<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Collector and VPN SSL/SNX in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/225963#M3366</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I saw about&amp;nbsp;&lt;SPAN&gt;changing the Account Unit usage in this video from 3:45 on:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.youtube.com/watch?v=SPF8BYYM1uY&amp;amp;list=PLBfjYlNj4w1tNYJk46ZlumprP0cKvHSS9&amp;amp;index=6" target="_blank"&gt;https://www.youtube.com/watch?v=SPF8BYYM1uY&amp;amp;list=PLBfjYlNj4w1tNYJk46ZlumprP0cKvHSS9&amp;amp;index=6&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;which makes sense, isn't it needed?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Anyway,&amp;nbsp;do you mean that Remote Access clients authenticate directly against the AD through RADIUS and not through AD Query which uses WMI to look into&amp;nbsp;&lt;SPAN class="mc-variable Vars_Other.tp_active_directory variable"&gt;Active Directory&lt;/SPAN&gt;&amp;nbsp;Security Event Logs?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Julián&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 09 Sep 2024 06:24:19 GMT</pubDate>
    <dc:creator>fjulianom</dc:creator>
    <dc:date>2024-09-09T06:24:19Z</dc:date>
    <item>
      <title>Identity Collector and VPN SSL/SNX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/222334#M3360</link>
      <description>&lt;P&gt;Hi community,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My customer has a deployment with many security gateways that currently are using AD Query to map users with IP addresses. He is moving to Identity Collector, and after installed and configured, right now the security gateways are learning login events from both AD Query and Identity Collector. Now and before migrating to only Identity Collector we have a doubt. My customer also has a security gateway running VPN SSL and VPN SNX for remote users, and it validates the remote users againts AD. Do we have to change anything on the configuration of VPN SSL/SNX?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Julián&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 07:13:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/222334#M3360</guid>
      <dc:creator>fjulianom</dc:creator>
      <dc:date>2024-07-31T07:13:29Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and VPN SSL/SNX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/222340#M3361</link>
      <description>&lt;P&gt;The actual authentication of VPN users doesn't leverage Identity Collector. So this would be more about what you don't remove when decommissioning ADquery e.g. LDAP Account units or Radius servers etc.&lt;/P&gt;
&lt;P&gt;There is also the ability to leverage "remote access" as an identity source for identity awareness enforcement in your security policy.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 08:48:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/222340#M3361</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2024-07-31T08:48:15Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and VPN SSL/SNX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/222352#M3362</link>
      <description>&lt;P&gt;Hi Chris,&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;The actual authentication of VPN users doesn't leverage Identity Collector. So this would be more about what you don't remove when decommissioning ADquery e.g. LDAP Account units or Radius servers etc.&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Do you mean my remote users will be still authenticated using RADIUS against the AD and we don't need to touch anything for the remote access section?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Julián&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 18:39:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/222352#M3362</guid>
      <dc:creator>fjulianom</dc:creator>
      <dc:date>2024-07-31T18:39:34Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and VPN SSL/SNX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/222418#M3363</link>
      <description>&lt;P&gt;Yes, it simply means making sure Remote Access is configured as an Identity Source on the relevant gateway object:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27058iE396EB64A0FDD767/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2024 22:41:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/222418#M3363</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-07-31T22:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and VPN SSL/SNX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/225839#M3364</link>
      <description>&lt;P&gt;Hi again,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Still one doubt. My VPN users are authenticated with the AD server (LDAP Account units). According to the Identity Collector guide, we should disable LDAP Query in the LDAP Account Unit object:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Imagen1.png" style="width: 228px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27517i8C7D099F118126F4/image-size/large?v=v2&amp;amp;px=999" role="button" title="Imagen1.png" alt="Imagen1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;And also, change the credentials with a non-admin user in this object:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Imagen2.png" style="width: 278px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27518i06409629BF6AB514/image-size/large?v=v2&amp;amp;px=999" role="button" title="Imagen2.png" alt="Imagen2.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;In this LDAP Account Unit, which is my AD server, all my users who connect to VPN&amp;nbsp;are stored.&lt;/P&gt;
&lt;P&gt;- Then, will they be still authenticated through RADIUS against the AD if Active Directory Query is disabled?&lt;/P&gt;
&lt;P&gt;- If so, if the credentials used are non-admin, isn't there a problem when contacting the AD? We are using Identity Collector because of the&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk180232" target="_blank" rel="noopener"&gt;sk180232&lt;/A&gt;&amp;nbsp;(When AD Query is configured for a user who is not an admin on the Domain Controller (DC), AD Query cannot access the DC.)&lt;/P&gt;
&lt;P&gt;- Or the VPN users will be authenticated not using "AD query" method but "Remote Access" method which is not affected by sk180232?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Julián&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 07:29:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/225839#M3364</guid>
      <dc:creator>fjulianom</dc:creator>
      <dc:date>2024-09-06T07:29:07Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and VPN SSL/SNX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/225877#M3365</link>
      <description>&lt;P&gt;Even with Identity Collector or Remote Access (with RADIUS auth), LDAP is used by the gateway to gather groups.&lt;BR /&gt;Not familiar with where the documentation states to change the Account Unit usage as you’ve shown, so an exact reference to the docs where this was suggested would be helpful.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You should definitely change the credentials used to non-admin credentials, though.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 12:30:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/225877#M3365</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-06T12:30:11Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and VPN SSL/SNX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/225963#M3366</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I saw about&amp;nbsp;&lt;SPAN&gt;changing the Account Unit usage in this video from 3:45 on:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;A href="https://www.youtube.com/watch?v=SPF8BYYM1uY&amp;amp;list=PLBfjYlNj4w1tNYJk46ZlumprP0cKvHSS9&amp;amp;index=6" target="_blank"&gt;https://www.youtube.com/watch?v=SPF8BYYM1uY&amp;amp;list=PLBfjYlNj4w1tNYJk46ZlumprP0cKvHSS9&amp;amp;index=6&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;which makes sense, isn't it needed?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Anyway,&amp;nbsp;do you mean that Remote Access clients authenticate directly against the AD through RADIUS and not through AD Query which uses WMI to look into&amp;nbsp;&lt;SPAN class="mc-variable Vars_Other.tp_active_directory variable"&gt;Active Directory&lt;/SPAN&gt;&amp;nbsp;Security Event Logs?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Julián&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 06:24:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/225963#M3366</guid>
      <dc:creator>fjulianom</dc:creator>
      <dc:date>2024-09-09T06:24:19Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and VPN SSL/SNX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/226016#M3367</link>
      <description>&lt;P&gt;I trust&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/177"&gt;@Peter_Elmer&lt;/a&gt;&amp;nbsp;on these matters &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Meanwhile, Remote Access clients are authenticated through RADIUS and their groups are looked up in LDAP.&lt;BR /&gt;The Remote Access checkbox in the Identity Awareness configuration for the relevant gateway objects is to ensure the users are given their correct Access Roles for Access Policy enforcement.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 16:25:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/226016#M3367</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-09T16:25:05Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and VPN SSL/SNX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/226025#M3368</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Then I will wait for&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/177"&gt;@Peter_Elmer&lt;/a&gt;. My customer is concerned because the VPN users' usernames and passwords are stored in the same AD server. Then he is afraid if we disable the Active Directory&amp;nbsp;&lt;SPAN&gt;Query in the LDAP Account Unit object, and change the credentials to&amp;nbsp;non-admin user in it, the VPN users will not be able to authenticate. I think VPN users are authenticated through RADIUS, and for the group membership you don't need AD Query. But I don't know if for the group membership an admin user credential is needed to access the AD server or not, I am not sure.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Julián&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 17:47:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/226025#M3368</guid>
      <dc:creator>fjulianom</dc:creator>
      <dc:date>2024-09-09T17:47:33Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and VPN SSL/SNX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/226052#M3369</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/177"&gt;@Peter_Elmer&lt;/a&gt;&amp;nbsp;actually did the video you linked.&lt;/P&gt;
&lt;P&gt;Removing the&amp;nbsp;Active Directory Query tickbox should have no effect on LDAP queries needed by the gateway&amp;nbsp;&lt;BR /&gt;Changing the credentials in the LDAP AU object to non-admin credentials is HIGHLY recommended.&lt;BR /&gt;Your users should still be able to authentication via VPN when you make these changes.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Sep 2024 19:47:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/226052#M3369</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-09-09T19:47:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and VPN SSL/SNX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/226090#M3370</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73441"&gt;@fjulianom&lt;/a&gt;&amp;nbsp;,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;It's hard making recommendations without seeing all the configuration of remote access SNX. There are options using 'legacy' objects in the Access Control Policy instead of the recommended Access Role Objects. It is my current recall, that for SNX remote access, no ID Awareness sessions are getting created. Authentication is performed based on the legacy settings, referencing the LDAP Account Unit object. Note, there is a Client Template setting in the 4th tab of the object. It's kind of impossible to say more by writing, as the complexity requires a remote session review.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;When you are using Access Role Objects to represent users, the setting in Gateway &amp;gt; ID Awareness is taken into account. It's been years I haven't configured SNX and don't have a lab running now to check quickly.&amp;nbsp; My lab is using Harmony SASE for Remote Access and have Quantum Gateways configured using dynamic route-based VPNs with Harmony SASE. In this way all Harmony SASE supported clients can connect via the SASE backbone to my 'data center' resources. On Harmony SASE and on Quantum I configured Microsoft Entra ID as authentication instance. In &lt;A title="Harmony SASE and Quantum Network Security" href="https://youtu.be/PCzqBiRefJg?feature=shared" target="_blank" rel="noopener"&gt;this video&lt;/A&gt;, you can see the user experience documented. You may want to explore such options with your local Check Point Sales Engineering contacts.&lt;/P&gt;
&lt;P&gt;I documented how ID Collector and AD Query impact the creation of Identity Sessions in &lt;A title="Identity Sessions" href="https://support.checkpoint.com/results/sk/sk179544" target="_blank" rel="noopener"&gt;sk179544&lt;/A&gt;. Here you can find as well information about the UserID (a regular domain user - not an administrative account) that you configure in the LDAP Account Unit Object.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am sorry, that I can't provide a 100% proven answer here, but in respect of the complexity and your production environment, I recommend either a lab exercise matching your production environment, or to engage Professional Services.&lt;/P&gt;
&lt;P&gt;Best regards&lt;/P&gt;
&lt;P&gt;Pelmer&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 05:42:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/226090#M3370</guid>
      <dc:creator>Peter_Elmer</dc:creator>
      <dc:date>2024-09-10T05:42:05Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and VPN SSL/SNX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/226094#M3371</link>
      <description>&lt;P&gt;Hi Peter_Elmer,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Many thanks for your answer. I think the point is to know if the Remote Access users uses AD Query to authenticate and get the role. If AD Query is not used, I think is sure to disable the AD Query checkbox in the LDAP Account Unit. My customer has SNX clients and regular VPN SSL clients. What do you think?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Julián&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 06:52:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/226094#M3371</guid>
      <dc:creator>fjulianom</dc:creator>
      <dc:date>2024-09-10T06:52:15Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and VPN SSL/SNX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/226096#M3372</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/73441"&gt;@fjulianom&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;to my understanding AD Query and Remote Access are not related. The legacy Remote Access configuration steps are referencing the LDAP Account Unit object. This object is as well referenced by AD Query. These are two different functionalities using the same object to know the answer to the question "how can I contact the Active Directory".&lt;/P&gt;
&lt;P&gt;This leads to a complex environment and therefore I suggested to stage it or to call Professional Services to get on-site help.&lt;/P&gt;
&lt;P&gt;best regards&lt;/P&gt;
&lt;P&gt;peter&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Sep 2024 07:02:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/226096#M3372</guid>
      <dc:creator>Peter_Elmer</dc:creator>
      <dc:date>2024-09-10T07:02:29Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and VPN SSL/SNX</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/226248#M3373</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As you said Peter, &lt;SPAN&gt;AD Query and Remote Access are not related.&amp;nbsp;&lt;/SPAN&gt;I engaged TAC and they confirmed that disabling AD Query will not affect the VPN users authentication, since the gateway authenticates the users and looks for the membership through LDAP, and not AD Query. Thank you very much&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/177"&gt;@Peter_Elmer&lt;/a&gt;&amp;nbsp;and&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;for your interest.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Julián&lt;/P&gt;</description>
      <pubDate>Wed, 11 Sep 2024 10:57:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Identity-Collector-and-VPN-SSL-SNX/m-p/226248#M3373</guid>
      <dc:creator>fjulianom</dc:creator>
      <dc:date>2024-09-11T10:57:26Z</dc:date>
    </item>
  </channel>
</rss>

