Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 

Identity Awareness Watcher

TurgutKaplanogl
Contributor
Contributor

Identity Awareness Watcher is an interactive, read-only troubleshooting tool designed for Check Point Gateways.

It provides real-time visibility into Identity Awareness blade status, user-to-IP mappings, and allows querying by username, IP address, or computer name all from a single, menu-driven interface.

 

Note: One-time before running the script

Expert mode: chmod +x identity_awareness_watcher.sh

Expert mode: dos2unix identity_awareness_watcher.sh

CP_ID_Watcher.png

 

ID_watcher_screen.png

...;
TO ACCESS CHECKMATES TOOLBOX it's simple and free

Disclaimer: Check Point does not provide maintenance services or technical or customer support for third party content provided on this Site, including in CheckMates Toolbox. See also our Third Party Software Disclaimer.




(1)
13 Replies

the_rock
MVP Platinum
MVP Platinum

Awesome! Will test it in the lab Monday.

;
TO ACCESS CHECKMATES TOOLBOX it's simple and free


For people who don't already know the pdp commands inside out, this is a really useful tool.
You could also add query by group.

I would perhaps extend it with pep commands for enforcing gateways.
It might be even more helpful here if I think of "pep s u q usr <username>", for example.

;
TO ACCESS CHECKMATES TOOLBOX it's simple and free


the_rock
MVP Platinum
MVP Platinum

will have to test it out.

;
TO ACCESS CHECKMATES TOOLBOX it's simple and free


0 Kudos

Maybe to test this?

;
TO ACCESS CHECKMATES TOOLBOX it's simple and free


(1)

the_rock
MVP Platinum
MVP Platinum

Will check Monday.

;
TO ACCESS CHECKMATES TOOLBOX it's simple and free


0 Kudos

TurgutKaplanogl
Contributor
Contributor

Hello,

In V2, I can also include PEP queries.

Thank you

TK

;
TO ACCESS CHECKMATES TOOLBOX it's simple and free


0 Kudos

the_rock
MVP Platinum
MVP Platinum

Very cool!

Worth pointing out dos2unix needs to be ran as well before running the script.

Lab output:

============================================================
IDENTITY AWARENESS WATCHER
============================================================
Gateway : CP-GW
Version :
============================================================
Identity Awareness Status:
Status: OK
============================================================
1) Query by IP Address
2) Query by Username
3) Query by Co

...;
TO ACCESS CHECKMATES TOOLBOX it's simple and free


0 Kudos

TurgutKaplanogl
Contributor
Contributor

Thank you. Yes, I mentioned "dos2unix" in my note above.  😊

From Notes: "Note: One-time before running the script

Expert mode: chmod +x identity_awareness_watcher.sh

Expert mode: dos2unix identity_awareness_watcher.sh"

 

;
TO ACCESS CHECKMATES TOOLBOX it's simple and free


the_rock
MVP Platinum
MVP Platinum

I know, but from my own experience when it comes to scripts, people usually download it and think it will run. Well, truth be told, I speak for myself lol

;
TO ACCESS CHECKMATES TOOLBOX it's simple and free


0 Kudos

TurgutKaplanogl
Contributor
Contributor

Thanks for your experience  😊

;
TO ACCESS CHECKMATES TOOLBOX it's simple and free


0 Kudos

the_rock
MVP Platinum
MVP Platinum

THANK YOU!

;
TO ACCESS CHECKMATES TOOLBOX it's simple and free


0 Kudos

the_rock
MVP Platinum
MVP Platinum

Great script btw!

;
TO ACCESS CHECKMATES TOOLBOX it's simple and free


Yes, well done!

;
TO ACCESS CHECKMATES TOOLBOX it's simple and free


0 Kudos