Identity Collector - Working with Active Directory

Use Identity CollectorClosed Check Point dedicated client agent installed on Windows Servers in your network. Identity Collector collects information about identities and their associated IP addresses and sends it to the Check Point Firewalls for identity enforcement, you can download the Identity Collector package from the Support Center. to get identity information from an Active Directory (AD) server more efficiently than with standard AD QueryClosed Check Point clientless identity acquisition tool. It is based on Active Directory integration and it is completely transparent to the user. The technology is based on querying the Active Directory Security Event Logs and extracting the user and computer mapping to the network address from them. It is based on Windows Management Instrumentation (WMI), a standard Microsoft protocol. The Check Point Firewall with Identity Awareness enabled communicates directly with the Active Directory domain controllers and does not require a separate server. No installation is necessary on the clients, or on the Active Directory server..

Prerequisites

  • Identity Collector uses the Windows Event Log API for fetching the security logs from Domain Controllers. You must give Identity Collector permissions to use this API.

  • By default, Identity Collector uses NTLM for communication with the Domain Controller (DC). KerberosClosed An authentication server for Microsoft Windows Active Directory Federation Services (ADFS). is also supported.

    To use Kerberos for communication between Identity Collector and the Domain Controller (DC) host, you must define the DC Host object with a host name (FQDN). If the DC Host object is defined with an IP address, or if Kerberos fails for any reason, then Identity Collector uses NTLM for communication with the DC host.

Limitations

  • Identity Collector can communicate with up to 35 Active Directory servers.
  • Identity Collector can process up to 1900 Active Directory events per second.

Configuring the Identity Collector to work with Active Directory:

  1. In Identity Collector, add a new Active Directory Domain.

  2. In Identity Collector, add new Active Directory Domain Controllers.

    Follow one of these procedures to add the necessary Domain Controllers.

  3. In the Identity Collector, add a new Query Pool, or edit a current Query Pool.

    See Identity Collector - Query Pools.

  4. In the Identity Collector, add a new Filter for the login events, or edit a current Filter.

    See Identity Collector - Filters for Login Events.

  5. Connect the Identity Collector to the Check Point Identity ServerClosed Check Point Firewall with enabled Identity Awareness Software Blade..

    See Identity Collector - Connecting to an Identity Awareness Gateway