- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello,
I found an old post regarding this topic but with no solution to the following issue:
I am integrating a third party identity source (Clearpass) via IA API and I would like to work with identity tags. The thing is that I cannot see in the IA API guide the way to create this tags in Clearpass so they can match with my Identity Tags in Check Point.
Would it match if the string of any attribute sent via api is the same as the value in Identity Tag "External Identifier"?
Thanks!!
As I recall it's the groups provided with the user-group field from Aruba that is matched to the identity tag (tag external identifier).
The Identity tag itself is created within Check Point and linked with an access-role referenced in the policy.
I would suggest to contact CP TAC to learn if and how this is possible ! You can later post the solution here...
As I recall it's the groups provided with the user-group field from Aruba that is matched to the identity tag (tag external identifier).
The Identity tag itself is created within Check Point and linked with an access-role referenced in the policy.
Hi Chris,
That makes sense. I will try by matching the tag External Identifier with the "user-group" attribute string and post the result.
Thanks!
Hello,
I have tested it and it works. The Identity Awareness API collects the string contained in the field "user-groups" and it matches it with the "External Identifyer" value of the Identity Tag.
The authentication event is correctly associated to the Access Role that contains the Identity Tag.
Thanks!!
I presume it is similar to how Azure AD worked in R80.40 (before we added support for GraphAPI).
This means manually creating the tag on the Check Point side using the same name, same capitalization as the relevant group(s) defined in Clearpass.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY