Identity Collector - Working with Active Directory
Use Identity Collector
Check Point dedicated client agent installed on Windows Servers in your network. Identity Collector collects information about identities and their associated IP addresses and sends it to the Check Point Firewalls for identity enforcement, you can download the Identity Collector package from the Support Center. to get identity information from an Active Directory (AD) server more efficiently than with standard AD Query
Check Point clientless identity acquisition tool. It is based on Active Directory integration and it is completely transparent to the user. The technology is based on querying the Active Directory Security Event Logs and extracting the user and computer mapping to the network address from them. It is based on Windows Management Instrumentation (WMI), a standard Microsoft protocol. The Check Point Firewall with Identity Awareness enabled communicates directly with the Active Directory domain controllers and does not require a separate server. No installation is necessary on the clients, or on the Active Directory server..
Prerequisites
-
Identity Collector uses the Windows Event Log API for fetching the security logs from Domain Controllers. You must give Identity Collector permissions to use this API.
-
By default, Identity Collector uses NTLM for communication with the Domain Controller (DC). Kerberos
An authentication server for Microsoft Windows Active Directory Federation Services (ADFS). is also supported.To use Kerberos for communication between Identity Collector and the Domain Controller (DC) host, you must define the DC Host object with a host name (FQDN). If the DC Host object is defined with an IP address, or if Kerberos fails for any reason, then Identity Collector uses NTLM for communication with the DC host.
Limitations
- Identity Collector can communicate with up to
35Active Directory servers. -
Identity Collector can process up to
1900Active Directory events per second.
Configuring the Identity Collector to work with Active Directory:
-
In Identity Collector, add a new Active Directory Domain.
To add a new Active Directory Domain
-
Open the Identity Collector application.
-
At the top, click Domains.
-
From the top toolbar, click New Domain (
). -
Enter the Domain name to show in the Identity Collector.
The domain name must exactly match the actual domain name to ensure all features function correctly.
-
Optional: Enter the comment.
-
In the Username and Password fields, enter the Domain account credentials.
Important:
-
The account must be a member of the Event Log Readers group.
-
To enable the configuration of Domain Controllers automatically by DNS and LDAP queries, as well as the periodic AD discovery flows to function seamlessly with Kerberos authentication, you must write the domain credentials in the User Principal Name (UPN) format. It is crucial to note that the use of a combination of User Principal Name format and DC IP address is not compatible.
-
-
In the DC Host name / IP Address field, enter the host name (FQDN) or the IP address of one of the Domain Controllers that you want to add.
-
Click OK.
To edit a current Active Directory Domain
-
Open the Identity Collector application.
-
At the top, click Domains.
-
Select the applicable Domain.
-
From the top toolbar, click Edit Domain (
). -
Configure the Domain.
-
Click OK.
To delete a current Active Directory Domain
-
Open the Identity Collector application.
-
At the top, click Domains.
-
Select the applicable Domain.
-
From the top toolbar, click Delete Domain (
). -
Click Yes to confirm.
-
Click OK.
-
-
In Identity Collector, add new Active Directory Domain Controllers.
Follow one of these procedures to add the necessary Domain Controllers.
Add Domain Controllers automatically by DNS and LDAP queries
-
Open the Identity Collector application.
-
From the left navigation toolbar, click Identity Sources.
-
Click New Source (
) > Active Directory > Fetch Automatically.
The Add Domain Controllers window opens.
-
Enter the Domain Controller information:
-
Domain - Select the Active Directory Domain that contains the Domain Controllers, or click
and add this Domain to Identity Collector.
-
DC Host name / IP Address - Enter the host name (FQDN) or the IP address of one of the Domain Controllers you want to add.
Note - To work with Kerberos authentication, you must enter a host name (FQDN). If you enter an IP address, then Identity Collector uses NTLM for communication with the DC.
-
-
Optional: To configure the Identity Collector to fetch Active Directory Domain Controllers from LDAP over SSL, select LDAP over SSL.
-
Click Fetch.
A list of the Domain Controllers appears.
-
Enable the Domain Controllers you want to add.
-
Click OK.
The enabled Domain Controllers are added.
Add Domain Controllers manually one at a time
-
Open the Identity Collector application.
-
From the left navigation toolbar, click Identity Sources.
-
Click New Source (
)> Active Directory > Add Manually.
-
Enter the Domain Controller Name to appear in the Identity Collector.
-
Optional: Enter your comment.
-
Enter the Domain Controller information:
-
Domain
Select the Active Directory Domain, or configure a new one.
-
DC Host name / IP Address
Enter the host name or the IP address of one of the Domain Controllers you want to add.
Note - To work with Kerberos authentication, you must use a host name that is an FQDN. If you enter an IP address, Identity Collector uses NTLM for communication with the Domain Controller.
-
Site
Optional. Enter the Domain Controller site name.
-
Is Forwarded Event Log Collector
Select this option, if this server is not a Domain Controller, but a server, to which the login events are forwarded.
-
-
Click Test.
-
Click OK.
The Domain Controller is added.
-
-
In the Identity Collector, add a new Query Pool, or edit a current Query Pool.
-
In the Identity Collector, add a new Filter for the login events, or edit a current Filter.
-
Connect the Identity Collector to the Check Point Identity Server
Check Point Firewall with enabled Identity Awareness Software Blade..See Identity Collector - Connecting to an Identity Awareness Gateway