- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Check Point Identity Collector - Windows Server fi...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Check Point Identity Collector - Windows Server firewall Permisoins
Hi all,
I looked at all the threads related to Identity Collector, as well as the documentation for deploing Identity Collector and like other, I also have had a problem until I turned off firewall on windows server.
This is enough for me just to check if there is a connection issue to DC other then firewall. Now I want to turn on the firewall and allow only what is necessary.
Are anyone here is willing to share setup of its windows firewall in case where its firewall is turned on, and connection with IC is green 🙂
Far now, I allowed only those 7 DCOM 135 rules but it is not enough.
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I just add a rule that says from fw to IC (bi-directionally), allow on any port, thats it.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
HTTPS, DCOM, RPC, LDAP, DNS are needed depending on the server role. https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Client...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Can you assist me how does this rule looks like in firewall policy:
Add "Allow" rule
Remote Event Log Management > Remote Event Log Management (RPC)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I just add a rule that says from fw to IC (bi-directionally), allow on any port, thats it.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Ok, I can accept that as a good workaround solution.
Thank you!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Glad we can help. Btw, since we all do IT security here, goes without saying ports should always be indicated whenever possible, but at the end of the day, this is just internal communication, so I dont find it would be a huge deal...just my 2 cents.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I can agree. Just bc it is internal communication between DC and IC, any any policy with specified source and destination will do a job.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Though you can always follow what Chris gave, its an official reference.
Andy
