- Products
- Learn
- Local User Groups
- Partners
-
More
Join Us for CPX 360
23-24 February 2021
Check Point Harmony
Highest Level of Security for Remote Users
Important certificate update to CloudGuard Controller, CME,
and Azure HA Security Gateways
Advanced Protection for
Small and Medium Business
Secure Endpoints from
the Sunburst Attack
Important! R80 and R80.10
End Of Support around the corner (May 2021)
Hello,
has anyone already tried to connect the Check Point Identity Collector to a Cisco Identiy Services Engine (ISE) Version 2.6 via pxGrid?
I know it is not supported yet (only up to 2.4, but perhaps someone has tried already (and even succeeded).
I have to next week.... Problem is, that DNA Center 1.3.1 requires ISE 2.6.
Yours, Martin
@Royi_Priov what say you?
Hi @Martin_Seeger ,
It was not tested by our QA yet.
However, from last certifications we didn't find any issues.
Did it worked for you eventually?
Thanks,
Royi Priov.
Hello @Royi_Priov ,
thank you for the information. That is really useful. We are currently trying to setup a connection to the ISE 2.6. I think we will see the results within the next week. I will report here.
Yours, Martin
Update: Connection to the ISE 2.6 seems to be working. We get Login/Logout events and the group names are matching known SGTs. Now we will build some rules.
Yours, Martin
Hello all,
I tried to integrate R80.10 with ISE 2.6 and i wanted to know if you have already done it and what was the result, if it works for you or NOT?
i know it's not recommended by Check Point.
thanks in advance
Hi,
we are doing it with R80.30 and Cisco ISE 2.6. It looks good (we see the IA events in the log), but we have not completed the tests. I will update this post when we are finished.
Yours, Martin
Short answer: Yes & No
Long answer:
It is quite an adventure so far. We are probably the first to implement Check Point SGT based firewalling in conjunction with Cisco DNA.
Yours, Martin
I just read your message properly.
We experience a bit of the same, some clients do not show up as a session. This I've figured out is probably 99% our wireless clients, but only a very few of them, and these clients have for some reason not triggered an accounting update from the WLC. I haven't looked into this but have thought that the authentication went wrong or something. We are using Cisco WLC 5508 and 5520, tunneled (flexconnect) from inside Cisco SDA/DNA, so no vxlan to the AP.
Our SDA-switches are by default configured to send accounting via the switches default update interval, some 2days (172000s) on cat9300. We haven't concluded on any different interval to use yet.
Sure is an adventure and will be amazing when it works! Rest assured that you are not alone! We are also trying to use SGT in our rules! 🙂
I've sent you a message directly.
Hi,
Does R80.10 support ISE 2.6 for PxGrid integration?
I have successfully integrated IDC with cisco ISE, but the SGT configured on ISE is not auto polled? Is that something expected? or should the SGT be auto populated when creating access roles? As per white paper from checkpoint, it is mentioned to create SGT manually same as what is configured on ISE with prefix CSGT. Is this the behavior i should expect?
About CheckMates
Learn Check Point
Advanced Learning
WELCOME TO THE FUTURE OF CYBER SECURITY