Which TWO of the following statements accurately describe the functionality of the Identity Awareness 'Identity Collector'?
Trap 1: It must be installed directly on the Security Gateway.
The Identity Collector is a standalone application typically installed on a dedicated server or a management station, not on the Security Gateway itself. Placing it on the gateway would increase CPU load and negate the primary performance benefit of offloading identity processing tasks.
Trap 2: It eliminates the need for any Identity Awareness configuration on…
Even with the Identity Collector, the Security Gateway must have the Identity Awareness Software Blade enabled and configured to receive identity updates. The Identity Collector is an auxiliary tool that improves efficiency but does not replace the fundamental requirement for gateway-level identity processing configuration.
Trap 3: It only supports integration with Microsoft Active Directory.
The Identity Collector is versatile and supports various sources beyond Microsoft Active Directory, including Cisco ISE, Novell eDirectory, and others. Restricting it to only Active Directory would limit its utility in heterogeneous enterprise networks that utilize multiple different identity management platforms to secure their infrastructure.
- A
It must be installed directly on the Security Gateway.
Why it fails: The Identity Collector is a standalone application typically installed on a dedicated server or a management station, not on the Security Gateway itself. Placing it on the gateway would increase CPU load and negate the primary performance benefit of offloading identity processing tasks.
- B
It communicates with Active Directory to retrieve identity information.
The Identity Collector connects to domain controllers using protocols like WMI or event logs to collect logon data. By acting as the central collection point, it consolidates identity data before forwarding it to multiple gateways, centralizing the management of identity sources in the network.
- C
It sends identity information to the Security Gateway using the OPSEC protocol.
The Identity Collector forwards the gathered user-to-IP mapping information to the Security Gateway using the proprietary Check Point Identity Awareness protocol. This ensures that the gateway can apply identity-based access control rules without needing to maintain direct connections to every domain controller or identity source.
- D
It eliminates the need for any Identity Awareness configuration on the Gateway.
Why it fails: Even with the Identity Collector, the Security Gateway must have the Identity Awareness Software Blade enabled and configured to receive identity updates. The Identity Collector is an auxiliary tool that improves efficiency but does not replace the fundamental requirement for gateway-level identity processing configuration.
- E
It only supports integration with Microsoft Active Directory.
Why it fails: The Identity Collector is versatile and supports various sources beyond Microsoft Active Directory, including Cisco ISE, Novell eDirectory, and others. Restricting it to only Active Directory would limit its utility in heterogeneous enterprise networks that utilize multiple different identity management platforms to secure their infrastructure.