- Products
- Learn
- Local User Groups
- Partners
- More
AI Security Masters
E1: How AI is Reshaping Our World
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi All,
I want to enable LDAPS port 636 for Identity Awareness for may gateways in a cluster, current it works with LDAP. Is it possible in Checkpoint?
Regards,
Salom
I have found out that for LDAPS to work, LDAP 389 should also be allowed on the FW rule.
Follow this article to understand how it works.
https://www.tec-bite.ch/the-pain-with-check-point-and-ldaps-and-some-medicine-against-it/
Regards,
Salom
Yes you can, go to Object Catégories>Users/identities> LDAP Account Units chose your LDAP server and go to Servers (like in the screenshot) chose your host server and configure the Encryption.
Note: you need to have LDAPS activated in your LDAP server.
Regards,
M_Soler
A cert might be required on the CP, how do I do that?
Regards,
Salom
No certificate needed, Check Point firewall validates the certificate of Microsoft DCs using the fingerprint.
Regards,
M_Soler
Thanks, I managed to fetch the fingerprints however If I removed LDAP 389, leaving 636 I am getting the attached error. Do I need to have all the protocol allowed on the FW rule?
Regards,
Salom
I have found out that for LDAPS to work, LDAP 389 should also be allowed on the FW rule.
Follow this article to understand how it works.
https://www.tec-bite.ch/the-pain-with-check-point-and-ldaps-and-some-medicine-against-it/
Regards,
Salom
Yes LDAPS is supported.
Start by reviewing SSL Encryption options in the LDAP Account unit.
Select 'Manage -> Servers and OPSEC Applications -> LDAP Account Unit'.
Under the Servers tab for your DC object, select Encryption tab.
See the setting "Use Encryption (SSL)". Port will be 636.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 16 | |
| 15 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsThu 08 Jan 2026 @ 05:00 PM (CET)
AI Security Masters Session 1: How AI is Reshaping Our WorldAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY