<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMB Identity Collector Mystery in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Identity-Collector-Mystery/m-p/204885#M10214</link>
    <description>&lt;P&gt;Only if there is a domain controller locally, as per&amp;nbsp;sk178604.&lt;/P&gt;&lt;TABLE border="1" cellspacing="2" cellpadding="4"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;SMBGWY-2486&lt;/TD&gt;&lt;TD&gt;An AD Domain Controller used for authenticating users that is located in the external zone of a device using Hide-NAT is not supported.&lt;BR /&gt;&lt;BR /&gt;Workaround: Install another Domain Controller in the internal zone of the device.&lt;/TD&gt;&lt;TD&gt;R81.10.00&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
    <pubDate>Fri, 02 Feb 2024 13:18:01 GMT</pubDate>
    <dc:creator>Steven_Sultana</dc:creator>
    <dc:date>2024-02-02T13:18:01Z</dc:date>
    <item>
      <title>SMB Identity Collector Mystery</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Identity-Collector-Mystery/m-p/77861#M3204</link>
      <description>&lt;P&gt;If we follow&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk123858&amp;amp;partition=Basic&amp;amp;product=Identity" target="_blank"&gt;sk123858: Identity Collector support on SMB Appliances&lt;/A&gt;, Identity Collector is not supported with&amp;nbsp;1100, 1200R, 1400, 600, 700&amp;nbsp;Gaia Embedded&amp;nbsp;R77.20, R75.20 Appliances and the same is declared in &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108235&amp;amp;partition=General&amp;amp;product=Identity" target="_blank"&gt;sk108235 - Identity Collector - Technical Overview&lt;/A&gt;. &lt;SPAN&gt;sk105380&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;Features and Known Limitations for R77.20.xx does not mention it, but in&amp;nbsp;sk159772&amp;nbsp;Check Point R80.20 for 1500 Appliances Features and Known Limitations we find that&amp;nbsp;Identity Collector is supported neither&amp;nbsp;Locally nor&amp;nbsp;Centrally&amp;nbsp;managed !&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;The background for this limitation: The&amp;nbsp;&lt;SPAN&gt;PDP of SMB Appliances has no API listening to tcp/443.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;But Identity Sharing between PDP on a Gaia GW and PEPs on SMB Appliances do work, see&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106965&amp;amp;partition=Advanced&amp;amp;product=Identity" target="_blank"&gt;sk106965: &lt;STRONG&gt;Identity&lt;/STRONG&gt; &lt;STRONG&gt;Sharing&lt;/STRONG&gt; does not work with &lt;STRONG&gt;SMB&lt;/STRONG&gt; appliance running&lt;/A&gt;&amp;nbsp;for details.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;So we have tested in lab a central GAiA GW with SMB star VPN topology. Identity Collector updates the GAiA GW and the GAiA GW performs&amp;nbsp;Identity Sharing with the PEPs on the SMB Appliances! This does work, so sk123858 seems a little too narrow-minded...8)&lt;/img&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2020 11:40:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Identity-Collector-Mystery/m-p/77861#M3204</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2020-03-10T11:40:03Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Identity Collector Mystery</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Identity-Collector-Mystery/m-p/78015#M3223</link>
      <description>You're correct, the underlying issue is the Identity Awareness API is not supported on SMB appliances.&lt;BR /&gt;Any feature that relies on this API is therefore not supported…at least directly.&lt;BR /&gt;If you have a regular gateway in the environment and implement identity sharing with the SMB appliances, that most definitely works.&lt;BR /&gt;Not sure exactly how to best represent this in the SK, though.</description>
      <pubDate>Wed, 11 Mar 2020 19:53:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Identity-Collector-Mystery/m-p/78015#M3223</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-03-11T19:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Identity Collector Mystery</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Identity-Collector-Mystery/m-p/158183#M7466</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;This is a very interesting solution that overcomes some of the limitations as described in the abovementioned sk.&lt;/P&gt;
&lt;P&gt;I have a customer who is only using SMB appliances and wants to deploy Identity Awareness using a dedicated Gaia FW as PDP.&lt;/P&gt;
&lt;P&gt;Question: as the management is only currently licensed to support SMB appliances, do we need to foresee a "full-Gaia" management license for this only firewall who will serve as PDP?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks and best regards&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 15:16:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Identity-Collector-Mystery/m-p/158183#M7466</guid>
      <dc:creator>rlopesdu</dc:creator>
      <dc:date>2022-09-27T15:16:21Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Identity Collector Mystery</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Identity-Collector-Mystery/m-p/158234#M7471</link>
      <description>&lt;P&gt;Yes, you will need a license to manage that gateway.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 21:05:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Identity-Collector-Mystery/m-p/158234#M7471</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-09-27T21:05:08Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Identity Collector Mystery</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Identity-Collector-Mystery/m-p/158263#M7473</link>
      <description>&lt;P&gt;Thanks for the clarification.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 07:02:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Identity-Collector-Mystery/m-p/158263#M7473</guid>
      <dc:creator>rlopesdu</dc:creator>
      <dc:date>2022-09-28T07:02:51Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Identity Collector Mystery</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Identity-Collector-Mystery/m-p/158281#M7474</link>
      <description>&lt;P&gt;In R81.10.00 for Quantum spark 1500\1600\1800, Identity collector is supported for centrally managed appliances.&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 08:53:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Identity-Collector-Mystery/m-p/158281#M7474</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-09-28T08:53:25Z</dc:date>
    </item>
    <item>
      <title>Re: SMB Identity Collector Mystery</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Identity-Collector-Mystery/m-p/204885#M10214</link>
      <description>&lt;P&gt;Only if there is a domain controller locally, as per&amp;nbsp;sk178604.&lt;/P&gt;&lt;TABLE border="1" cellspacing="2" cellpadding="4"&gt;&lt;TBODY&gt;&lt;TR&gt;&lt;TD&gt;SMBGWY-2486&lt;/TD&gt;&lt;TD&gt;An AD Domain Controller used for authenticating users that is located in the external zone of a device using Hide-NAT is not supported.&lt;BR /&gt;&lt;BR /&gt;Workaround: Install another Domain Controller in the internal zone of the device.&lt;/TD&gt;&lt;TD&gt;R81.10.00&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;</description>
      <pubDate>Fri, 02 Feb 2024 13:18:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-Identity-Collector-Mystery/m-p/204885#M10214</guid>
      <dc:creator>Steven_Sultana</dc:creator>
      <dc:date>2024-02-02T13:18:01Z</dc:date>
    </item>
  </channel>
</rss>

