<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Activate Identity Awareness in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144621#M22722</link>
    <description>&lt;P&gt;Maybe we got lucky that time, not sure, but thats what worked. I could be wrong when I say this, but from what I recall n old days, you never had to use admin account, but maybe that changed in R80 +.&lt;/P&gt;</description>
    <pubDate>Wed, 23 Mar 2022 16:46:23 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-03-23T16:46:23Z</dc:date>
    <item>
      <title>Activate Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144228#M22717</link>
      <description>&lt;P&gt;Hello community,&lt;BR /&gt;When I tried activate IA with AD Query, I got error message "User is not a domain administrator as such AD Query will not work".&lt;BR /&gt;But I using admin account with right credentials. Environment clusterXL R81.10, windows server 2012 R2.&lt;BR /&gt;What can be checked to understand where the problem is? &lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="111.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/15781iD9968A2050520C8A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="111.jpg" alt="111.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 20 Mar 2022 17:11:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144228#M22717</guid>
      <dc:creator>Herman</dc:creator>
      <dc:date>2022-03-20T17:11:27Z</dc:date>
    </item>
    <item>
      <title>Re: Activate Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144229#M22718</link>
      <description>&lt;P&gt;See&amp;nbsp;&lt;A class="cp_link sc_ellipsis" href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk86441&amp;amp;partition=Advanced&amp;amp;product=Identity" target="_blank"&gt;sk86441: &lt;STRONG&gt;ATRG&lt;/STRONG&gt;: &lt;STRONG&gt;Identity&lt;/STRONG&gt; &lt;STRONG&gt;Awareness&lt;/STRONG&gt;&lt;/A&gt;&amp;nbsp;!&lt;/P&gt;</description>
      <pubDate>Sun, 20 Mar 2022 17:57:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144229#M22718</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-03-20T17:57:51Z</dc:date>
    </item>
    <item>
      <title>Re: Activate Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144617#M22719</link>
      <description>&lt;P&gt;Have just seen this issue in a lab environment with the same issue (account is Enterprise Administrator etc.).&lt;BR /&gt;Installing a different policy fixed it.&lt;/P&gt;&lt;P&gt;Not sure yet what the problem is but at the moment but suspect HTTPS Inspection could be causing it or Application Control or URLF blade. HTTPS Inspection policy was last updated.&lt;/P&gt;&lt;P&gt;Edit: Also R81.10, no JHFA 30 installed yet.&lt;/P&gt;&lt;P&gt;Edit2: Windows Server 2016 Standard&lt;BR /&gt;&lt;BR /&gt;Rgds,&lt;/P&gt;&lt;P&gt;Don&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 16:34:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144617#M22719</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2022-03-23T16:34:19Z</dc:date>
    </item>
    <item>
      <title>Re: Activate Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144618#M22720</link>
      <description>&lt;P&gt;I saw this once before when I was on site with a customer and we just created another admin account and then it all worked. I really never got a good explanation from TAC why this would happen...&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 16:36:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144618#M22720</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-23T16:36:09Z</dc:date>
    </item>
    <item>
      <title>Re: Activate Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144619#M22721</link>
      <description>&lt;P&gt;We tried that and it failed for us. New AD admin and same groups (Enterprise admins etc.) with no luck.#&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 16:43:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144619#M22721</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2022-03-23T16:43:13Z</dc:date>
    </item>
    <item>
      <title>Re: Activate Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144621#M22722</link>
      <description>&lt;P&gt;Maybe we got lucky that time, not sure, but thats what worked. I could be wrong when I say this, but from what I recall n old days, you never had to use admin account, but maybe that changed in R80 +.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 16:46:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144621#M22722</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-03-23T16:46:23Z</dc:date>
    </item>
    <item>
      <title>Re: Activate Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144624#M22723</link>
      <description>&lt;P&gt;Have seen this happen when the AD domain is configured to only allow NTLMv2.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Check Point recommends using&amp;nbsp;&lt;/SPAN&gt;Identity Collector&lt;SPAN&gt;&amp;nbsp;as the identity source instead of AD Query - any chance you can switch to using that?&amp;nbsp; Seems using ADQ will only get more challenging in the future - check out &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk176148&amp;amp;partition=Basic&amp;amp;product=Identity" target="_self"&gt;sk176148&lt;/A&gt;.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 17:01:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144624#M22723</guid>
      <dc:creator>Ruan_Kotze</dc:creator>
      <dc:date>2022-03-23T17:01:05Z</dc:date>
    </item>
    <item>
      <title>Re: Activate Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144625#M22724</link>
      <description>&lt;P&gt;Good call. That would be my recommendation too,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 17:02:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144625#M22724</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2022-03-23T17:02:42Z</dc:date>
    </item>
    <item>
      <title>Re: Activate Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144626#M22725</link>
      <description>&lt;P&gt;Hi guys, many thanks for advice.&lt;BR /&gt;I catch this issue in my lab environment not production, I don't know what was it, but I reinstall windows server and it was resolve.&amp;nbsp;&lt;BR /&gt;Regarding Identity Collector I know, but for some tests needed exactly AD Query.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Mar 2022 17:07:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/144626#M22725</guid>
      <dc:creator>Herman</dc:creator>
      <dc:date>2022-03-23T17:07:15Z</dc:date>
    </item>
    <item>
      <title>Re: Activate Identity Awareness</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/205691#M38830</link>
      <description>&lt;P&gt;Just encountered the exact same issue with a fresh Win2022 Server lab installation.&lt;/P&gt;&lt;P&gt;The error messages when trying to connect the AD are quite useful: they tell you if it can't reach the ADC, if the credentials are wrong or if the domain can't be found.&lt;/P&gt;&lt;P&gt;Thus, if you see this "User is not a domain administrator as such AD Query will not work" message, it's most likely not a connection/lack of policies issue.&lt;BR /&gt;&lt;BR /&gt;Also keep in mind that the initial connectivity test is made from the SmartConsole's machine instead of from the GW.&lt;/P&gt;&lt;P&gt;&lt;U&gt;However, in my case after installing all the Windows updates and couple reboots, the connection eventually worked.&lt;/U&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 11 Feb 2024 14:24:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Activate-Identity-Awareness/m-p/205691#M38830</guid>
      <dc:creator>timdude</dc:creator>
      <dc:date>2024-02-11T14:24:09Z</dc:date>
    </item>
  </channel>
</rss>

