- Products
- Learn
- Local User Groups
- Partners
-
More
Celebrate the New Year
With CheckMates!
Value of Security
Vendor Self-Awareness
Join Us for CPX 360
23-24 February 2021
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
How to Remediate Endpoint & VPN
Issues (in versions E81.10 or earlier)
Mobile Security
Buyer's Guide Out Now
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hello,
I am trying to enable identity awareness, the server team needs to create a LDAP account for the firewall.
Should the LDAP account be an admin account or a user account?
If it has to be an admin account, is there a documentation i can reference to, which i can provide to the server team?
greatly appreciate the help
Thank You
Of course there is a very detailed reference : Identity Awareness Administration Guide R80.20 ! And for further information we have the sk86441: ATRG: IdentityAwareness, sk149255: IdentityAwareness- IdentitySharing and sk88520: Best Practices - IdentityAwarenessLarge Scale Deployment
Thank You for your feedback. I dont see anywhere on the documentation where it states the LDAP account has to be an administrator account except sk108235 - Identity Collector: Technical Overview which we are not deploying in my environment.
I would appreciate if you can direct me to where its stated on any of the sks.
I think this may be what you're looking for if you don't want admin accounts: Using Identity Awareness AD Query without Active Directory Administrator privileges on Windows Serve...
The information i've got from PS and support is the account should be an admin account for identity awareness setup. I'm looking for a document from checkpoint that supports this requirement
I think the closest thing I can find is in the Identity Awareness R80.20 Admin guide where it says:
"Enter the Active Directory credentials and click Connect to verify the credentials.
Important - For AD Query you must enter domain administrator credentials. For Browser-Based Authentication standard credentials are sufficient."
So, I would read that to mean the default requirement is an admin (or domain admin) account unless you wanted to create a user with custom permissions (without domain admin) as illustrated in the sk article I referenced.
Here's a direct link to that portion of the admin guide for your AD administrator's reference. It should be under the section titled "Enabling Identity Awareness on the Log Server for Identity Logging"
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY