10. Check Point Getting Started R80.20. Identity Awareness

10. Check Point Getting Started R80.20. Identity Awareness

Welcome to the anniversary — the 10th lesson. Today, we will talk about another Check Point blade — Identity Awareness. At the very beginning, when describing the NGFW, we determined that it is essential to regulate access based on accounts rather than IP addresses. This necessity arises primarily from the increased mobility of users and the widespread adoption of the BYOD — bring your own device model. A company may have numerous people connecting via WiFi, obtaining dynamic IPs, and from different network segments. Good luck creating access lists based on IPs. Here, user identification becomes indispensable. And the Identity Awareness blade will assist us in this matter.

But first, let's understand what user identification is most commonly used for.

  1. To restrict network access based on user accounts rather than IP addresses. Access can be regulated not only to the Internet but also to any other network segments, such as DMZ.
  2. Access based on VPN. It is much more convenient for a user to use their domain account for authentication than to come up with another password.
  3. To manage Check Point, an account is also necessary, which can have various permissions.
  4. And the most pleasant part — Reporting. It's much nicer to see specific users in reports, not just their IP addresses.

At the same time, Check Point supports two types of accounts:

  • Local Internal Users. A user is created in the local database of the management server.
  • External Users. External databases can include Microsoft Active Directory or any other LDAP server.

Today we will talk about network access. To manage network access with an Active Directory in place, the so-called Access Role, is used as an object (source or destination), allowing the use of three user parameters:

  1. Network — that is, the network from which the user is trying to connect
  2. AD User or User Group — this data is retrieved directly from the AD server
  3. Machine — workstation.

User identification can be performed in several ways:

  • AD QueryCheck Point reads the logs of the AD server for authenticated users and their IP addresses. Computers that are in the AD domain are automatically identified.
  • Browser-Based AuthenticationUser identification via the browser (Captive Portal or Transparent Kerberos). This is most often used for devices that are not in the domain.
  • Terminal ServersIn this case, identification is carried out using a special terminal agent (installed on the terminal server).

These are the three most common options, but there are three more:

  • Identity AgentsA special agent is installed on user computers.
  • Identity CollectorA separate utility that is installed on Windows Server and collects authentication logs instead of a gateway. This is practically mandatory when there are a large number of users.
  • RADIUS AccountingAnd how could we do without the good old RADIUS.

In this lesson, I will demonstrate the second option — Browser-Based. I think we have enough theory; let's move on to practice.

Video lesson

Play video

Stay tuned for more and join our YouTube channel 🙂

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster