amp;gt;/_IA_API/idasdk/show-identity -H "Content-Type: application/json" --data-binary "{}"&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&amp;lt;!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&amp;lt;HTML&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&amp;lt;HEAD&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&amp;lt;TITLE&amp;gt; 404 File Not Found &amp;lt;/TITLE&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&amp;lt;/HEAD&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&amp;lt;BODY&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;The URL you requested could not be found on this server.&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&amp;lt;/BODY&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&amp;lt;/HTML&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;When I actually pass the correct information via the API call, I get a meaningful result:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P class=""&gt;&lt;SPAN style="font-family: 'courier new', courier, monospace;"&gt;&lt;STRONG&gt;&lt;SPAN class=""&gt;&lt;SPAN&gt;curl --silent --insecure -XPOST &lt;/SPAN&gt;&lt;A class="jive-link-external-small" href="https://10.6.5.1/_IA_API/idasdk/show-identity" rel="nofollow"&gt;https://10.6.5.1/_IA_API/idasdk/show-identity&lt;/A&gt;&lt;SPAN&gt; -H "Content-Type: application/json" --data-binary "{ \"shared-secret\": \"aaaa\", \"ip-address\": \"1.1.1.1\" }"&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;{&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&lt;SPAN class=""&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;"ipv4-address" : "1.1.1.1",&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;&lt;SPAN class=""&gt;&amp;nbsp;&amp;nbsp; &lt;/SPAN&gt;"message" : "total 0 user records were found."&lt;/SPAN&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;SPAN class="" style="font-family: 'courier new', courier, monospace;"&gt;}&lt;/SPAN&gt;&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 18 Jan 2019 23:15:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Identity-Awareness-API/m-p/25095#M5023</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-01-18T23:15:06Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Identity Awareness API</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Identity-Awareness-API/m-p/25096#M5024</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Dameon,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Yes of course we did but we don't get any answer from API... We also tried to change setting On all interface to make sure but without success&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I will try to reboot the gateway this weekend or open a TAC ticket&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jan 2019 06:00:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Identity-Awareness-API/m-p/25096#M5024</guid>
      <dc:creator>CP-NDA</dc:creator>
      <dc:date>2019-01-19T06:00:54Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Identity Awareness API</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Identity-Awareness-API/m-p/25097#M5025</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;No answer at all?&lt;/P&gt;&lt;P&gt;Maybe the firewall access policy is blocking the traffic.&lt;/P&gt;&lt;P&gt;Any logs?&lt;/P&gt;&lt;P&gt;What does tcpdump/fw monitor show?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sat, 19 Jan 2019 18:10:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Identity-Awareness-API/m-p/25097#M5025</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-01-19T18:10:43Z</dc:date>
    </item>
    <item>
      <title>Re: R80.20 Identity Awareness API</title>
      <link>https://community.checkpoint.com/t5/General-Topics/R80-20-Identity-Awareness-API/m-p/115029#M21478</link>
      <description>&lt;P&gt;In R81 your command didn't work for me.&amp;nbsp;&lt;/P&gt;&lt;P&gt;This worked for me:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;curl -k -H "Content-Type: application/json" -d $'{"shared-secret":"aaaaaaa",\n "ip-address":"192.168.1.11"}' https://192.168.0.1/_IA_API/v1.0/show-identity&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="javascript"&gt;[root@lnx ~]# curl -k -H "Content-Type: application/json" -d $'{"shared-secret":"aaaaaaaa",\n "ip-address":"192.168.0.11"}' https://192.168.0.1/_IA_API/v1.0/show-identity
{
   "ipv4-address" : "192.168.0.11",
   "message" : "total 0 user records were found."
}
[root@lnx ~]# &lt;/LI-CODE&gt;</description>
      <pubDate>Wed, 31 Mar 2021 12:32:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/R80-20-Identity-Awareness-API/m-p/115029#M21478</guid>
      <dc:creator>Soeren_Rothe</dc:creator>
      <dc:date>2021-03-31T12:32:10Z</dc:date>
    </item>
  </channel>
</rss>

