Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Dr_Steve_Brule
Participant

Quantum Spark DAIP GW - Identity options

Hello,

For our main office, we are currently using Identity Collectors with our main 7000 GW cluster to handle IA for all of our office users (around 1500 users).  We will be opening a couple of remote branch offices where we'll be using DAIP SMB gateways.  I would prefer to use Identity sharing from our main 7000 GW cluster, but it appears this isn't compatible with DAIP gateways.  Also, AD query is no longer a viable option. 

These remote office will only have 5-10 users, so I'd like to avoid deploying agents to these random users.  With that said, is tying the SMBs to my existing ID collectors the best option?  Is there any concern about the SMBs learning thousands of identities via the existing ID collectors?

Also, the DAIP gateways (Spark 1570s) will be centrally managed and running R81.10.05 (or R81.10.07). 

0 Kudos
2 Replies
G_W_Albrecht
Legend
Legend

That should work fine.

CCSE CCTE CCSM SMB Specialist
0 Kudos
PhoneBoy
Admin
Admin

Not clear if this is supported on SMB appliances or not, but maybe you can use Identity Broker instead?
See: https://sc1.checkpoint.com/documents/R81.10/WebAdminGuides/EN/CP_R81.10_IdentityAwareness_AdminGuide...  

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events