Hi everyone,
I’m working on an Identity Awareness deployment on Check Point and I’d like some clarification.
I understand that in large or complex environments, the PDP/PEP Broker is used to centralize identities and share them across multiple gateways. What I’m not sure about is:
-
Is it possible to configure Identity Awareness directly on the gateway without relying on a Broker?
-
In which scenarios is it sufficient to enable IA using methods like AD Query, Identity Collector, or Captive Portal directly on the firewall?
-
When is an Identity Broker actually required (e.g. multi-gateway environments, distributed clusters, or multiple AD domains)?
I’d like to confirm whether, in a relatively simple setup (a single cluster and one AD domain), everything can be done without a Broker, or if there are hidden limitations I should be aware of.
Thanks in advance.