Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
OrkhanRustamli
Participant
Jump to solution

VPN Cert Auth - Read OU for User Groups

Hi All,

We are implementing certificate authentication for remote VPN without LDAP and AD. ISE is identity store and we are using ISE`s CA feature. 

The authentication is working fine, as auth is going internally in firewall but we also need user groups for policy management.

I wonder is it possible to configre CP to read OU from cert and add users to groups based on OU?

 

Thanks in advance!

0 Kudos
1 Solution

Accepted Solutions
PhoneBoy
Admin
Admin

I believe we can only retrieve groups from LDAP.
However, if you're integrating with Cisco ISE, you should be able to use Identity Tags as a group source.
See: https://community.checkpoint.com/t5/Policy-Management/How-to-use-Identity-Awareness-Tags-in-R80-20-M... 

View solution in original post

0 Kudos
1 Reply
PhoneBoy
Admin
Admin

I believe we can only retrieve groups from LDAP.
However, if you're integrating with Cisco ISE, you should be able to use Identity Tags as a group source.
See: https://community.checkpoint.com/t5/Policy-Management/How-to-use-Identity-Awareness-Tags-in-R80-20-M... 

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Tue 23 Apr 2024 @ 11:00 AM (EDT)

    East US: What's New in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events