<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: 700 and Azure AD in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/700-and-Azure-AD/m-p/18306#M607</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you try the steps from Check Point 600/700 Appliances Administration Guide R77.20.80 p. 154 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To add an Active Directory domain:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;1. In the Active Directory section, click &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;New&lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The Add new Domain window opens.&lt;/P&gt;&lt;P&gt;2. Enter this information:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;• &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Domain - &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;The domain name. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;• &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;IP address &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;- The IP address of one of the domain controllers of your domain. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;&lt;STRONG&gt;Note &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;- 600 appliances only support IPv4 addresses. 700 appliances support both IPv4 and IPv6 servers. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;• &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;User name &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;- The user must have administrator privileges to ease the configuration process and create a user based policy using the users defined in the Active Directory. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;• &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Password - &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;The user's password. You cannot use these characters when you enter a password or shared secret: { } [ ] ` ~ | ‘ " # + \ &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;• &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;User DN &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;- Click &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Discover &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;for automatic discovery of the DN of the object that represents that user or enter the user DN manually. For example: CN=John James,OU=RnD,OU=Germany,O=Europe,DC=Acme,DC=com &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;3. Select &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Use user groups from specific branch only &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;if you want to use only part of the user database defined in the Active Directory. Enter the branch in the Branch full DN in the text field. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;4. Click &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Apply&lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;When an Active Directory is defined, you can select it from the table and choose &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Edit &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;or &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Delete &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;when necessary. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;When you edit, note that the Domain information is read-only and cannot be changed.&lt;/P&gt;&lt;P&gt;When you add a new Active Directory domain, you cannot create another object using an existing domain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Mon, 13 Aug 2018 10:35:25 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2018-08-13T10:35:25Z</dc:date>
    <item>
      <title>700 and Azure AD</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/700-and-Azure-AD/m-p/18305#M606</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am looking for some tutorial how to setup Active Directory on Azure and then connect device 700 for Identity Awareness.&lt;/P&gt;&lt;P&gt;I have already created AD on Azure, but I have no clue how to connect from 700 to this AD. I can see the External IP for this domain created, but when I try to use it I get message Connect to server failed: Unknown error.&lt;/P&gt;&lt;P&gt;Definitely I am missing something and tutorial or list of steps would help me.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;cheers&lt;/P&gt;&lt;P&gt;yaric&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 10 Aug 2018 19:44:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/700-and-Azure-AD/m-p/18305#M606</guid>
      <dc:creator>Jaroslaw_Pietra</dc:creator>
      <dc:date>2018-08-10T19:44:39Z</dc:date>
    </item>
    <item>
      <title>Re: 700 and Azure AD</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/700-and-Azure-AD/m-p/18306#M607</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Did you try the steps from Check Point 600/700 Appliances Administration Guide R77.20.80 p. 154 ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;To add an Active Directory domain:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;1. In the Active Directory section, click &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;New&lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The Add new Domain window opens.&lt;/P&gt;&lt;P&gt;2. Enter this information:&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;• &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Domain - &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;The domain name. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;• &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;IP address &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;- The IP address of one of the domain controllers of your domain. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;&lt;STRONG&gt;Note &lt;/STRONG&gt;&lt;/SPAN&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;- 600 appliances only support IPv4 addresses. 700 appliances support both IPv4 and IPv6 servers. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;• &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;User name &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;- The user must have administrator privileges to ease the configuration process and create a user based policy using the users defined in the Active Directory. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;• &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Password - &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;The user's password. You cannot use these characters when you enter a password or shared secret: { } [ ] ` ~ | ‘ " # + \ &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;• &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;User DN &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;- Click &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Discover &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;for automatic discovery of the DN of the object that represents that user or enter the user DN manually. For example: CN=John James,OU=RnD,OU=Germany,O=Europe,DC=Acme,DC=com &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;3. Select &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Use user groups from specific branch only &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;if you want to use only part of the user database defined in the Active Directory. Enter the branch in the Branch full DN in the text field. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;4. Click &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Apply&lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;When an Active Directory is defined, you can select it from the table and choose &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Edit &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;or &lt;/SPAN&gt;&lt;STRONG style=": ; font-size: medium; font-family: DINOT-Bold,DINOT-Bold;"&gt;Delete &lt;/STRONG&gt;&lt;SPAN style="font-size: medium; font-family: DINOT,DINOT;"&gt;when necessary. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;When you edit, note that the Domain information is read-only and cannot be changed.&lt;/P&gt;&lt;P&gt;When you add a new Active Directory domain, you cannot create another object using an existing domain.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 13 Aug 2018 10:35:25 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/700-and-Azure-AD/m-p/18306#M607</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-08-13T10:35:25Z</dc:date>
    </item>
    <item>
      <title>Re: 700 and Azure AD</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/700-and-Azure-AD/m-p/18307#M608</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks Günther for your answer. Obviously I read it. I think something I am missing on Azure side that connection is not getting established. That's the reason I asked for some tutorial on setup both sides Azure and 700.&lt;/P&gt;&lt;P&gt;However I have other domain set it up already on Synology device (it's not MS). But when I try to connect I get an error: "Stronger connection required" on Checkpoint device. Any advise here?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2018 15:05:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/700-and-Azure-AD/m-p/18307#M608</guid>
      <dc:creator>Jaroslaw_Pietra</dc:creator>
      <dc:date>2018-08-14T15:05:30Z</dc:date>
    </item>
    <item>
      <title>Re: 700 and Azure AD</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/700-and-Azure-AD/m-p/18308#M609</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jaroslaw,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have asked about this in this&amp;nbsp;here:&amp;nbsp;&lt;A href="https://community.checkpoint.com/message/16999"&gt;User Awareness with Azure AD on locally managed SMB&lt;/A&gt;‌&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;User awareness&amp;nbsp;connects with a Windows Server with Active Directory service, which is not the case of the Azure AD service. You would need to add support for LDAP in the Azure AD service in some way. I don't know if there is an additional (paid) service which will support this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have not found a solution for this issue yet.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 14 Aug 2018 16:54:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/700-and-Azure-AD/m-p/18308#M609</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-08-14T16:54:20Z</dc:date>
    </item>
  </channel>
</rss>

