<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness with AD and SSSD in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-with-AD-and-SSSD/m-p/149668#M24034</link>
    <description>&lt;P&gt;hey,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i think you have smth wrong with the Linux and AD part there, as for us, we can see clearly the machine (IP is showed on purpose) and the user (actually is the last user that logged on that machine).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 807px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16745i501F651B2551E187/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also the pdp monitor on Linux Node:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 757px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16748i5C4B4BEC2A28907C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;and on an windows node:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 757px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16747iAFA585C5A494DE2F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;PS: I don't get it why are you afraid in showing pictures of errors or whatever you consider being wrong, and blur whatever is unnecessary....&lt;/P&gt;</description>
    <pubDate>Sat, 28 May 2022 17:45:22 GMT</pubDate>
    <dc:creator>Sorin_Gogean</dc:creator>
    <dc:date>2022-05-28T17:45:22Z</dc:date>
    <item>
      <title>Identity Awareness with AD and SSSD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-with-AD-and-SSSD/m-p/148991#M23847</link>
      <description>&lt;P&gt;We have an AD and a working SSSD configuration for unix server. The identity awareness blade is configured via the collector and unfortunately (as far as I know) there is no agent for unix server.&lt;/P&gt;&lt;P&gt;If checking a specific server via "pdp monitor" every unix server has a domain controller as machine_name, which is obviously wrong.&lt;/P&gt;&lt;P&gt;Any hints on how to fix this?&lt;/P&gt;</description>
      <pubDate>Thu, 19 May 2022 09:55:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-with-AD-and-SSSD/m-p/148991#M23847</guid>
      <dc:creator>User1234</dc:creator>
      <dc:date>2022-05-19T09:55:15Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness with AD and SSSD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-with-AD-and-SSSD/m-p/149596#M24005</link>
      <description>&lt;P&gt;As far as I know, Check Point Identity Collector is reading the Active Directory security logs just like the old AD Query did, but with a different (and more robust and scalable) approach.&lt;/P&gt;
&lt;P&gt;What I want to say: Have you checked the Active Directory security logs for log-in events from these unix servers? Do they look different, than the ones from Microsoft servers? If yes, do they have the needed and correct information in them?&lt;/P&gt;
&lt;P&gt;If the needed and correct information is there, but just the format is different, then Check Point could improve their Identity Collector code to support this scenario.&lt;/P&gt;
&lt;P&gt;If the security logs do not contain the correct information, than Check Point cannot do anything and you have to reconfigure (or even patch) SSSD to provide the correct information during authentication process so that the domain controllers have a chance to write usefull security logs.&lt;/P&gt;
&lt;P&gt;Sorry, I do not have access to such a setup at the moment to provide you with own findings, I just want to help you to get one step further in troubleshooting, when nobody from the community has answered after a week &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 May 2022 08:08:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-with-AD-and-SSSD/m-p/149596#M24005</guid>
      <dc:creator>Tobias_Moritz</dc:creator>
      <dc:date>2022-05-27T08:08:44Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness with AD and SSSD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-with-AD-and-SSSD/m-p/149668#M24034</link>
      <description>&lt;P&gt;hey,&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i think you have smth wrong with the Linux and AD part there, as for us, we can see clearly the machine (IP is showed on purpose) and the user (actually is the last user that logged on that machine).&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 807px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16745i501F651B2551E187/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also the pdp monitor on Linux Node:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 757px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16748i5C4B4BEC2A28907C/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;and on an windows node:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Untitled.png" style="width: 757px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16747iAFA585C5A494DE2F/image-size/large?v=v2&amp;amp;px=999" role="button" title="Untitled.png" alt="Untitled.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you,&lt;/P&gt;&lt;P&gt;PS: I don't get it why are you afraid in showing pictures of errors or whatever you consider being wrong, and blur whatever is unnecessary....&lt;/P&gt;</description>
      <pubDate>Sat, 28 May 2022 17:45:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-with-AD-and-SSSD/m-p/149668#M24034</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-05-28T17:45:22Z</dc:date>
    </item>
  </channel>
</rss>

