- CheckMates
- :
- Products
- :
- Quantum
- :
- Management
- :
- Identity tags from third party sources
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Identity tags from third party sources
Hello,
I found an old post regarding this topic but with no solution to the following issue:
I am integrating a third party identity source (Clearpass) via IA API and I would like to work with identity tags. The thing is that I cannot see in the IA API guide the way to create this tags in Clearpass so they can match with my Identity Tags in Check Point.
Would it match if the string of any attribute sent via api is the same as the value in Identity Tag "External Identifier"?
Thanks!!
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As I recall it's the groups provided with the user-group field from Aruba that is matched to the identity tag (tag external identifier).
The Identity tag itself is created within Check Point and linked with an access-role referenced in the policy.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I would suggest to contact CP TAC to learn if and how this is possible ! You can later post the solution here...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
As I recall it's the groups provided with the user-group field from Aruba that is matched to the identity tag (tag external identifier).
The Identity tag itself is created within Check Point and linked with an access-role referenced in the policy.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Chris,
That makes sense. I will try by matching the tag External Identifier with the "user-group" attribute string and post the result.
Thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
I have tested it and it works. The Identity Awareness API collects the string contained in the field "user-groups" and it matches it with the "External Identifyer" value of the Identity Tag.
The authentication event is correctly associated to the Access Role that contains the Identity Tag.
Thanks!!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I presume it is similar to how Azure AD worked in R80.40 (before we added support for GraphAPI).
This means manually creating the tag on the Check Point side using the same name, same capitalization as the relevant group(s) defined in Clearpass.
