Configuring Active Directory and LDAP for DLP

You can configure the DLP Gateway to access a Microsoft Active Directory or LDAP server to:

  • Authenticate to the DLP Portal with Active Directory credentials

  • Authenticate to UserCheck with Active Directory credentials

  • Define Active Directory or LDAP groups to be used in the DLP policy

  • Define the My Organization object

If you run the wizard from a computer in the Active Directory domain, the Data Loss PreventionClosed Check Point Software Blade on a Security Gateway that detects and prevents the unauthorized transmission of confidential information outside the organization. Acronym: DLP. Wizard asks for your Active Directory credentials to create the LDAP account unit automatically. You can run the wizard again from a computer in the Active Directory domain to create the LDAP account unit.

Rerunning the Data Loss Prevention Wizard

If you run the DLP Wizard from a computer that is not part of the Active Directory domain, you can run it again from a computer in the Active Directory domain to create the LDAP account unit.

To run the Data Loss Prevention Wizard again:

  1. In SmartConsoleClosed Check Point GUI application used to manage a Check Point environment - configure Security Policies, configure devices, monitor products and events, install updates, and so on., click Gateways & Servers and double-click the Security GatewayClosed Dedicated Check Point server that runs Check Point software to inspect traffic and enforce Security Policies for connected network resources..

    The gateway window opens and shows the General Properties page.

  2. Clear the Data Loss Prevention Software BladeClosed Specific security solution (module): (1) On a Security Gateway, each Software Blade inspects specific characteristics of the traffic (2) On a Management Server, each Software Blade enables different management capabilities..

  3. Select the Data Loss Prevention Software Blade.

    The Data Loss Prevention Wizard starts.