Identity Tag
What can I do here?
Use this window to create a new identity tag or edit an existing one.
|
Getting Here - Object Explorer > New > User > Identity tag
|
Using Identity Tags in Access Role Matching
Identity Tags let you include external identifiers (such as Cisco® Security Group Tags, or any other groups provided by any Identity Source) in Access Role matching. These external identifiers act like a tag that can be assigned to a certain user, machine or group.
To use Identity Tags in Access Role matching:
- Create a new Identity Tag:
- Click menu > > > .
- Enter a name for the object.
Note - If you enter the first, the Identity Tag object gets the same name.
- In the field, enter one of these:
- A Cisco Security Group Tag, as defined on the Cisco ISE server or acquired through Identity Collector.
- A custom tag (defined on a third party product) acquired through the Check Point Identity Web API.
Note - The External Identifier must be a unique name.
- Click .
- Include the Identity Tag in an Access Role:
- Click menu > > > .
- On the tab or tab, select.
- Click the icon.
- Click on the domain name button in the top left corner and select .
- Select the Identity Tag created in Step 1.
- Click .
- Add this Access Role to the or column of an Access Policy rule.
- Install the Access Policy.