Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
freeman91
Participant
Jump to solution

Check Point Identity Collector - Windows Server firewall Permisoins

Hi all, 

I looked at all the threads related to Identity Collector, as well as the documentation for deploing Identity Collector and like other, I also have had a problem until I turned off firewall on windows server.

This is enough for me just to check if there is a connection issue to DC other then firewall. Now I want to turn on the firewall and allow only what is necessary. 
Are anyone here is willing to share setup of its windows firewall in case where its firewall is turned on, and connection with IC is green 🙂

Far now, I allowed only those 7 DCOM 135 rules  but it is not enough.

 

Screenshot_1.png

0 Kudos
1 Solution

Accepted Solutions
the_rock
Legend
Legend

I just add a rule that says from fw to IC (bi-directionally), allow on any port, thats it.

Andy

View solution in original post

0 Kudos
7 Replies
Chris_Atkinson
Employee Employee
Employee

HTTPS, DCOM, RPC, LDAP, DNS are needed depending on the server role. https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Client...

CCSM R77/R80/ELITE
0 Kudos
freeman91
Participant

Can you assist me how does this rule looks like in firewall policy:

  • Add "Allow" rule

    Remote Event Log Management > Remote Event Log Management (RPC)
0 Kudos
the_rock
Legend
Legend

I just add a rule that says from fw to IC (bi-directionally), allow on any port, thats it.

Andy

0 Kudos
freeman91
Participant

Ok, I can accept that as a good workaround solution. 

 

Thank you!

0 Kudos
the_rock
Legend
Legend

Glad we can help. Btw, since we all do IT security here, goes without saying ports should always be indicated whenever possible, but at the end of the day, this is just internal communication, so I dont find it would be a huge deal...just my 2 cents.

Andy

0 Kudos
freeman91
Participant

I can agree. Just bc it is internal communication between DC and IC, any any policy with specified source and destination will do a job.

0 Kudos
the_rock
Legend
Legend

Though you can always follow what Chris gave, its an official reference.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events