Hi there we have checkpoint multi domain server , one of our Domain/CMA manages 12 gateway for externally connected sites
so this means our MDS is in one physical location and ll the customer's firewalls are in another location . (mutiple)
We are trying to figure out how we can use LDAP user groups in the checkpoint policy ?
How do we setup our management server to read the LDAP attributes from their on-premise active directory if we do not have any connectivity. (besides gateway management via SIC trust) Do we need a site-to-site vpn tunnel between our MDS and their on-premise Active directory infrastructure?
What is the best way to do this?