Security

last person joined: 18 hours ago 

Forum to discuss Enterprise security using HPE Aruba Networking NAC solutions (ClearPass), Introspect, VIA, 360 Security Exchange, Extensions, and Policy Enforcement Firewall (PEF).
Expand all | Collapse all

Clearpass Checkpoint Identity Awareness Integration

This thread has been viewed 21 times
  • 1.  Clearpass Checkpoint Identity Awareness Integration

    Posted Dec 07, 2018 03:53 AM

    Hi All

     

    Currently i try to integrate some identity awareness for checpoint with clearpass, the aim of this integration is to get know user id and ip from radius that given on clearpass, currently i follow the step Technote CPPM Third party enforcement 1.3, i get confused on where i can get the url api link from clearpass for checkpoint.

    Clearpass Version ClearPass Policy Manager 6.5

    and checkpoint verison R80.10



  • 2.  RE: Clearpass Checkpoint Identity Awareness Integration

    EMPLOYEE
    Posted Dec 07, 2018 08:30 AM
    A new doc for R80 will be released very soon.


  • 3.  RE: Clearpass Checkpoint Identity Awareness Integration

    Posted Dec 09, 2018 10:42 PM

    Thanks for your information sir :)



  • 4.  RE: Clearpass Checkpoint Identity Awareness Integration

    Posted Dec 08, 2018 07:38 AM

    Hi,

     

    The URLs for R80 are

    - "/_IA_API/v1.0/add-identity" for Check Point Login

    - "/_IA_API/v1.0/delete-identity" for Check Point Logout

     

    Everything else is the same as the guides already published.

    Also, under R80 "Identity Awareness" tab, there is a new Identity API setting you should enable, instead of using the "Terminal Server Agent". Make sure you enable the API access on the Checkpoint interface you will target,  under "Accessibility".

     

    Unfortunatelly I no longer have access to a CheckPoint, but as far as I remember this was all that was needed.

     

    Regards



  • 5.  RE: Clearpass Checkpoint Identity Awareness Integration

    Posted Dec 09, 2018 10:41 PM

    Hi Ricard

     

    by ur reply ist should be like on the attachment ?, i already did all of the command from the technote but still fail,



  • 6.  RE: Clearpass Checkpoint Identity Awareness Integration

    Posted Aug 11, 2020 02:17 PM

    Are you using a distributed deployment? If so, are you pointing ClearPass to the Management server or the gateway for the context server?



  • 7.  RE: Clearpass Checkpoint Identity Awareness Integration

    Posted Sep 04, 2020 05:24 AM

    Thanks for sharing useful information with us.. It really helpful to me..I always prefer to read the quality content and this thing I found in you post. thanks for sharing with us.. Tell Dunkin



  • 8.  RE: Clearpass Checkpoint Identity Awareness Integration

    Posted Sep 04, 2020 08:17 AM

    For a distributed Check Point deployment  set the context server IP in CPPM to the firewall, and if the firewalls are in a cluster use the VIP.

     Also don't forget to configure profiling, which was my mistake.