- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Announcing Quantum R82.10!
Learn MoreOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello Everyone,
Me and my team from few days are trying to integrate Checkpoint Security Gateway with FreeIPA.
We have integration with Microsoft AD by LDAP Unit Object which is works.
Unfortunately, FreeIPA haven't "samAccountName" object class in directory schema, so when we try to add some users to Checkpoint Access Role we receive only blank directory tree.
We try to change Profile in FreeIPA Ldap Unit from Microsoft AD to OPSEC and Create LDAP Group with some option "Only Group in branch (DN prefix)", where we paste uid path to specific group, but log in to VPN was without success.
Somebody have any idea how to integrate this to systems?
Best regards
Jakub
Finally, we integrated FreeIPA with Checkpoint
Profile: Netscape_DS - this profile has good user info mapping
First: We are integrating two environments, so we forgot about routes - all traffic were from WAN interface (on first environment traffic were accepted, on second environment traffic were drop from WAN or not occur)
Second: To use this object, we need to use LDAP Group, where important is to use good LDAP Filter
Thank you for help, for me this post/issue is solved
Generic LDAP definitions should work.
Yes, we thought the same, but no.
User Object Class in FreeIPA is "uid". We try to use another User Directory Profile, but without success to log in.
From another site, when we use old Dashboard, with attribute "uid", we receive good results.
Maybe custom User Directory Profile, but how can we create it? Only by database edit?
Presumably through guidbedit, it might be possible.
Is there any manual or KB where this is described?
You can try asking the TAC about this.
However, you are ultimately trying to integrate with an LDAP directory we don't support.
Which means even if you do somehow make this work, if and when it breaks again, it won't be formally supported.
If this is a business requirement, your best bet is to work with the local Check Point office on an RFE.
Finally, we integrated FreeIPA with Checkpoint
Profile: Netscape_DS - this profile has good user info mapping
First: We are integrating two environments, so we forgot about routes - all traffic were from WAN interface (on first environment traffic were accepted, on second environment traffic were drop from WAN or not occur)
Second: To use this object, we need to use LDAP Group, where important is to use good LDAP Filter
Thank you for help, for me this post/issue is solved
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 27 | |
| 20 | |
| 16 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 3 | |
| 3 |
Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Fri 12 Dec 2025 @ 10:00 AM (CET)
Check Mates Live Netherlands: #41 AI & Multi Context ProtocolTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY