How To's - Configure the SmartConsole Administrator with ISE as the Authentication Server

How To's - Configure the SmartConsole Administrator with ISE as the Authentication Server

Hi there,

In this post, we are going to create an administrator account for Homer and Bart in SmartConsole, using ISE as the authentication server.

This lab assumes you already have an AD, ISE and a Check Point distributed deployment in place. If you want to deploy a similar solution, please read my previous posts (or watch The Simpsons :-).

Hajime!

You should create 2 users:

  • homer.simpson in AD
  • bart.simpson in ISE

Then let’s configure ISE, by adding the Security Management Server as NAD in Administration > Network Resources > Network Devices > Add

No alt text provided for this image

Next, confirm that your authentication and authorization rules will allow access.

No alt text provided for this image

Moving on to the SmartConsole, let's create an object representing ISE by going to New > Host...

No alt text provided for this image

Now let's create a RADIUS server in New > More > Server > Radius...

Enter the name to define the RADIUS server. For Host, select the node defined in previous step. Set the Service as Radius. Enter the Shared Secret configured on ISE. Select the Version as RADIUS Ver. 1.0. Set the Protocol type as PAP. Leave the Priority set to the default value of 1 (highest priority) and publish the changes.

No alt text provided for this image

Now let's create the new Administrators in the Users and Administrators menu.

Enter the administrator name and select the Permissions Profile > Super User.

Set the Authentication Method as RADIUS.

Note: Give the same administrator the name that is defined on AD and ISE.

Finally Install Database.

No alt text provided for this image


No alt text provided for this image
No alt text provided for this image

Now let's try log in using the new accounts.

User: homer.simpson

No alt text provided for this image
No alt text provided for this image

User: bart.simpson

No alt text provided for this image
No alt text provided for this image

And we configured successfully two administrator accounts in SmartConsole using ISE as the authentication server.

I hope you enjoyed this post, leave your comments below and I'll see you on the next one.


Reference:

https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk40697



要查看或添加评论,请登录

Silésio Carvalho的更多文章

  • The Power of Visualization

    The Power of Visualization

    I am Silésio Carvalho, CCIE #65745 and I passed the CCIE lab exam on November 30 2021. If you paid attention to the…

    8 条评论
  • ForticlientEMS fails connection with Fortihate

    ForticlientEMS fails connection with Fortihate

    For those trying to play with Fortigate ZTNA, if you're using Fortigate on evaluation mode, one of the restrictions…

  • Why you won't become a CCIE

    Why you won't become a CCIE

    I'm not the author for the text below but I wanted to share this with you, in case you're thinking about taking the…

    10 条评论
  • Trobleshoot SD-WAN – Part 2

    Trobleshoot SD-WAN – Part 2

    Hi there, in the last article we saw how to troubleshoot control connection failure on Cisco SD-WAN, caused by…

  • Trobleshoot SD-WAN – Part 1

    Trobleshoot SD-WAN – Part 1

    Hi there, While deploying Cisco SD-WAN you might face control connection errors related to certificate. Here are some…

  • Como eu come?aria de novo, em Networking (Redes)?

    Como eu come?aria de novo, em Networking (Redes)?

    Estou nesta jornada a mais de uma década e até a data, tem sido uma caminhada nada fácil (por op??o minha) mas muito…

    6 条评论
  • CCIE - The Plan

    CCIE - The Plan

    Hi there, first of all, I’d like thank everyone for the congratulations messages. As a thank you back, I’ll share with…

    20 条评论
  • How To's - Deploy Checkpoint Remote Access VPN

    How To's - Deploy Checkpoint Remote Access VPN

    Hi there, in this post we'll see how to deploy remote access using Checkpoint Remote Access VPN client. Some…

    3 条评论
  • How To’s – Deploy DMVPN Front Door VRF (automating with ansible)

    How To’s – Deploy DMVPN Front Door VRF (automating with ansible)

    Hi there, in this post we're going to deploy DMVPN Front Door VRF and using ansible. Basically, we'll be using DMVPN…

    1 条评论
  • How To’s – Deploy DMVPN Dual Hub Dual Cloud

    How To’s – Deploy DMVPN Dual Hub Dual Cloud

    Hi there, in this post we’ll see how to deploy DMVPN Dual Hub Dual Cloud. Basically it means we’ll have two or more…

社区洞察

其他会员也浏览了