<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Unable to enforce user-based policy(AD query) from Security Gateway in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-enforce-user-based-policy-AD-query-from-Security/m-p/107781#M14455</link>
    <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;will have to comment on your first question, but I suspect the answer is no.&lt;/P&gt;
&lt;P&gt;Identity Collector is generally recommended in larger AD environments (more than a few hundred users).&lt;BR /&gt;It uses&lt;SPAN&gt;&amp;nbsp;the Windows Event Log API for fetching the DC's security logs, which is in contrast to AD Query which uses WMI, with the identities pushed from the Active Directory server.&lt;/SPAN&gt;&lt;BR /&gt;More details here:&amp;nbsp;&lt;A href="https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108235" target="_blank" rel="noopener"&gt;https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108235&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 14 Jan 2021 05:12:32 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2021-01-14T05:12:32Z</dc:date>
    <item>
      <title>Unable to enforce user-based policy(AD query) from Security Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-enforce-user-based-policy-AD-query-from-Security/m-p/107452#M14388</link>
      <description>&lt;P&gt;Hi All&lt;/P&gt;&lt;P&gt;We have integrated the CheckPoint with Active Directory to enforce user-based policy through an AD query. Post integration, we are able to fetch all user information through the dashboard therby create access role objects and also push the user-based policy to the Gateway. But the main problem here is that the Gateway is not able to enforce this user-based policy.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Setup details:&lt;/P&gt;&lt;P&gt;Management server: Baremetal server R80.20&lt;/P&gt;&lt;P&gt;Gateway: 44k Chassis R80.20sp&lt;/P&gt;&lt;P&gt;AD server: Windows 2012&lt;/P&gt;&lt;P&gt;AD user for integration: Not Administrator but followed&amp;nbsp;sk93938&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Observation:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;"#adlog a dc" command shows "has connection" to all the domain controllers.&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp; wbemtest results show success for the user that is used to integrate with AD.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;No firewall between Gateway and Domain controllers to block DCE-PRC protocol port negotiation.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;No drop logs in the Gateway where AD query is running for traffic towards Domain controller except for the occasional TCP out of state drops(traffic is symmetric checked).&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Able to see user information from "adlog a query ip/user" command output.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Only able to see failed authentication and logout logs for the users in the CheckPoint smartlog.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;test_ad_connectivity -x &amp;lt;customer domain&amp;gt; -o my_test.txt output is shown below.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;[Expert@Checkpoint-ch01-01:0]# more my_test.txt&lt;BR /&gt;(&lt;BR /&gt;:status (SUCCESS_WMI)&lt;BR /&gt;:err_msg ("ADLOG_SUCCESS;LDAP_PROTOCOL_ERROR")&lt;BR /&gt;:ldap_status (LDAP_PROTOCOL_ERROR)&lt;BR /&gt;:wmi_status (ADLOG_SUCCESS)&lt;BR /&gt;:timestamp ("Fri Jan 8 17:14:28 2021")&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;My Analysis:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;Chances are that the domain controller is not sending user login event logs to CheckPoint.&lt;/P&gt;&lt;P&gt;OR&lt;/P&gt;&lt;P&gt;The Gateway is not able to extract the information for the logs pulled from the Domain controller.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Need your expertise to proceed further!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;Amith Gururaj Rao&lt;/P&gt;</description>
      <pubDate>Mon, 11 Jan 2021 10:20:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-enforce-user-based-policy-AD-query-from-Security/m-p/107452#M14388</guid>
      <dc:creator>amith_rao</dc:creator>
      <dc:date>2021-01-11T10:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to enforce user-based policy(AD query) from Security Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-enforce-user-based-policy-AD-query-from-Security/m-p/107559#M14396</link>
      <description>&lt;P&gt;Is there a TCP connection between the AD Servers and the gateway?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 04:30:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-enforce-user-based-policy-AD-query-from-Security/m-p/107559#M14396</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-12T04:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to enforce user-based policy(AD query) from Security Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-enforce-user-based-policy-AD-query-from-Security/m-p/107561#M14397</link>
      <description>&lt;P&gt;Yes, I can see traffic on ports 135 and 389 between Gateway and AD server.&lt;/P&gt;&lt;P&gt;Just to give more background we are doing a Migration from PAN to CheckPoint. A similar user-based policy is properly being enforced by the existing PAN gateway but only to note they are using user-id agent server for AD query and the credential used by them is super admin.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 05:42:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-enforce-user-based-policy-AD-query-from-Security/m-p/107561#M14397</guid>
      <dc:creator>amith_rao</dc:creator>
      <dc:date>2021-01-12T05:42:28Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to enforce user-based policy(AD query) from Security Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-enforce-user-based-policy-AD-query-from-Security/m-p/107655#M14421</link>
      <description>&lt;P&gt;What we do with AD Query is subscribe to very specific events, which the AD Server is supposed to send us.&lt;BR /&gt;The gateway then looks up the groups via LDAP.&lt;BR /&gt;That said, for anything more than a few hundred users, Identity Collector is probably a better solution than AD Query.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Recommend a TAC case to troubleshoot this.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Jan 2021 21:40:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-enforce-user-based-policy-AD-query-from-Security/m-p/107655#M14421</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-12T21:40:57Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to enforce user-based policy(AD query) from Security Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-enforce-user-based-policy-AD-query-from-Security/m-p/107676#M14425</link>
      <description>&lt;P&gt;Thanks for the valuable input&amp;nbsp;Dameon and also we will consider moving it to the TAC.&lt;/P&gt;&lt;P&gt;Meanwhile, during yesterdays troubleshooting it was observed that the AD server is not enabled with Success &amp;amp; Failure for both "Audit Account logon events" and "Audit Logon Events" as per&amp;nbsp;sk60501.&amp;nbsp;&lt;/P&gt;&lt;P&gt;So before going ahead with the enablement of these settings can the below two options work?&lt;BR /&gt;&amp;nbsp;&lt;BR /&gt;1. Considering the integration with an Administrator account, will it have the privilege to read the Audit logs even though the "success &amp;amp; failure for Audit account logon event and Audit logon event is not enabled" in the AD server.&lt;/P&gt;&lt;P&gt;2. Will the Identity collector be of any help in this scenario? the reason for this question is we don't have enough information on the querying method of the identity collector and how different it is from the typical AD query.&lt;/P&gt;</description>
      <pubDate>Wed, 13 Jan 2021 06:50:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-enforce-user-based-policy-AD-query-from-Security/m-p/107676#M14425</guid>
      <dc:creator>amith_rao</dc:creator>
      <dc:date>2021-01-13T06:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: Unable to enforce user-based policy(AD query) from Security Gateway</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-enforce-user-based-policy-AD-query-from-Security/m-p/107781#M14455</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;will have to comment on your first question, but I suspect the answer is no.&lt;/P&gt;
&lt;P&gt;Identity Collector is generally recommended in larger AD environments (more than a few hundred users).&lt;BR /&gt;It uses&lt;SPAN&gt;&amp;nbsp;the Windows Event Log API for fetching the DC's security logs, which is in contrast to AD Query which uses WMI, with the identities pushed from the Active Directory server.&lt;/SPAN&gt;&lt;BR /&gt;More details here:&amp;nbsp;&lt;A href="https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108235" target="_blank" rel="noopener"&gt;https://supportcenter.us.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk108235&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Jan 2021 05:12:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Unable-to-enforce-user-based-policy-AD-query-from-Security/m-p/107781#M14455</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-01-14T05:12:32Z</dc:date>
    </item>
  </channel>
</rss>

