<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness auth and validation in separate domains? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-auth-and-validation-in-separate-domains/m-p/26639#M5436</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Paul, when used 2 domains, AD query will bring two events of logon (1 per domain). IP of Terminal server will be diferent of their workstation and, because transparent kerberos, the identity of user will work fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 23 Jan 2019 17:10:48 GMT</pubDate>
    <dc:creator>Alessandro_Marr</dc:creator>
    <dc:date>2019-01-23T17:10:48Z</dc:date>
    <item>
      <title>Identity Awareness auth and validation in separate domains?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-auth-and-validation-in-separate-domains/m-p/26636#M5433</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;With Identity Awareness is it possible to authenticate against one domain, and have Check Point validate the group membership for that user against another domain, thus providing them access if the same username exists in both domains?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have a scenario where users are in Domain A. They are on workstations and also a Terminal Server in the same Domain A. They need to access resources in Domain B which is behind Check Point gateways, and there is a business requirement to identify the users by authenticating them against the isolated Domain B only (as it a secure environment).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this possible&amp;nbsp;or&amp;nbsp;could&amp;nbsp;we only authenticate against Domain A in this scenario?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I guess Captive Portal could be used for the users on workstations, and have&amp;nbsp;Check Point authenticate against Domain B, and the users use their Domain B accounts when authenticating?&lt;/P&gt;&lt;P&gt;But I don't see a method that would work for the Terminal Server, as the Identity Agent will pass on the credentials from Domain A.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Any thoughts?&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jan 2019 11:20:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-auth-and-validation-in-separate-domains/m-p/26636#M5433</guid>
      <dc:creator>Paul_Hewitson</dc:creator>
      <dc:date>2019-01-23T11:20:57Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness auth and validation in separate domains?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-auth-and-validation-in-separate-domains/m-p/26637#M5434</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You will create a object Ldap Account Unit for this second domain and setup your identity awareness to search on both.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am considering you are using AD query...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jan 2019 13:17:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-auth-and-validation-in-separate-domains/m-p/26637#M5434</guid>
      <dc:creator>Alessandro_Marr</dc:creator>
      <dc:date>2019-01-23T13:17:57Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness auth and validation in separate domains?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-auth-and-validation-in-separate-domains/m-p/26638#M5435</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;thanks for the reply Alessandro&lt;/P&gt;&lt;P&gt;The issue I have is the 2 domains are isolated from each other, there is no trust or any connectivity.&lt;/P&gt;&lt;P&gt;The user&amp;nbsp;will have logged into Domain A on their workstation or Terminal Server. If I used AD query against Domain A &amp;amp; Domain B, it would pick up the user from Domain A, but it wouldn't see any login events on Domain B for that user&lt;/P&gt;&lt;P&gt;The business requirement is that the user is authenticated against Domain B by the Check Point somehow. The only way I can see this working is to use Captive Portal where you could you just put the Domain B credentials into the webpage.&lt;/P&gt;&lt;P&gt;With a terminal server the only option seems to be to use the Identity Agent which would pass the user's Domain A credentials through.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I can't see any scenario where I can get terminal server user's to authenticate as Domain B users. Or is it possible to map the username from Domain A onto Domain B, so that the user log onto Domain A, the agent passes this to Check Point, and Check Point looks up the same username in Domain B, and we can allow access based on group membership or the fact that this account is active in Domain B.&lt;/P&gt;&lt;P&gt;Or is Kerberos or something involved here so this is not possible?&lt;/P&gt;&lt;P&gt;Not sure if I'm explaining myself very clearly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We&amp;nbsp;could have&amp;nbsp;potentially used Check Point EndPoint client instead for access, for which I could specific Domain B DC for authentication, but this client isn't supported to be used from a Terminal Server. That seems to be the key issue in both cases.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jan 2019 15:30:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-auth-and-validation-in-separate-domains/m-p/26638#M5435</guid>
      <dc:creator>Paul_Hewitson</dc:creator>
      <dc:date>2019-01-23T15:30:22Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness auth and validation in separate domains?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-auth-and-validation-in-separate-domains/m-p/26639#M5436</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Paul, when used 2 domains, AD query will bring two events of logon (1 per domain). IP of Terminal server will be diferent of their workstation and, because transparent kerberos, the identity of user will work fine.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 23 Jan 2019 17:10:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-auth-and-validation-in-separate-domains/m-p/26639#M5436</guid>
      <dc:creator>Alessandro_Marr</dc:creator>
      <dc:date>2019-01-23T17:10:48Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness auth and validation in separate domains?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-auth-and-validation-in-separate-domains/m-p/26640#M5437</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;The trouble with this solution is that the user will not have logged into Domain B (it's isolated from Domain A where the user is located), so there won't be any authentication events in that Domain for AD query to pick up. So I can only authenticate against the local Domain A.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've labbed this up yesterday, and&amp;nbsp;I think I've come to the assumption this is not possible for users on a Terminal Server, since User Identity maps a user to an IP address, and the only option for Terminal Server access is to use the agent, and the agent passes the local domain credentials of the user including the DN and the SID, so Check Point can only validate this against the local Domain A also.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I've also tried using Mobile Blade + SSL extender to provide access into the Domain B environment from terminal server users. I can have this authenticate against Domain B no problem, and run applications through SSL Extender. But as soon as I logon&amp;nbsp;a 2nd&amp;nbsp;TS user then they cannot run SSL extender. Which to be fair ties in with the support statement from Check Point that Remote VPN clients are not supported on multi-user servers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Unfortunately I'm out of ideas&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 25 Jan 2019 09:57:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-auth-and-validation-in-separate-domains/m-p/26640#M5437</guid>
      <dc:creator>Paul_Hewitson</dc:creator>
      <dc:date>2019-01-25T09:57:36Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness auth and validation in separate domains?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-auth-and-validation-in-separate-domains/m-p/26641#M5438</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://community.checkpoint.com/migrated-users/63537"&gt;Paul Hewitson&lt;/A&gt;‌,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I understand correctly, although the user was not authenticated&amp;nbsp;in front of domain B active directory, you still want us to authenticate and associate the user with this domain.&lt;/P&gt;&lt;P&gt;In most identity sources we are receiving the domain explicitly in the login information, so&amp;nbsp;PDP will go and look for an account unit for this domain.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;In case you want to give up the "domain A" identity completely, you can map domain a to domain b with Identity Collector alias feature. You can set up different IDC which will serve this gateway, and all authentications which will be done to domain A active directory will be sent to the GW as domain B authentications.&lt;/P&gt;&lt;P&gt;another option, as you have mentioned, is to use the captive portal, and specify domain B in the username (e.g. &lt;A href="mailto:user@domainb"&gt;user@domainb&lt;/A&gt;&amp;nbsp;or domainb/user - depends on the UserLoginAttr configured for this realm).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope this helps!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Royi.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 05 Feb 2019 09:32:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-auth-and-validation-in-separate-domains/m-p/26641#M5438</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2019-02-05T09:32:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness auth and validation in separate domains?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-auth-and-validation-in-separate-domains/m-p/118398#M22028</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We integrate Active Directory servers by creating LDAP units of account. Domain user authentication is done through a VPN Check Point mobile client.&lt;BR /&gt;When a client connects to a domain that is registered with Check Point, everything is normal. Their respective logs are generated in SmartConsole and everything is ok.&lt;/P&gt;&lt;P&gt;The problem arises, there are several users who have a user with the same name in one domain and registered with the same name in another subdomain.&lt;BR /&gt;For example:&lt;BR /&gt;JonhDoe@domain.com&lt;BR /&gt;JonhDoe@subdomain.domain.com&lt;/P&gt;&lt;P&gt;The priority of subdomain.domain.com is set to 1, and the priority of domain.com is set to 5.&lt;BR /&gt;When the user enters his username JonhDoe, he manages to access the domain.com that has lower priority, when he should access subdomain.domain.com&lt;/P&gt;&lt;P&gt;Is there a way that the user can choose which domain he wants to connect to from the VPN client?&lt;BR /&gt;For example, have the user enter JonhDoe@domain.com or&lt;BR /&gt;JonhDoe@subdomain.domain.com and from there it is determined which domain it will access?&lt;BR /&gt;&lt;BR /&gt;We have a SMS and Firewall cluster on R80.30 version&lt;BR /&gt;Regards!&lt;/P&gt;</description>
      <pubDate>Fri, 14 May 2021 15:01:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Awareness-auth-and-validation-in-separate-domains/m-p/118398#M22028</guid>
      <dc:creator>israelsc</dc:creator>
      <dc:date>2021-05-14T15:01:18Z</dc:date>
    </item>
  </channel>
</rss>

