Identity Collector - Working with Active Directory
To configure the Identity Collector to work with Active Directory:
-
In Identity Collector Check Point dedicated client agent installed on Windows Servers in your network. Identity Collector collects information about identities and their associated IP addresses and sends it to the Check Point Security Gateways for identity enforcement, you can download the Identity Collector package from the Support Center., add a new Active Directory Domain.
To add a new Active Directory Domain-
Open the Identity Collector application.
-
At the top, click Domains.
-
From the top toolbar, click New Domain ().
-
Enter the Domain name to show in the Identity Collector.
The domain name must exactly match the actual domain name to ensure all features function correctly.
-
Optional: Enter the comment.
-
In the Username and Password fields, enter the Domain account credentials.
Important:
-
The account must be a member of the Event Log Readers group.
-
To enable the configuration of Domain Controllers automatically by DNS and LDAP queries, as well as the periodic AD discovery flows to function seamlessly with Kerberos An authentication server for Microsoft Windows Active Directory Federation Services (ADFS). authentication, it is imperative that domain credentials be formatted in the User Principal Name (UPN) format. It is crucial to note that the use of a combination of User Principal Name format and DC IP address is not compatible.
-
-
In the DC Host name / IP Address field, enter the host name or the IP address of one of the Domain Controllers that you want to add.
-
Click OK.
To edit a current Active Directory Domain-
Open the Identity Collector application.
-
At the top, click Domains.
-
Select the applicable Domain.
-
From the top toolbar, click Edit Domain ().
-
Configure the Domain.
-
Click OK.
To delete a current Active Directory Domain-
Open the Identity Collector application.
-
At the top, click Domains.
-
Select the applicable Domain.
-
From the top toolbar, click Delete Domain ().
-
Click Yes to confirm.
-
Click OK.
-
-
In Identity Collector, add new Active Directory Domain Controllers.
Follow one of these procedures to add the necessary Domain Controllers.
Add Domain Controllers automatically by DNS and LDAP queries-
Open the Identity Collector application.
-
From the left navigation toolbar, click Identity Sources.
-
From the top toolbar, click New Source > Active Directory > Fetch Automatically.
-
Enter the Domain Controller information:
-
Domain - Select the Active Directory Domain, or configure a new one.
-
DC Host name / IP Address - Enter the host name or the IP address of one of the Domain Controllers you want to add.
Note - To work with Kerberos authentication, you must use the host name.
-
-
Optional: To configure the Identity Collector to fetch Active Directory Domain Controllers from LDAP over SSL, select LDAP over SSL.
-
Click Fetch.
A list of the Domain Controllers appears.
-
Enable the Domain Controllers you want to add.
-
Click OK.
The enabled Domain Controllers are added.
Add Domain Controllers manually one at a time-
Open the Identity Collector application.
-
From the left navigation toolbar, click Identity Sources.
-
From the top toolbar, click New Source > Active Directory > Add Manually.
-
Enter the Domain Controller Name to appear in the Identity Collector.
-
Optional: Enter your comment.
-
Enter the Domain Controller information:
-
Domain
Select the Active Directory Domain, or configure a new one.
-
DC Host name / IP Address
Enter the host name or the IP address of one of the Domain Controllers you want to add.
Note - To work with Kerberos authentication, you must use the host name.
-
Site
Optional. Enter the Domain Controller site name.
-
Is Forwarded Event Log Collector
Select this option, if this server is not a Domain Controller, but a server, to which the login events are forwarded.
-
-
Click Test.
-
Click OK.
The Domain Controller is added.
-
-
In the Identity Collector, add a new Query Pool, or edit a current Query Pool.
-
In the Identity Collector, add a new Filter for the login events, or edit a current Filter.
-
Connect the Identity Collector to the Check Point Identity Server Check Point Security Gateway with enabled Identity Awareness Software Blade..
See Identity Collector - Connecting to an Identity Awareness Gateway
|
Notes:
|