> Source: [sk180475](https://support.checkpoint.com/results/sk/sk180475)

# sk180475 - Cannot install IoT policy on a Centrally Managed Spark Firewall because Identity Awareness is not enabled in the Security Gateway object

| Property | Value |
|----------|-------|
| Solution ID | sk180475 |
| Date Created | 2023-05-09 |
| Last Modified | 2025-04-21 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R81.10.X |

## Symptoms

- Cannot install IoT policy on a Centrally Managed Quantum Spark appliance because Identity Awareness is not enabled in the Security Gateway object.

## Cause

The Identity Awareness Management API is not supported when a Management Server manages an R81.10.X Quantum Spark appliance that runs the Gaia Embedded operating system.

Note - This limitation does **not** apply to Security Gateways that run the Gaia operating system.

## Solution

To manually enable Identity Awareness on the Centrally Managed Quantum Spark appliance that is managed by a Management Server:

1. Connect with SmartConsole to the Security Management Server / Domain Management Server that manages the Quantum Spark appliance.

2. From the left navigation panel, click **Gateways \& Servers**.

3. Create a new **Host** object with these settings:

   * Name: **localhost**

   * IPv4 address: **127.0.0.1**

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk180475/SK_IOT202305181628271.png)
4. Open the applicable Security Gateway object.

5. From the left tree, click the **General Properties** page.

6. On the **Network Security** tab, select the **Identity Awareness** Software Blade:

   1. The **Identity Awareness Configuration** wizard opens.

   2. In the **Methods for Acquiring Identity** window, clear the **AD Query** option, if you do not use it.

   3. Click **Cancel**.

7. From the left tree, click the **Identity Awareness** page.

8. Configure the **Identity Web API** settings:

   1. Select **Identity Web API** and click **Settings**.

      Example:

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1672757093583/identity_web_api202301031704283.png)
   2. In the **Authorized Clients** section, click **\[+\]** and select the **Host** object you created earlier (**localhost**).

   3. In the **Selected Client Secret** field, enter your secret word, or click **Generate** to create a random secret.

   4. Click **OK** to close the **Identity Web API Settings** window.

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1672757093583/configure_identity_web_api202301031705204.png)
9. Click **OK** to close the Security Gateway object.

10. Install the Access Control Policy on the Security Gateway object.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
