- CheckMates
- :
- Products
- :
- Developers
- :
- API / CLI Discussion
- :
- Identity Awareness Web API in Cluster mode
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Identity Awareness Web API in Cluster mode
Hey,
I am trying to integrate 3rd party NAC (based on OpenRADIUS) with Checkpoint R81.10 using Identity Web API.
What i want to send is "add-identity" like described here: Add Identity (v1.0)
Does anybody know if Web API configuration might be different in Cluster mode than in single Gateway?
Because I was able to successfully configure Web API in my LAB environment (virtual machine) many times, send username + IP address to Checkpoint without problem and check in pdp if it's correct.
At the same time I struggle to configure Web API for my client, but they have Checkpoint 15400 in Cluster mode, also R81.10.
I even tried sending API requests using curl but it didn't return any error, just standard HTML output. It looked like Web API wasn't even turned on but in "Device Status" Identity Awareness had green status, no errors, no problems.
This is my curl command working in LAB and not working in client's environment. Should I modify this command to make it working with Checkpoint Cluster?
curl -k -H "Content-Type: application/json" -X POST -d "{\"shared-secret\":\"SECRET\",\"ip-address\":\"192.168.29.110\",\"user\":\"test\"}" https://192.168.55.121/_IA_API/idasdk/add-identity
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Are you positive that Identity API is enabled on both cluster members, and that you are connecting to the private IP addresses and NOT VIP of the cluster?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for the reply. I tried all IP addressess without luck, but mostly I was connecting to the private IP of the gateway.
Thank you for the hint about enabling API on both members, I will have to verify this setting with the client.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Let me know how it goes. Here is what Admin guide is saying: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topic...
and also this: https://sc1.checkpoint.com/documents/latest/IdentityAPIs/#ida_api_config~v1%20
