<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Identity Awareness (AD Query) not applying Identities in Rulebase in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-AD-Query-not-applying-Identities-in-Rulebase/m-p/82626#M11380</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm looking at an issue with Identity awareness AD Query. From looking at the CPview, pdpd &amp;amp; pepd debug files I can see that identities are being gathered and stored on the gateway; PDP monitor has confirmed this. On the central management server, I am able to create access roles with the correct AD account set within &amp;amp; add them to the rulebase. However when testing the rule, my traffic hits the cleanup rule and is skipping the AD rule I have set.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am struggling to understand why this is happening as the gateway has knowledge of each AD user and associated IP address, as far as I can see all the required services are up. The gateway is also actively receiving events from multiple domain controllers.&lt;/P&gt;&lt;P&gt;Gateway is R80.20 Take 19 IAAS Azure&lt;/P&gt;&lt;P&gt;Management is R80.30&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is anybody able to point me in the right direction?&lt;/P&gt;</description>
    <pubDate>Tue, 21 Apr 2020 14:16:10 GMT</pubDate>
    <dc:creator>AshleyM</dc:creator>
    <dc:date>2020-04-21T14:16:10Z</dc:date>
    <item>
      <title>Identity Awareness (AD Query) not applying Identities in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-AD-Query-not-applying-Identities-in-Rulebase/m-p/82626#M11380</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;I'm looking at an issue with Identity awareness AD Query. From looking at the CPview, pdpd &amp;amp; pepd debug files I can see that identities are being gathered and stored on the gateway; PDP monitor has confirmed this. On the central management server, I am able to create access roles with the correct AD account set within &amp;amp; add them to the rulebase. However when testing the rule, my traffic hits the cleanup rule and is skipping the AD rule I have set.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am struggling to understand why this is happening as the gateway has knowledge of each AD user and associated IP address, as far as I can see all the required services are up. The gateway is also actively receiving events from multiple domain controllers.&lt;/P&gt;&lt;P&gt;Gateway is R80.20 Take 19 IAAS Azure&lt;/P&gt;&lt;P&gt;Management is R80.30&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is anybody able to point me in the right direction?&lt;/P&gt;</description>
      <pubDate>Tue, 21 Apr 2020 14:16:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-AD-Query-not-applying-Identities-in-Rulebase/m-p/82626#M11380</guid>
      <dc:creator>AshleyM</dc:creator>
      <dc:date>2020-04-21T14:16:10Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness (AD Query) not applying Identities in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-AD-Query-not-applying-Identities-in-Rulebase/m-p/82670#M11381</link>
      <description>Have you verified the LDAP portion of the config is correct and working?&lt;BR /&gt;This is needed to correctly associate users with their groups, and thus their access roles.</description>
      <pubDate>Tue, 21 Apr 2020 18:40:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-AD-Query-not-applying-Identities-in-Rulebase/m-p/82670#M11381</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2020-04-21T18:40:01Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness (AD Query) not applying Identities in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-AD-Query-not-applying-Identities-in-Rulebase/m-p/82775#M11382</link>
      <description>&lt;P&gt;Thanks for your response &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;, yes I believe it is all correct and working. The Account used is a domain administrator &amp;amp; I can see the AD user information such as group membership is being pulled through, both when adding users to access roles on the management server &amp;amp; when running a PDP monitor on the gateway.&lt;/P&gt;&lt;P&gt;It looks like all the required information is present on the gateway but just not being used.&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 14:19:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-AD-Query-not-applying-Identities-in-Rulebase/m-p/82775#M11382</guid>
      <dc:creator>AshleyM</dc:creator>
      <dc:date>2020-04-22T14:19:57Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness (AD Query) not applying Identities in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-AD-Query-not-applying-Identities-in-Rulebase/m-p/82778#M11383</link>
      <description>&lt;P&gt;Have you verified the pepd daemon is running?&lt;/P&gt;&lt;P&gt;Here a couple useful commands to test if pepd is doing its job&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;SPAN&gt;#pep show stat&lt;/SPAN&gt;&lt;FONT face="Calibri"&gt; – shows basic status of PEP&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Calibri"&gt;&lt;SPAN&gt;#pep show pdp all&lt;/SPAN&gt;&lt;SPAN&gt; – shows status of PDPs&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Calibri"&gt;&lt;SPAN&gt;&lt;SPAN&gt;#pep show user query usr &amp;lt;username&amp;gt;&lt;/SPAN&gt; – shows identity status of single user. Useful to confirm that the PEP has received identity data from PDP.&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Calibri"&gt;&lt;SPAN&gt;&lt;SPAN&gt;#pep show user query cid &amp;lt;IP address&amp;gt;&lt;/SPAN&gt; – shows identity status of single IP address&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#000000"&gt;&lt;FONT face="Calibri"&gt;&lt;SPAN&gt;Dave&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Apr 2020 14:31:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-AD-Query-not-applying-Identities-in-Rulebase/m-p/82778#M11383</guid>
      <dc:creator>David_C1</dc:creator>
      <dc:date>2020-04-22T14:31:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness (AD Query) not applying Identities in Rulebase</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-AD-Query-not-applying-Identities-in-Rulebase/m-p/97349#M11384</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I went back over the LDAP configuration again &amp;amp; found that the information in the LDAP account was correct. However when I took a look at the access roles in use I found they were pointing towards another LDAP account present on the management server, once I changed it to the new LDAP account I had created it started working. I'm now in the process of removing the obsolete LDAP accounts from the management server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks all for your help.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Sep 2020 11:46:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-AD-Query-not-applying-Identities-in-Rulebase/m-p/97349#M11384</guid>
      <dc:creator>AshleyM</dc:creator>
      <dc:date>2020-09-23T11:46:08Z</dc:date>
    </item>
  </channel>
</rss>

