> Source: [sk122157](https://support.checkpoint.com/results/sk/sk122157)

# sk122157 - Identity Collector support on Scalable Chassis 40000 / 60000

| Property | Value |
|----------|-------|
| Solution ID | sk122157 |
| Date Created | 2018-01-09 |
| Last Modified | 2023-08-15 |
| Technical Level | General |
| Products | Security Gateway, Scalable Platforms |
| Versions | R82.10, R82, R81.20, R82, R81.20 |
| Platform | 6, 41000 (EOL), 44000, 64000 |

## Solution

The **40000 / 60000 Scalable Chassis** support the Identity Collector starting from:

* [Check Point R80.20SP](https://support.checkpoint.com/results/sk/sk140392)
* [Jumbo Hotfix Accumulator for R76SP.50](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk117633) - Take 31 (Issue SPC-16)

### Supported features:

* Versions R80.20SP and higher fully support Identity Collector in the Push mode (SmartPull is not supported).
* Up to 150,000 users are supported with the following conditions:
  * Security Groups R76SP.50 act as PEP only.
  * Memory consumption might increase up to 1 Gb.
  * For an R77.30 Security Management that manages Security Groups R76SP.50, a hotfix is required.   
    [Contact Check Point Support](https://www.checkpoint.com/support-services/contact-support/) to get a required Hotfix (Issue 01976351).

### Part 1 - Configuring the Security Group

**To configure the Security Gateway to work with the Identity Collector:**

1. In SmartConsole, click the ***Gateways \& Servers*** view.
2. Double-click the Security Gateway object for your Security Group.
3. On the ***General Properties*** page, on the ***Network Security*** tab, select ***Identity Awareness*** .  
   The Identity Awareness Configuration wizard opens.
4. In the ***Methods For Acquiring Identity*** step, click ***Terminal Servers -\> Next***.
5. Select the domain of your Active Directory and enter your AD username and password. (You must have at least the LDAP permissions).
6. Click ***Next -\> Finish***.
7. From the tree on the left, select ***Identity Awareness***.
8. Select ***Terminal Servers -\> Settings*** .  
   Set the ***Pre-shared secret*** . Click ***Edit***.
9. In the ***Accessibility*** window, select how the Identity Collector connects to the Security Group.   
   Click ***OK***.
10. Click ***OK*** to close all windows.
11. Install the Access Control policy.

### Part 2 - Configuring Identity Collector

If you install Identity Collector on two computers for High Availability, the Identity Collector must be configured identically. The Security Group ignores the duplicate identity events.[](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk108235)

**To configure the Identity Collector:**

1. Open the Identity Collector.
2. In the main window at the top, click ***Domains***.
3. In the ***Domains*** window, click the ***New*** icon. Enter the new domain.
4. Click ***Test -\> OK***.
5. In the ***Identity Sources*** tab, click the ***New*** icon.
6. Select ***Active Directory*** and choose either ***Fetch Automatically*** or ***Add Manually*** .
   1. If you chose ***Fetch Automatically*** :
      * Choose your domain and add the domain controller IP address. Click ***Fetch***.
      * Select the servers from the Fetched Servers list. Click ***OK***.
   2. If you chose ***Add Manually*** :
      * In the ***New Active Directory Server window***, enter: The domain controller FQDN, Domain, domain controller IP address, and the site name.
      * Click ***Test -\> OK***.
7. In the main window at the top, click ***Query Pools*** and click the ***New*** icon.
8. In the ***Query Pool*** window, enter a name for the query pool, and select the ***Identity Sources*** that you want to query. Click ***OK***.
9. In the ***Gateways*** tab, click the ***New*** icon.  
   Set the configured gateway to be the Identity Server for this Identity Collector.
10. In the ***New Gateway*** window:
    1. Enter the name of the Security Group.
    2. Enter the ***IP address*** of the Security Group.
    3. Enter the ***Shared Secret***you generated earlier.
    4. Select a ***Query Pool*** .  
       **Important**: If the version of the Security Group you are configuring is lower than R80.10, select the checkbox.
11. Click ***Test -\> OK***.
12. When the certificate fingerprint and name show, click ***Trust***, to enable trust.
13. Click ***OK***.

For more information, refer to:

* [Identity Awareness Clients Administration Guide](https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Default.htm) \> the "Identity Collector" section.
* [](http://downloads.checkpoint.com/dc/download.htm?ID=26770)[sk113833 - "Table pdp_sessions entries limit (90000) reached" critical system alert messages in SmartView Tracker](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk113833)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
