> Source: [sk31841](https://support.checkpoint.com/results/sk/sk31841)

# sk31841 - LDAP Configuration for Remote Access VPN

| Property | Value |
|----------|-------|
| Solution ID | sk31841 |
| Date Created | 2006-06-15 |
| Last Modified | 2025-03-03 |
| Technical Level | General |
| Products | Security Gateway, Security Management Server |
| Versions | R81 (EOS), R81 (EOS) |

## Solution

This article shows a basic workflow for using LDAP user groups to configure an Access Control rule for Remote Access VPN users.

When working with a User Directory (LDAP) server, the Check Point Security Management and Security Gateways work as User Directory (LDAP) clients. An Account Unit is the interface that allows interaction between these entities and the User Directory (LDAP) server(s).  

To configure Check Point to take identities from an User Directory (LDAP) server, the administrator must:

1. Define the Account Unit(s) that represent(s) the organization.
2. Enter the access information, required in order to connect to the relevant User Directory (LDAP) server.

Then, the Security Management / Multi-Domain Management / Security Gateways can connect to that User Directory (LDAP) server to retrieve users or make queries.  

**Note:** To retrieve users from a User Directory (LDAP) server, you need a User Directory (CPSB-UDIR) License. User Directory License is included in our newer management server products. For older management products that does not include CPSB-UDIR, need to purchase CPSB-UDIR to enable this feature. After you get the license, you must define an Account Unit that represents the User Directory (LDAP) server.   

**Procedure:**

1. For versions lower than R81, enable the "Use User Directory" option.  

   In SmartConsole, click **Menu** \> **Global properties** \> **User Directory** , and enable **Use User Directory** .  

   Example:  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk31841/11702161119.PNG)  

2. Create a Host object to represent your LDAP server.  

   In SmartConsole, from the right panel, click **New** \> **Host** .  

   At the top, enter a descriptive name.  
   Enter the IP address of your LDAP server.  
   Click OK.  

   Example:  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk31841/21702161123.PNG)  

3. Create a user template to represent the LDAP users.  

   In SmartConsole, from the right panel, click **New** \> **More** \> **User/Identity** \> **User Template** .  

   At the top, enter a descriptive name.  
   From the left, click **Authentication** .  
   In the **Authentication method** field, select **Check Point Password** .  
   Click OK.  

   Example:  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk31841/31702161129.1.PNG)  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk31841/31702161129.2.PNG)  

4. Create an LDAP Account Unit.  

   In SmartConsole, from the right panel, click **New** \> **More** \> **User/Identity** \> **LDAP Account Unit** .  

   1. On the **General** tab:  

      In the **Name** field, enter the object name  
      In the **Profile** field, select **Microsoft_AD**   
      In the **Account Unit usage** section, select **CRL Retrieval** and **User management** .  

      Example:  
      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk31841/41702170052.1.PNG)
   2. On the **Servers** tab:  

      Click **Add**   
      In the **Host** field, select the Host object of your LDAP server  
      In the **Port** field, leave the default value 389  
      In the **Username** field, enter the applicable username to connect to this LDAP server  
      In the**Login DN** field, enter the applicable DN (for example: `cn=useraccount, cn=users, DC=Domain, DC=org`)  
      To find a DN value of a user, you can use this command on the Windows LDAP server:  
      `dsquery user -name <username>`  
      In the **Password** and **Confirm password** fields, enter the applicable password to connect to this LDAP server  
      Click OK  

      Note: Do not configure anything on the Encryption tab.  

      Example:  

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk31841/41702161151.2.PNG)  

   3. On the **Objects Management** tab:  

      In the **Manage objects on** field, the object of your LDAP server appears automatically  
      Click **Fetch branches**   
      The AD branches must appear  

      Example:  
      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk31841/41702170053.3.1.PNG)  

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk31841/41702170054.3.2.PNG)  

      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk31841/41702170054.3.3.PNG)
   4. On the **Authentication** tab:  

      Clear the checkbox **Use common group path for queries**   
      In the **Allowed authentication schemes** section, you must select **Check Point Password**   
      Select **Users default template** and select the user template object you created earlier  
      Clear all other options  

      Click OK to close the LDAP Account Unit Properties
      Example:  
      ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk31841/41702170055.4.PNG)  

5. Create the necessary LDAP Group.  

   In SmartConsole, from the right panel, click **New** \> **More** \> **User/Identity** \> **LDAP Group**   

   At the top, enter a descriptive name  
   In the **Account Unit** field, select the LDAP Account Unit object you created earlier  
   In the **Group's Scope** section, select **All Account-Unit's Users**   
   Click OK  

   Example:  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk31841/51702170106.1.PNG)  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk31841/51702170109.2.PNG)  

6. In the Access Control policy, create a rule to allow traffic from users in the LDAP Group that connect over a Remote Access VPN.  

   In the **Source** column, right-click, and click **Add Legacy User Access**   
   In the **User Group** field, select the LDAP Group object and click OK  
   In the **Destination** column, select the applicable objects  
   In the **VPN** column, select the applicable Remote Access VPN community  
   In the **Services/Applications** column, select the applicable objects  
   In the **Action** column, select **Accept**   

   Example:  
   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk31841/61702170717.1.PNG)  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk31841/61702170717.2.PNG)  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk31841/61702170718.3.PNG)  

7. Install the Access Control Policy on the applicable Security Gateway / Cluster objects.

<br />

For more information, refer to the [Security Management Administration Guide](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doShowproductpage&productTab=documents&product=184) for your version.  

**Note** : If you use Remote Access VPN clients or Mobile Access SNX, then configure the smallest applicable number of LDAP branches in the LDAP Account Unit. The Security Gateway checks each connected user against the Active Domain Server. The number of LDAP queries the Security Gateway makes is equal to the number of LDAP branches. These LDAP queries can cause the VPND process to consume CPU a a high level. As a result, Security Gateway may not respond fast enough to Remote Access VPN connections. For example, see [sk134092](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk134092).

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
