<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity collector account across domain Trust? in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-account-across-domain-Trust/m-p/62518#M12439</link>
    <description>Why is it's not acceptable to use an account from other.biz to pull logs from other.biz?</description>
    <pubDate>Wed, 11 Sep 2019 20:44:16 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2019-09-11T20:44:16Z</dc:date>
    <item>
      <title>Identity collector account across domain Trust?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-account-across-domain-Trust/m-p/62492#M12438</link>
      <description>Hello I can't figure out, how to use an account in another domain to access the logs on a DC with Identity Collector. We have one main company AD forest and some domains outside with bidirectional domain trust, say -&amp;gt; main domain: company.biz -&amp;gt; some domain: other.biz other.biz is not in the same forest as Company.biz, however there is a domain trust in both directions. Now if I use an account in other.biz to access the DC of other.biz, everything works fine. But no matter how I enter an account of company.biz there always is an auth. failure (tried company\account , company.biz\account, account@company.biz). Account is member of [Event Log Readers] group in other.biz. What am I missing here (every idea welcome)??</description>
      <pubDate>Wed, 11 Sep 2019 15:08:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-account-across-domain-Trust/m-p/62492#M12438</guid>
      <dc:creator>Richard_Farnham</dc:creator>
      <dc:date>2019-09-11T15:08:30Z</dc:date>
    </item>
    <item>
      <title>Re: Identity collector account across domain Trust?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-account-across-domain-Trust/m-p/62518#M12439</link>
      <description>Why is it's not acceptable to use an account from other.biz to pull logs from other.biz?</description>
      <pubDate>Wed, 11 Sep 2019 20:44:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-account-across-domain-Trust/m-p/62518#M12439</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-09-11T20:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: Identity collector account across domain Trust?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-account-across-domain-Trust/m-p/62704#M12440</link>
      <description>Well, this will be our workaround? Its main drawback is administrative overhead: in my case there is a bunch of bidirectionally trusted external domains, which then each requires a own account with own pwd Change and maybe different conventions in naming/pwd complexity.. . And there is in fact no technical reason that prohibits the use of one central account.</description>
      <pubDate>Fri, 13 Sep 2019 07:59:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-account-across-domain-Trust/m-p/62704#M12440</guid>
      <dc:creator>Richard_Farnham</dc:creator>
      <dc:date>2019-09-13T07:59:36Z</dc:date>
    </item>
    <item>
      <title>Re: Identity collector account across domain Trust?</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-account-across-domain-Trust/m-p/62732#M12441</link>
      <description>&lt;P&gt;It was a question, that's all.&lt;BR /&gt;Not sure it's a limitation specifically, but maybe&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;can comment.&lt;/P&gt;</description>
      <pubDate>Fri, 13 Sep 2019 18:12:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-collector-account-across-domain-Trust/m-p/62732#M12441</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-09-13T18:12:19Z</dc:date>
    </item>
  </channel>
</rss>

