<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity awareness and AD logs in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-and-AD-logs/m-p/32188#M6731</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have&amp;nbsp;at least two other options:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Browser-based authentication (Captive Portal)&lt;/LI&gt;&lt;LI&gt;Identity Collector (which doesn't use AD logs), see here for a technical overview:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108235" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108235"&gt;Identity Collector - Technical Overview&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63311_pastedImage_1.png" style="width: 620px; height: 432px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 23 Feb 2018 18:48:10 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2018-02-23T18:48:10Z</dc:date>
    <item>
      <title>Identity awareness and AD logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-and-AD-logs/m-p/32187#M6730</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Bonjour,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Je souhaiterai&amp;nbsp;implémenter l'ID Awareness sur checkpoint basé sur une authentification AD.&lt;/P&gt;&lt;P&gt;Le problème qui se pose est que le client ne souhaite pas que l'AD envoi les events logs au checkpoint.&lt;/P&gt;&lt;P&gt;Pouvez vous me dire si il y a une possibilité de faire de l'ID awareness avec une authentification AD sans que le Firewall ne recupère les events Logs AD ( Genre le client envoi un ticket Kerberos directement au Checkpoint).&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Cordialement.&lt;/P&gt;&lt;P&gt;---------------------------------------------------------------------------------------------------------------------------------------------------------&lt;/P&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to implement ID Awareness on checkpoint based on AD authentication.&lt;/P&gt;&lt;P&gt;The problem is that the client does not want that the AD&amp;nbsp;sends the events logs to the checkpoint.&lt;/P&gt;&lt;P&gt;Could you please tell me if there is an option to make the ID awareness based on AD&amp;nbsp;authentication on the checkpoint without AD event logs?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Feb 2018 12:39:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-and-AD-logs/m-p/32187#M6730</guid>
      <dc:creator>Oussama_Kadim1</dc:creator>
      <dc:date>2018-02-23T12:39:47Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness and AD logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-and-AD-logs/m-p/32188#M6731</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You have&amp;nbsp;at least two other options:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;Browser-based authentication (Captive Portal)&lt;/LI&gt;&lt;LI&gt;Identity Collector (which doesn't use AD logs), see here for a technical overview:&amp;nbsp;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108235" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108235"&gt;Identity Collector - Technical Overview&lt;/A&gt;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;IMG class="image-1 jive-image" src="https://community.checkpoint.com/legacyfs/online/checkpoint/63311_pastedImage_1.png" style="width: 620px; height: 432px;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 23 Feb 2018 18:48:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-and-AD-logs/m-p/32188#M6731</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-02-23T18:48:10Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness and AD logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-and-AD-logs/m-p/32189#M6732</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thank you for your answer.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 25 Feb 2018 00:35:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-and-AD-logs/m-p/32189#M6732</guid>
      <dc:creator>Oussama_Kadim1</dc:creator>
      <dc:date>2018-02-25T00:35:09Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness and AD logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-and-AD-logs/m-p/32190#M6733</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/2075"&gt;Dameon Welch Abernathy&lt;/A&gt;‌&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am currently facing the same problem, and according to your link the Identity Collector does also need the security logs from the DCs:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H3&gt;Technical Description&lt;/H3&gt;&lt;P&gt;The Identity Collector is using the Windows Event Log API for fetching the DC's security logs.&lt;BR /&gt; Windows Event Log is included in the operating system beginning with Windows Vista and Windows Server 2008 (client and server).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2018 11:00:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-and-AD-logs/m-p/32190#M6733</guid>
      <dc:creator>Carsten_Pfitzer</dc:creator>
      <dc:date>2018-07-09T11:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness and AD logs</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-and-AD-logs/m-p/32191#M6734</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, you're right, I missed that.&lt;/P&gt;&lt;P&gt;The main difference between AD Query and Identity Collector is the API used to acquire the information.&lt;/P&gt;&lt;P&gt;The reason we need to read the security logs is to automatically associate IP addresses to usernames and machine names.&lt;/P&gt;&lt;P&gt;LDAP is used to get groups, which are also relevant for Access Roles.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Identity Agent can also get the information, but this requires installing agents on the local PCs.&lt;/P&gt;&lt;P&gt;There is also an agent for Terminal Servers.&lt;/P&gt;&lt;P&gt;And of course Captive Portal, as I mentioned earlier (but this is not necessarily automatic).&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 09 Jul 2018 11:16:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-and-AD-logs/m-p/32191#M6734</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2018-07-09T11:16:26Z</dc:date>
    </item>
  </channel>
</rss>

