- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Recon User for CyberArk Password Rotation
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Recon User for CyberArk Password Rotation
We have a Checkpoint Cluster deployed in AWS on R81.20
we are planning to integrate it with CyberArk i.e. administrator login via cyberark.
I wanted to know if Checkpoint supports recon user configuration with CyberArk i.e Automatic Password Rotation via CyberArk for user logins ?
is there any official documentation for this.
thanks
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There is an official supported integration by CyberArk which comes out-of-the-box which supports reconcile.
https://docs.cyberark.com/pam-self-hosted/Latest/en/Content/PASIMP/CheckPoint-GAiA-plugin.htm
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We don't have a specific integration with Cyberark that I'm aware of.
That doesn't mean it won't work, of course.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
There is an official supported integration by CyberArk which comes out-of-the-box which supports reconcile.
https://docs.cyberark.com/pam-self-hosted/Latest/en/Content/PASIMP/CheckPoint-GAiA-plugin.htm
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks..for this to work only cyberark users with admin privilidge are required ? or any specific configuration at Firewall end.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In the environments I use it, we manage either built-in admin or other local accounts through CyberArk. For this no special configuration is needed.
To get into expert mode a bit more configuration is needed, with 2 options:
- Save expert password as separate account (unmanaged) and use Gaia account as logon account
- Set expert-authentication-mode to user-password and use a grouped dummy account as expert password (allows to use expert for different users)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you for the reply...this also takes care of password rotation via cyberark I believe ?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Sure
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thank you..i will test this out.
