<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: dentity Collector (Active Directory) - Identity Propagation Failed Login in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/dentity-Collector-Active-Directory-Identity-Propagation-Failed/m-p/149216#M23899</link>
    <description>&lt;P&gt;Hey,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First, blur your LogServerOrigin - if it matters or not.&lt;/P&gt;&lt;P&gt;Now, do you get the error on the "Failed Log In" or on any identity records ?!?!?!?!&lt;/P&gt;&lt;P&gt;We had that in the past, and all we did was to drop the SSL HASH from the LDAP objects.&amp;nbsp;&lt;/P&gt;&lt;P&gt;That happened because AD Team changed certificates on their servers... so it will fail since the fingerprint/hash doesn't match anymore .&lt;/P&gt;&lt;P&gt;(see the&amp;nbsp;sk156853 and you will get it, &lt;STRONG&gt;JUST&lt;/STRONG&gt;&lt;U&gt;!!!!! &lt;STRONG&gt;leave&lt;/STRONG&gt; the Fingerprint &lt;STRONG&gt;empty&lt;/STRONG&gt; !!!!! )&lt;/U&gt;&lt;/P&gt;&lt;P&gt;This is how an "Failed Log In" looks for us - as you can see the machine was identified properly in AD and mapped to AD groups.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 802px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16657i58DC1000698BD2C9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 23 May 2022 07:38:01 GMT</pubDate>
    <dc:creator>Sorin_Gogean</dc:creator>
    <dc:date>2022-05-23T07:38:01Z</dc:date>
    <item>
      <title>dentity Collector (Active Directory) - Identity Propagation Failed Login</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/dentity-Collector-Active-Directory-Identity-Propagation-Failed/m-p/149201#M23896</link>
      <description>&lt;P&gt;Dear All,&lt;/P&gt;&lt;P&gt;i discovered a few days that the majority of the&amp;nbsp;Identity Awareness events from "Identity Collector (Active Directory)"&lt;/P&gt;&lt;P&gt;are followed by&amp;nbsp;Authentication Status "Failed Login".&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;Any clues what might is wrong?&lt;/P&gt;&lt;P&gt;MAny Thanks,&lt;/P&gt;&lt;P&gt;YV&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 05:03:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/dentity-Collector-Active-Directory-Identity-Propagation-Failed/m-p/149201#M23896</guid>
      <dc:creator>johnyb</dc:creator>
      <dc:date>2022-05-23T05:03:09Z</dc:date>
    </item>
    <item>
      <title>Re: dentity Collector (Active Directory) - Identity Propagation Failed Login</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/dentity-Collector-Active-Directory-Identity-Propagation-Failed/m-p/149216#M23899</link>
      <description>&lt;P&gt;Hey,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;First, blur your LogServerOrigin - if it matters or not.&lt;/P&gt;&lt;P&gt;Now, do you get the error on the "Failed Log In" or on any identity records ?!?!?!?!&lt;/P&gt;&lt;P&gt;We had that in the past, and all we did was to drop the SSL HASH from the LDAP objects.&amp;nbsp;&lt;/P&gt;&lt;P&gt;That happened because AD Team changed certificates on their servers... so it will fail since the fingerprint/hash doesn't match anymore .&lt;/P&gt;&lt;P&gt;(see the&amp;nbsp;sk156853 and you will get it, &lt;STRONG&gt;JUST&lt;/STRONG&gt;&lt;U&gt;!!!!! &lt;STRONG&gt;leave&lt;/STRONG&gt; the Fingerprint &lt;STRONG&gt;empty&lt;/STRONG&gt; !!!!! )&lt;/U&gt;&lt;/P&gt;&lt;P&gt;This is how an "Failed Log In" looks for us - as you can see the machine was identified properly in AD and mapped to AD groups.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 802px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16657i58DC1000698BD2C9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 07:38:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/dentity-Collector-Active-Directory-Identity-Propagation-Failed/m-p/149216#M23899</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-05-23T07:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: dentity Collector (Active Directory) - Identity Propagation Failed Login</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/dentity-Collector-Active-Directory-Identity-Propagation-Failed/m-p/149217#M23900</link>
      <description>&lt;P&gt;PS:&lt;/P&gt;&lt;P&gt;See this&amp;nbsp;&lt;A title="Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is" href="https://community.checkpoint.com/t5/Security-Gateways/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/m-p/100671/highlight/true#M10304" target="_self"&gt;(Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is)&lt;/A&gt;&amp;nbsp;and others similar - just search LDAPs in the CheckMates Forum.&lt;/P&gt;</description>
      <pubDate>Mon, 23 May 2022 07:40:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/dentity-Collector-Active-Directory-Identity-Propagation-Failed/m-p/149217#M23900</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-05-23T07:40:04Z</dc:date>
    </item>
    <item>
      <title>Re: dentity Collector (Active Directory) - Identity Propagation Failed Login</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/dentity-Collector-Active-Directory-Identity-Propagation-Failed/m-p/149308#M23919</link>
      <description>&lt;P&gt;What about this error message from the windows event log :&lt;/P&gt;&lt;P&gt;The server-side authentication level policy does not allow the user AAAAAA SID (S-1-5-21-000000000000) from address XX.XX.XX.XX to activate DCOM server. Please raise the activation authentication level at least to RPC_C_AUTHN_LEVEL_PKT_INTEGRITY in client application.&lt;/P&gt;&lt;P&gt;The above belongs to Management server trying to access the domain controller.&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 08:22:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/dentity-Collector-Active-Directory-Identity-Propagation-Failed/m-p/149308#M23919</guid>
      <dc:creator>johnyb</dc:creator>
      <dc:date>2022-05-24T08:22:22Z</dc:date>
    </item>
    <item>
      <title>Re: dentity Collector (Active Directory) - Identity Propagation Failed Login</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/dentity-Collector-Active-Directory-Identity-Propagation-Failed/m-p/149372#M23940</link>
      <description>&lt;P&gt;There are a ton of writings out-there in regards to the error you presented.&lt;/P&gt;&lt;P&gt;Seems more like an AD issue or account rights or a protocol change in the communication - didn't dig up too much.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tnx,&lt;/P&gt;&lt;P&gt;PS: have you cleared the AD server SSL HASH from the LDAP objects ?&lt;/P&gt;</description>
      <pubDate>Tue, 24 May 2022 20:21:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/dentity-Collector-Active-Directory-Identity-Propagation-Failed/m-p/149372#M23940</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-05-24T20:21:18Z</dc:date>
    </item>
    <item>
      <title>Re: dentity Collector (Active Directory) - Identity Propagation Failed Login</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/dentity-Collector-Active-Directory-Identity-Propagation-Failed/m-p/149399#M23942</link>
      <description>&lt;P&gt;no not yet i will have to raise a TAC.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2022 02:14:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/dentity-Collector-Active-Directory-Identity-Propagation-Failed/m-p/149399#M23942</guid>
      <dc:creator>johnyb</dc:creator>
      <dc:date>2022-05-25T02:14:04Z</dc:date>
    </item>
    <item>
      <title>Re: dentity Collector (Active Directory) - Identity Propagation Failed Login</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/dentity-Collector-Active-Directory-Identity-Propagation-Failed/m-p/149426#M23947</link>
      <description>&lt;P&gt;Is that required for a change in your environment, or you referred to TAC as CheckPoint TAC ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;You see in your logs some AD group retrieval errors and like we've seen it in the past, one of the problems was the fact that the SSL certificate was changed on AD servers, was changed.&lt;/P&gt;&lt;P&gt;In order to overcome that, all you have to do is to drop the Fingerprint from the LDAP objects, so they will not fail if the SSL cert changes in the future.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;</description>
      <pubDate>Wed, 25 May 2022 08:41:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/dentity-Collector-Active-Directory-Identity-Propagation-Failed/m-p/149426#M23947</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-05-25T08:41:58Z</dc:date>
    </item>
  </channel>
</rss>

