<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity awareness &amp; Kerberos transparent auth ? in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33284#M6992</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't need to install anything on actual domain controller. You add a new Windows machine that runs IDC. And it acts as a "proxy" between GW and AD. Reducing load on both. So yes - you will need at least one (or more depending on your network) windows machine (VM or physical) to install IDC.&lt;/P&gt;&lt;P&gt;By doing that we saw incredible reduction of CPU usage on gateway and also no more issues with actual domain controller as AD queries caused lots of headaches as it used WMI.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Fri, 02 Mar 2018 09:02:41 GMT</pubDate>
    <dc:creator>Kaspars_Zibarts</dc:creator>
    <dc:date>2018-03-02T09:02:41Z</dc:date>
    <item>
      <title>Identity awareness &amp; Kerberos transparent auth ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33279#M6987</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I need your help ^^&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I just implemented Identity awareness. The client does not want to use AD query and would like to have transparent authentication.&lt;/P&gt;&lt;P&gt;I decided to set up the id awareness based on Kerberos authentication using the identity agent. The problem is that when I connect to the client machine with my domain name, the identity awareness asks me to retype my domain user and password to recognize me. Could you please tell me how to make this transparent? how can the identity agent recover my identity&amp;nbsp;without retyping my user and password (i.e: by using the authentication data used during my first connection to my&amp;nbsp;PC)?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 01 Mar 2018 22:53:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33279#M6987</guid>
      <dc:creator>Oussama_Kadim1</dc:creator>
      <dc:date>2018-03-01T22:53:54Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness &amp; Kerberos transparent auth ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33280#M6988</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Have you looked into Identity Collector option?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108235&amp;amp;partition=General&amp;amp;product=Identity" title="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108235&amp;amp;partition=General&amp;amp;product=Identity"&gt;Identity Collector - Technical Overview&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;We have have it before it was called IDC and are very satisfied. As it says on the tin:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;H3 style="color: #333333; background-color: #ffffff; font-weight: bold; font-size: 16px;"&gt;Identity Collector key benefits over standard AD Query&lt;/H3&gt;&lt;UL style="color: #000000; background-color: #ffffff; font-size: 14px;"&gt;&lt;LI&gt;Reduces the load on the Security Gateway - the agent is doing the queries instead of the Security Gateway.&lt;/LI&gt;&lt;LI&gt;Reduces the load on the DCs - the native Windows API used consumes less resources.&lt;/LI&gt;&lt;LI&gt;The Identity Collector requires no administrator or administrator-like permissions. Only permission required is read-only access to the domain security logs.&lt;/LI&gt;&lt;LI&gt;One Identity Collector can serve multiple Security Gateways, even from different CMA.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Plus nothing to install on the client.&lt;/P&gt;&lt;P&gt;We are 25000+ users organization and AD query was not built for that scale. plus we wanted to avoid any installs on the client.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2018 06:50:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33280#M6988</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-03-02T06:50:19Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness &amp; Kerberos transparent auth ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33281#M6989</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;did you set the corresponding SPN?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2018 08:19:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33281#M6989</guid>
      <dc:creator>cstueckrath</dc:creator>
      <dc:date>2018-03-02T08:19:43Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness &amp; Kerberos transparent auth ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33282#M6990</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you use a dedicated machine for that? since the collector require java env maybe some customer could argue with that choice &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2018 08:39:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33282#M6990</guid>
      <dc:creator>Marco_Valenti</dc:creator>
      <dc:date>2018-03-02T08:39:41Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness &amp; Kerberos transparent auth ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33283#M6991</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/migrated-users/47831"&gt;Kaspars Zibarts&lt;/A&gt;‌:&amp;nbsp;unfortunately&amp;nbsp;&lt;SPAN lang="en"&gt;we can not install anything on AD it's forbidden.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="en"&gt;@Christian Stueckrath: yes I added the corresponding SPN on the AD (It is working when I enter manually my AD login and password on the Identity agent)&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2018 08:47:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33283#M6991</guid>
      <dc:creator>Oussama_Kadim1</dc:creator>
      <dc:date>2018-03-02T08:47:25Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness &amp; Kerberos transparent auth ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33284#M6992</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You don't need to install anything on actual domain controller. You add a new Windows machine that runs IDC. And it acts as a "proxy" between GW and AD. Reducing load on both. So yes - you will need at least one (or more depending on your network) windows machine (VM or physical) to install IDC.&lt;/P&gt;&lt;P&gt;By doing that we saw incredible reduction of CPU usage on gateway and also no more issues with actual domain controller as AD queries caused lots of headaches as it used WMI.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2018 09:02:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33284#M6992</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-03-02T09:02:41Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness &amp; Kerberos transparent auth ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33285#M6993</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Yes, I agree with you I will present this solution to the client but&amp;nbsp;&lt;SPAN lang="en"&gt;the Identity Agent solution has been validated in CAB and it will be very difficult&amp;nbsp;for the client to rollback :S&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2018 09:10:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33285#M6993</guid>
      <dc:creator>Oussama_Kadim1</dc:creator>
      <dc:date>2018-03-02T09:10:12Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness &amp; Kerberos transparent auth ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33286#M6994</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #333333; background-color: #ffffff;"&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;yes I added the corresponding SPN on the AD (It is working when I enter manually my AD login and password on the Identity agent)&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2018 09:20:56 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33286#M6994</guid>
      <dc:creator>Oussama_Kadim1</dc:creator>
      <dc:date>2018-03-02T09:20:56Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness &amp; Kerberos transparent auth ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33287#M6995</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Just part of our daily lives &lt;img id="smileyhappy" class="emoticon emoticon-smileyhappy" src="https://community.checkpoint.com/i/smilies/16x16_smiley-happy.png" alt="Smiley Happy" title="Smiley Happy" /&gt;&amp;nbsp;took as nearly 2 years to get IA running as expected&amp;nbsp;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2018 10:00:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33287#M6995</guid>
      <dc:creator>Kaspars_Zibarts</dc:creator>
      <dc:date>2018-03-02T10:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness &amp; Kerberos transparent auth ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33288#M6996</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It was an SPN issue, it is working now, thank you all for your feedback.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 02 Mar 2018 13:30:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33288#M6996</guid>
      <dc:creator>Oussama_Kadim1</dc:creator>
      <dc:date>2018-03-02T13:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness &amp; Kerberos transparent auth ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33289#M6997</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;What was the SPN issue? Maybe I'm running into the same problem.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2018 12:26:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33289#M6997</guid>
      <dc:creator>Piet_vd_Maas_2</dc:creator>
      <dc:date>2018-12-17T12:26:33Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness &amp; Kerberos transparent auth ?</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33290#M6998</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To check if there is any SPN issue, make a flow capture with wireshark in your Kerberos server (Active directory) and&amp;nbsp; filter kerberos flows and you will see the error.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 17 Dec 2018 13:33:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-awareness-Kerberos-transparent-auth/m-p/33290#M6998</guid>
      <dc:creator>Oussama_Kadim1</dc:creator>
      <dc:date>2018-12-17T13:33:49Z</dc:date>
    </item>
  </channel>
</rss>

