Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
israelfds95
Contributor
Contributor
Jump to solution

LDAP Account unit

I've been studying Identity Awareness and digging deeper to close some knowledge gaps. So I've been reading guides, SKs, and also using ChatGPT Plus to clarify some questions and research a few things based on the files and information I shared with it.

One of the questions I asked was:

Which Identity Awareness options (Browser-authentication, AD Query, Identity Agent, Terminal Server, Identity Collector, RADIUS Accounting, Identity Web API, and Remote Access) actually require an LDAP Account Unit to work, and which ones don't?

And it replied:

"Almost all identity sources require the LDAP Account Unit — not for authentication, but for authorization, meaning to associate users with groups used in Access Roles."

identity-agent-ldap-account-uni-chatgpt.jpeg

 

I found that really useful. What do you think?

0 Kudos
1 Solution

Accepted Solutions
G_W_Albrecht
Legend Legend
Legend

This is fully explained in sk86441: ATRG: Identity Awareness

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist

View solution in original post

5 Replies
israelfds95
Contributor
Contributor

I found that really useful. What do you think?

0 Kudos
Lesley
Authority Authority
Authority

Hi,

There are more blades using the LDAP account unit.  Please refer to: https://support.checkpoint.com/results/sk/sk101372

"Additionally, LDAP Account Units are used in the SmartDashboard, when opening, editing or fetching LDAP attributes."

With this they mean the access roles (that you can use for example an ad group in a firewall rule). 

-------
If you like this post please give a thumbs up(kudo)! 🙂
the_rock
Legend
Legend

See if below discussion helps. Also, I believe ldap account unit is needed regardless, as thats how users are pulled no matter what method you use.

Andy

https://community.checkpoint.com/t5/Security-Gateways/New-IA-Implementation/m-p/185851#M34184

0 Kudos
G_W_Albrecht
Legend Legend
Legend

This is fully explained in sk86441: ATRG: Identity Awareness

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
the_rock
Legend
Legend

SK @G_W_Albrecht sent is the answer, for sure.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events