Identity Collector - Working with NetIQ eDirectory LDAP Servers
|
Note - Check Point only supports user authentication for NetIQ eDirectory. |
Configuration Procedure:
-
In SmartConsole Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on., configure the Identity Awareness Check Point Software Blade on a Security Gateway that enforces network access and audits data based on network location, the identity of the user, and the identity of the computer. Acronym: IDA. Gateway to work with a NetIQ eDirectory LDAP server.
-
Configure the Identity Awareness Gateway object.
Procedure-
Open the Identity Awareness Gateway object.
-
Enable the Identity Awareness Software Blade Specific security solution (module): (1) On a Security Gateway, each Software Blade inspects specific characteristics of the traffic (2) On a Management Server, each Software Blade enables different management capabilities..
The Identity Awareness Configuration Wizard opens.
-
On the Methods For Acquiring Identity page, select Browser-Based Authentication or Terminal Servers and click Next.
You can disable this Identity Source later.
-
On the Integration With Active Directory page, select I do not wish to configure the Active Directory at this time and click Next.
-
Click Finish.
The Identity Awareness Configuration Wizard closes.
-
From the left navigation tree, go to the Identity Awareness page.
-
Select Identity Collector and click Settings.
-
Configure these settings:
-
Client Access Permissions - though which interfaces Identity Collector Check Point dedicated client agent installed on Windows Servers in your network. Identity Collector collects information about identities and their associated IP addresses, and sends it to the Check Point Security Gateways for identity enforcement. For more information, see sk108235. You can download the Identity Collector package from sk134312. client can connect to Security Gateway Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources.
-
Authorized Clients - which computers with installed Identity Collector can connect to Security Gateway
-
Selected Shared Secret - to configure in Identity Collector for this Security Gateway
-
Authentication Settings - how to authenticate users
-
-
Click OK to close the Identity Collector Settings window.
-
Click OK to close the Check Point Gateway window.
-
-
Create a new Host object to represent your NetIQ eDirectory LDAP server.
Procedure-
In the top left corner, click Objects > New Host.
-
Configure the object name and IP address.
-
Click OK.
-
-
Create a new LDAP Account Unit object to represent the NetIQ eDirectory LDAP server, which manages the identities.
Procedure-
In the top left corner, click Objects menu > Object Explorer.
-
In the left navigation tree, click Servers.
-
From the top toolbar, click New > More > User/Identity > LDAP Account Unit.
The LDAP Account Unit Properties window opens.
-
-
Configure the new LDAP Account Unit object that represents the NetIQ eDirectory LDAP server.
-
The 'General' tab
-
In the Name field, enter the applicable object name (for example,
mycompany.com_LDAP_ACC_UNIT
). -
In the Profile field, select Novell_DS.
-
In the Prefix field, enter your domain name (for example,
mycompany.com
). -
In the Account Unit usage section, select all the options.
-
In the Additional configuration section, select Enable Unicode support.
-
-
The 'Servers' tab
-
Click Add.
-
The LDAP Server Properties window opens.
-
Go to the General tab.
-
In the Host field, select the host object you created for this LDAP server in Step 2 above.
-
In the Username field, enter the username for this LDAP server (for example,
John.Smith
). -
In the Login DN field, enter the user's distinguished name (DN) for this LDAP server (see RFC1779).
Note - Refer to the official NetIQ documentation. For example, use the
ldapsearch
command. -
In the Password field, enter the password for this LDAP server.
-
In the Confirm password field, enter the password again.
-
Click OK to close the LDAP Server Properties window.
Note - The order in which these LDAP Servers come to the view, is the default order in which they are queried. You can configure the applicable priority for these LDAP Servers.
-
-
The 'Objects Management' tab
-
In the Server to connect field, select the host object you created for this LDAP server in Step 2 above.
-
Fetch or manually add the branch(es).
The branch name is the suffix of the Login DN that begins with
DC=
.For example, if the Login DN is
CN=John.Smith,CN=Users,DC=mycompany,DC=com
then the branch name is
DC=mycompany,DC=com
-
-
The 'Authentication' tab (Optional)
-
Clear Use common group path for queries.
-
In the Allowed authentication schemes section, select all the options.
-
In the Users' default values section:
-
Clear Use user template.
-
Select Default authentication scheme > Check Point Password.
-
-
-
-
Click OK to close the LDAP Account Unit Properties window.
-
In SmartConsole, install the Access Control Policy on the Identity Awareness Gateway that works as Identity Server Check Point Security Gateway with enabled Identity Awareness Software Blade..
-
-
In the Identity Collector, add a new NetIQ eDirectory LDAP Server.
Procedure-
Open the Identity Collector application.
-
From the left navigation toolbar, click Identity Sources.
-
From the top toolbar, click New Source > eDirectory.
-
Enter the eDirectory Server information:
-
Object Name - Enter the NetIQ eDirectory Server name to show in the Identity Collector.
-
Domain - Select the NetIQ eDirectory domain, or click New Domain to configure a New Domain:
-
Domain Name - Enter the NetIQ eDirectory Domain name to show in the Identity Collector.
-
(Optional) Enter your comment.
-
Username - Enter the NetIQ eDirectory username DN.
-
Password - Enter the password for the given NetIQ eDirectory username.
-
Click OK to close the New Domain window.
-
-
IP address - Enter the NetIQ eDirectory Server IP address.
-
Port - Enter the NetIQ eDirectory LDAP port (default is 389, SSL default is 636).
-
Site - (Optional) Enter the NetIQ eDirectory site.
-
Base DN - (Optional) Enter the queried base DN (for example,
o=corp
). -
LDAP over SSL - (Optional) Select for using LDAP over SSL.
-
-
Click OK to close the New eDirectory Server window.
-
-
In the Identity Collector, add a new Query Pool, or edit a current Query Pool
-
In the Identity Collector, add a new Filter for the login events, or edit a current Filter
-
Connect the Identity Collector to the Check Point Identity Server (Identity Awareness Gateway)
See Identity Collector - Connecting to an Identity Awareness Gateway.