Cisco Identity Services Engine and Check Point Integration

Cisco ISE gives a wealth of user identity, endpoint device, and network context data that is beneficial to multiple IT platforms for customers around the globe. To bring more insight to hazardous user activities on the network, Cisco ISE employs Cisco Platform Exchange Grid (pxGrid) technology to share identity, device, and network information. The IT infrastructure can aid more use cases and function more effectively by becoming identity, device, and network conscious. Cisco pxGrid is a cohesive framework that provisions multivendor, cross-platform network system cooperation among IT infrastructures such as security monitoring and detection structures, network policy platforms, identity and access management platforms, and almost any other IT operations platform.

This integration delivers Check Point gateways with improved visibility of user actions while improving management of corporate resources. ISE assists the Check Point console to show circumstantial data associated with an incident, such as the user’s characteristics and level of access. This ability enables your security team to make access policy judgments by using identity information which provides far more policy information than traditional firewalls, which are restricted to data like IP addresses or port numbers. This improved level of detail from ISE can decrease threats and data loss by limiting access to resources by users and devices. The resolution is composed of Cisco ISE running pxGrid context-exchange abilities, an ISE Plus or Advanced Feature license, and the Check Point Identity Awareness Software Blade.

How Cisco ISE & Check Point Integration Work

• Cisco ISE supplies its user identity and device data to Check Point Identity Awareness

• Identity Awareness utilizes the precise, real-time user identity context given by ISE in its firewall rule base

• ISE circumstantial information is also added to related events in Check Point to give the supplementary context of the user, device, and access level, assisting analysts to better comprehend the consequence of a security incident

• All of these utilities can be recorded and reported on within the Check Point console, which gives unified user activities for security threat reporting

Some of the chief ISE attributes obtainable for use by Check Point for user-related context include:

• User: user name, IP address, authentication status, location

• User class: authorization group

• Cisco TrustSec: security group tag (SGT)

For more details on the Cisco Identity Services Engine, go to http://cisco.com/go/ise or contact our Cisco Licensing Specialists here.