- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Re: Checkpoint LDAP Integration
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Checkpoint LDAP Integration
Hi,
First of all, I want to talk about the structure. There is an AD with many (hundreds of thousands) users. A remote Checpoint firewall is pulling users from this AD. I configured Identityy Awernes, but since the location is remote and there are too many users, user queries take a long time.
I think the problem will be solved if I pull the organization unit part of the region where the firewall is from the AD. When searching or querying users, it speeds up if it is done from a certain organization unit instead of all users.
-Can I do this organization unit part with Identity collector?
-If I can, can you share the relevant document?
Or can you suggest if there is another solution?
Thanks.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sk88520: Best Practices - Identity Awareness Large Scale Deployment
sk170765: Identity Awareness Scalable Design - Identity Agent
sk86441: ATRG: Identity Awareness
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
sk88520: Best Practices - Identity Awareness Large Scale Deployment
sk170765: Identity Awareness Scalable Design - Identity Agent
sk86441: ATRG: Identity Awareness
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for your reply and for sharing this information. I have not yet been able to provide controls in the environment. I will share the solution information when it is finalized.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi
I installed with identity collector but there are small problems.
It is now doing user verification in the rules. But I want to cancel this rule and write a new rule. With this new rule, I want to check that only one computer is in a certain OU (organization unit). If this computer is in the OU, it passes the rule. I couldn't figure out how to do this rule.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I believe you can refer to individual machines in the Access Role, but I don't think we support groups for this function.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
We install identity Collector and our problem solved.
Our environment have 42 ADC and we use 35 ADC with İdentity Collector.
