Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
babicmilan
Collaborator

Identity Collector?

Hello, I'm interested in where to install Identity Collector agent? I have a two AD Domain Controllers in my environment. One AD is active, second one is standby.

 

Which one is the best practice?

 

1) Install a two Identity Colletor agents on both AD Domain Controllers (active and passive)

2) Install one Identity Collector agent on some independent server (which is not AD Domain Controller)

3) Install a two Identity Colletor agents on some independent servers (which are not AD Domain Controllers)

 

Which solution would you prefer?

 

Best regards.

0 Kudos
5 Replies
Chris_Atkinson
Employee Employee
Employee

(3) is probably considered best practice by many, especially in environments with multiple DCs.

CCSM R77/R80/ELITE
0 Kudos
Martijn
Advisor
Advisor

Hi,

Option 3 is the one you should go for. This is what we always do when using Identity Awareness with Identity Collectors.

In large companies, the AD administrators are not the same person as the network / firewall administrators. And those AD administrators are not very keen on letting other people accessing the Domain Controllers and installing 3rd party software on those servers.

With independent servers (not domain joined) for the Identity Collector, firewall administrators can have complete control over the Identity Collector without the help of the AD administrator. This is very usefull when troubleshooting Identity Awareness issues. 

And Domian Controllers have a specific task. Being Domain Controllers (maybe with the DNS and NTP services enabled). Installing 3rd party software on these vital servers is not something I would normally prefer.

Regards,
Martijn

the_rock
Legend
Legend

I can tell you having done all 3, they ALL work fine, BUT, as the guys said, option 3 is definitely most preferred.

Andy

PhoneBoy
Admin
Admin

Our official documentation says to install on a separate system (not the AD controller).

the_rock
Legend
Legend

From:

https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics/Identity-...

 

  • If you install Identity Collector directly on the Domain Controllers (DCs) (including Windows Firewall), make sure the Windows Firewall rules allow DNS, LDAP, and DCOM traffic from the computer on which Identity Collector is installed.

    In Windows Firewall, add this "Allow" rule

    the_rock_0-1694455111123.gif

     

    :

    "Remote Event Log Management" > "Remote Event Log Management (RPC)"

  • Identity Collector processes these Windows events:

    • Authentication events - 4624, 4768, 4769, 4770

    • Group update events - 4728, 4729, 4732, 4733, 4756, 4757

    • Group deletion events - 4730, 4734, 4758

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events