Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
CyberBreaker
Contributor

Identity Awareness in VSX

Hi Guys,

I've done enabling identity awareness in a standalone but not in a VSX environment. Is it possible in VSX? If possible, how the gateway communicate to the AD is it per VS basis?

Thanks

0 Kudos
8 Replies
Lari_Luoma
Ambassador Ambassador
Ambassador

Hi! 

What is your specific use case?

In VSX you enable IA on each virtual system and most commands work in VS context as in regular gateway.

Check the following:

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

 

0 Kudos
CyberBreaker
Contributor

Hi @Lari_Luoma ,

The use case is that I have a policy based on AD OU (e.g. Finance or HR) that is why I plan to use the IA blade.

You mean for example in my VS1 I enable IA but in VS2 IA is disable?

Another thing, when I deploy VSX, the dedicated management port is the one I use to register to the Smart Console as the VSX gateway and the internal interface of each VS is the one I use to enroll the VS in Smart Console. Is there's a way to create a sub-interface in the management port so that i can assign that management port sub-interface per VS?

For example, VS1 will have MGMT1.1 then VS2 MGMT1.2, is it possible?

Thanks

0 Kudos
Maarten_Sjouw
Champion
Champion

Some clarifications on VSX are needed it seems.
All communications between VS's and management are done over the VSX Gateway IP, also called VS0, so the IP you set on a Virtual System does not need to be able to communicate with the management server nor with the SmartConsole.
Each VS can be turned on or off regarding Identity Awareness, so you decide if it is needed for that specific VS and you turn it on only for those who need it.
Regards, Maarten
0 Kudos
Norbert_Bohusch
Advisor

Also LDAP communication is using VS0 per default.
If this needs to be changed, because VS0 is not able to reach the needed LDAP-Server, this behavior is controlled as described in the following SK: https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...
0 Kudos
CyberBreaker
Contributor

Hi @Lari_Luoma ,

Is the IA blade still supported even in VSX bridge mode for R80.x?

Thanks

0 Kudos
Lari_Luoma
Ambassador Ambassador
Ambassador

IA is not supported in bridge mode VS.

For more information take a look at the following SK.

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solut...

0 Kudos
CyberBreaker
Contributor

Hi @Lari_Luoma ,

Thanks for the feedback. 

But it supports in non-VSX bridge mode right?

Thanks

0 Kudos
Lari_Luoma
Ambassador Ambassador
Ambassador

Yes, supported in gw mode

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events