<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Identity Awareness Issues after resetting AD service account in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Issues-after-resetting-AD-service-account/m-p/55532#M12688</link>
    <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am running an environment with R80.10 and AD Query enabled for my gateways. All have been well till we had to perform a yearly password rotation for service accounts.&lt;/P&gt;&lt;P&gt;After the service account change, rules based on ID management and Mobile access authentication via AD stopped working.&lt;/P&gt;&lt;P&gt;I have updated the LDAP Account object with the new passwords, yet the issue still persist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Output of adlog a DC show the gateways are connected to the DC's. Output of the Test_ad_Connectivity tool returns a success status.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point don't know what else to check, any ideas on how to resolve.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 11 Jun 2019 16:51:47 GMT</pubDate>
    <dc:creator>chuka</dc:creator>
    <dc:date>2019-06-11T16:51:47Z</dc:date>
    <item>
      <title>Identity Awareness Issues after resetting AD service account</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Issues-after-resetting-AD-service-account/m-p/55532#M12688</link>
      <description>&lt;P&gt;Hello All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am running an environment with R80.10 and AD Query enabled for my gateways. All have been well till we had to perform a yearly password rotation for service accounts.&lt;/P&gt;&lt;P&gt;After the service account change, rules based on ID management and Mobile access authentication via AD stopped working.&lt;/P&gt;&lt;P&gt;I have updated the LDAP Account object with the new passwords, yet the issue still persist.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Output of adlog a DC show the gateways are connected to the DC's. Output of the Test_ad_Connectivity tool returns a success status.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;At this point don't know what else to check, any ideas on how to resolve.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 11 Jun 2019 16:51:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Issues-after-resetting-AD-service-account/m-p/55532#M12688</guid>
      <dc:creator>chuka</dc:creator>
      <dc:date>2019-06-11T16:51:47Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness Issues after resetting AD service account</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Issues-after-resetting-AD-service-account/m-p/55750#M12689</link>
      <description>&lt;P&gt;Have you opened a TAC case by chance?&lt;BR /&gt;Possible&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;has a suggestion.&lt;/P&gt;</description>
      <pubDate>Thu, 13 Jun 2019 18:28:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Issues-after-resetting-AD-service-account/m-p/55750#M12689</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-13T18:28:13Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness Issues after resetting AD service account</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Issues-after-resetting-AD-service-account/m-p/55762#M12690</link>
      <description>&lt;P&gt;Sounds like something is stuck in pdpd.&amp;nbsp; Anything interesting getting logged into $FWDIR/log/pdpd.elg?&amp;nbsp; As a last resort try killing it with "fw kill pdpd" and letting cpwd automatically restart pdpd within 60 seconds.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Jun 2019 01:14:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Issues-after-resetting-AD-service-account/m-p/55762#M12690</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2019-06-14T01:14:08Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness Issues after resetting AD service account</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Issues-after-resetting-AD-service-account/m-p/55888#M12691</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the response, I have logged a request with a checkpoint patner, who are our first level support, they insist the permissions on the account have changed, which is not the case.&lt;/P&gt;&lt;P&gt;To isolate the account permissions possibility, i have setup an identity collector, however the gateways are not identifying users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regards.&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jun 2019 00:19:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Issues-after-resetting-AD-service-account/m-p/55888#M12691</guid>
      <dc:creator>chuka</dc:creator>
      <dc:date>2019-06-16T00:19:05Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness Issues after resetting AD service account</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Issues-after-resetting-AD-service-account/m-p/55889#M12692</link>
      <description>&lt;P&gt;Hi Tim,&lt;/P&gt;&lt;P&gt;Thanks for having a look, the only noticeable thing in pdpd.elg is that their are no user associations coming in. I have killed the process and restarted the gateway, stuck at same.&lt;/P&gt;&lt;P&gt;I have also deployed an IDC, issue still same, a snippet of pdpd.elg is shown below.&lt;/P&gt;&lt;P&gt;Anymore thoughts is welcomed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;[25936 4106254096]@fw-xxxx-[16 Jun 1:19:49] [TRACKER]: #3478674 -&amp;gt; OUTGOING -&amp;gt; IDENTITY_REVOKE -&amp;gt; to pep: 127.0.0.1 (ipv4); (ipv6), RevokeInformation dump:&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;Unique ID : cbdd72e9&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;Remove existing connections : no&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;[25936 4106254096]@fw-xxx[16 Jun 1:19:49] [TRACKER]: #3478675 -&amp;gt; OUTGOING -&amp;gt; IDENTITY_REVOKE -&amp;gt; to pep: 127.0.0.1 (ipv4); (ipv6), RevokeInformation dump:&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;Unique ID : a5f1ee1c&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;Remove existing connections : no&lt;/EM&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;[25936 4106254096]@fw-xxx[16 Jun 1:19:54] [TRACKER]: #3478676 -&amp;gt; INCOMING -&amp;gt; AGENT_REQUEST -&amp;gt; ip: , type: IDCLogEvent&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;[25936 4106254096]@fw-xxx[16 Jun 1:19:54] [TRACKER]: #3478677 -&amp;gt; OUTGOING -&amp;gt; AGENT_RESPONSE -&amp;gt; ip: , type: IDCLogEvent, result: OK&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;[25936 4106254096]@fw-fw-xxx[16 Jun 1:19:54] [TRACKER]: #3478678 -&amp;gt; INCOMING -&amp;gt; AGENT_REQUEST -&amp;gt; ip: , type: IDCEvent&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;FONT color="#FF6600"&gt;&lt;EM&gt;[25936 4106254096]@fw-xxx[16 Jun 1:19:54] [TRACKER]: #3478679 -&amp;gt; INCOMING -&amp;gt; IDCOLLECTOR_ASSOCIATION -&amp;gt; Ip: x.x.x.x; User: ; User Groups: ; User Roles: ; Machine: bitlocker02v; Machine Groups: ; Machine Roles: ; Domain: xxxx.com; Source Type: AD; TTL: 43200; IDC IP: x.x.x.x&lt;/EM&gt;&lt;/FONT&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 16 Jun 2019 00:30:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Issues-after-resetting-AD-service-account/m-p/55889#M12692</guid>
      <dc:creator>chuka</dc:creator>
      <dc:date>2019-06-16T00:30:26Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness Issues after resetting AD service account</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Issues-after-resetting-AD-service-account/m-p/56070#M12693</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/28194"&gt;@chuka&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;[25936 4106254096]@fw-xxx[16 Jun 1:19:54] [TRACKER]: #3478679 -&amp;gt; INCOMING -&amp;gt; IDCOLLECTOR_ASSOCIATION -&amp;gt; Ip: x.x.x.x; User: ; User Groups: ; User Roles: ; Machine: bitlocker02v; Machine Groups: ; Machine Roles: ; Domain: xxxx.com; Source Type: AD; TTL: 43200; IDC IP: x.x.x.x&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This log means that IDC published an association to PDP for bitlocker02v machine in the specified domain.&lt;/P&gt;
&lt;P&gt;The rest of Identity Awareness chain is:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;send LDAP request to receive the identity groups.&amp;nbsp;&lt;/LI&gt;
&lt;LI&gt;match the identity (user/machine) + LDAP groups with Check Point access roles.&lt;/LI&gt;
&lt;LI&gt;publish this identity to all relevant PEP gateways.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I do recommend addressing this with TAC, as it seems to be something in the configuration which needs to be tuned.&lt;/P&gt;</description>
      <pubDate>Tue, 18 Jun 2019 12:55:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Issues-after-resetting-AD-service-account/m-p/56070#M12693</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2019-06-18T12:55:47Z</dc:date>
    </item>
  </channel>
</rss>

