156-215.75 · Question #522
Where does the security administrator activate Identity Awareness within SmartDashboard?
The correct answer is B. Gateway Object > General Properties. See the full explanation below for the reasoning.
Question
Where does the security administrator activate Identity Awareness within SmartDashboard?
Options
- ALDAP Server Object > General Properties
- BGateway Object > General Properties
- CPolicy > Global Properties > Identity Awareness
- DSecurity Management Server > Identity Awareness
How the community answered
(32 responses)- A16% (5)
- B75% (24)
- C6% (2)
- D3% (1)
Community Discussion
8The correct answer is B, Gateway Object > General Properties. Identity Awareness is a blade, and like all blades on a Check Point gateway, you enable it per-gateway in the gateway object itself, not at the global policy level or on the management server. When you open the gateway object in SmartDashboard and go to General Properties, you will see the Software Blades section where Identity Awareness has its own checkbox, and checking it activates the blade and unlocks the Identity Awareness tab for further configuration. The other options are distractors, LDAP server objects handle directory integration after the blade is already on, and Global Properties does not house blade activation controls.
I kept clicking C but the gateway is where you actually flip the switch, not global policy.
Guessed C, but Identity Awareness is a per-gateway toggle, so B.
Right, but the toggle she is calling per-gateway is actually per-interface on the gateway object, so a single gateway can have Identity Awareness enabled on its external leg while the internal DMZ leg collects no identity at all.
I went with C at first because Global Properties felt like the logical place to flip on a feature like this, but then I remembered you enable Identity Awareness blade per gateway, not globally, so it lives in the Gateway Object > General Properties where you tick the blade on.
Yeah Carlos that tracks, and the one thing I would add is that after you tick the blade on in the gateway object you still have to go into the Identity Awareness configuration tab to point it at your AD Query or Browser-Based Auth source, otherwise the blade is enabled but not actually doing anything.
I actually went straight to C first because Global Properties felt like the right level for enabling a feature across the board, but then I remembered that Identity Awareness is a blade, and blades get enabled per gateway on the Gateway Object under General Properties, same as you would enable IPS or Application Control. The blade architecture is what nailed it, B is correct.
Blade-level enablement on the Gateway Object is right, and worth adding that you also need the Identity Awareness policy layer wired in SmartConsole and at least one identity source configured, like AD Query or the Captive Portal, or the blade sits enabled but effectively blind.