<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity awareness and ADS machine identity propagation in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/118939#M24129</link>
    <description>&lt;P&gt;Hi Niels,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;summary: it appears only the AD Servers , selected as an identity source that appear to be affected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;long:&lt;/P&gt;&lt;P&gt;We have the same behaviour in our environment. (1st time posting on checkpoint.... hooray.)&lt;BR /&gt;&amp;gt; other domain controllers,&amp;nbsp; &amp;nbsp;NOT in the Identity Collector as sources are registering just fine here.&lt;/P&gt;&lt;P&gt;It's only those&amp;nbsp; that are enlisted as "Identity Collector Sources"&amp;nbsp; that are not registering as "machine identity". Exactly what you described.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Was this fixed for you somehow recently? or still an open question? Wondering if we should open a case&amp;nbsp;@ CP for this or not.&lt;BR /&gt;Honestly we don't know if it has always been like this - but considering the Ruleset we stumbled upon a couple issues - and narrowed it down to the fact those specific Domain Controllers are not having their machine identity updated towards our Security Gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Thu, 20 May 2021 14:33:19 GMT</pubDate>
    <dc:creator>alexander_ae</dc:creator>
    <dc:date>2021-05-20T14:33:19Z</dc:date>
    <item>
      <title>Identity awareness and ADS machine identity propagation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/115009#M24123</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;In our setup we are using the Identity Awareness blade on a R80.40 Security Gateway, which receives identities from an Identity Collector. The Identity Collector itself collects the identities from a pool of Microsoft Active Directory servers.&lt;/P&gt;&lt;P&gt;Everything seems to be working fine for some time now, but I've noticed that for the Active Directory servers themselfs the Security Gateway isn't receiving Machine Identity Propagation login or updates. Is this by design?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;--Niels&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 08:05:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/115009#M24123</guid>
      <dc:creator>Niels_van_Sluis</dc:creator>
      <dc:date>2021-03-31T08:05:33Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness and ADS machine identity propagation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/115044#M24124</link>
      <description>&lt;P&gt;You mean when someone logs into the AD server itself?&lt;BR /&gt;Note only AD users are acquired, no local users will be acquired.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 15:35:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/115044#M24124</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-31T15:35:37Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness and ADS machine identity propagation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/115050#M24125</link>
      <description>&lt;P&gt;Hi Phoneboy,&lt;/P&gt;&lt;P&gt;No, it is for the AD server itself. For other non-AD-servers I see log entries like shown below.&lt;/P&gt;&lt;P&gt;Id: 0a6000f1-b607-a64b-6064-724300000001&lt;BR /&gt;Marker: @A@@B@1617193489@C@911804&lt;BR /&gt;Log Server Origin: x.x.x.x&lt;BR /&gt;Time: 2021-03-31T12:59:47Z&lt;BR /&gt;Id Generated By Indexer:false&lt;BR /&gt;First: true&lt;BR /&gt;Sequencenum: 87&lt;BR /&gt;Domain Name: example.com&lt;BR /&gt;Source: y.y.y.y&lt;BR /&gt;Endpoint IP: y.y.y.y&lt;BR /&gt;Authentication Status: Successful Login&lt;BR /&gt;Identity Source: Identity Collector (Active Directory)&lt;BR /&gt;Session ID: 66d6b3c5&lt;BR /&gt;Source Machine Name: servername&lt;BR /&gt;Source Machine Group: All Machines; ad_group_my_servers;&lt;BR /&gt;Authentication Method: Machine Identity Propagation&lt;BR /&gt;Identity Type: machine&lt;BR /&gt;Authentication Trial: this is a reauthentication for session xxxxxx&lt;BR /&gt;Roles: My_Servers&lt;BR /&gt;Action: Update&lt;BR /&gt;Type: Log&lt;BR /&gt;Blade: Identity Awareness&lt;BR /&gt;Origin: FW-A&lt;BR /&gt;Product Family: Network&lt;BR /&gt;Logid: 131073&lt;BR /&gt;Description: Successful Login&amp;nbsp;&lt;/P&gt;&lt;P&gt;Updates like these are not being received for the AD servers themself.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Mar 2021 16:04:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/115050#M24125</guid>
      <dc:creator>Niels_van_Sluis</dc:creator>
      <dc:date>2021-03-31T16:04:49Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness and ADS machine identity propagation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/115073#M24126</link>
      <description>&lt;P&gt;But you're using an actual AD account to log in, correct?&lt;BR /&gt;Maybe&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21902"&gt;@Adi_Babai&lt;/a&gt;&amp;nbsp;or&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;know here.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 00:46:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/115073#M24126</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-01T00:46:48Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness and ADS machine identity propagation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/115096#M24127</link>
      <description>&lt;P&gt;Well as far as I know, it is the AD server itself. I think the 'Machine Identity Propagation' update is send when a system itself is domain joined en authenticates itself to the AD server or domain. Maybe the AD represents the domain itself, and therefore doesn't join the domain like non-ADS servers do. That could be the reason that I don't see updates on the Security Gateway.&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 10:58:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/115096#M24127</guid>
      <dc:creator>Niels_van_Sluis</dc:creator>
      <dc:date>2021-04-01T10:58:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness and ADS machine identity propagation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/115127#M24128</link>
      <description>&lt;P&gt;Your explanation seems reasonable to me, at least.&lt;/P&gt;</description>
      <pubDate>Thu, 01 Apr 2021 20:19:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/115127#M24128</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-04-01T20:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness and ADS machine identity propagation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/118939#M24129</link>
      <description>&lt;P&gt;Hi Niels,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;summary: it appears only the AD Servers , selected as an identity source that appear to be affected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;long:&lt;/P&gt;&lt;P&gt;We have the same behaviour in our environment. (1st time posting on checkpoint.... hooray.)&lt;BR /&gt;&amp;gt; other domain controllers,&amp;nbsp; &amp;nbsp;NOT in the Identity Collector as sources are registering just fine here.&lt;/P&gt;&lt;P&gt;It's only those&amp;nbsp; that are enlisted as "Identity Collector Sources"&amp;nbsp; that are not registering as "machine identity". Exactly what you described.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Was this fixed for you somehow recently? or still an open question? Wondering if we should open a case&amp;nbsp;@ CP for this or not.&lt;BR /&gt;Honestly we don't know if it has always been like this - but considering the Ruleset we stumbled upon a couple issues - and narrowed it down to the fact those specific Domain Controllers are not having their machine identity updated towards our Security Gateway.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 20 May 2021 14:33:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/118939#M24129</guid>
      <dc:creator>alexander_ae</dc:creator>
      <dc:date>2021-05-20T14:33:19Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness and ADS machine identity propagation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/147464#M24130</link>
      <description>&lt;P&gt;I'm wondering if machine identity propagation can be turned off when it's not being used.&amp;nbsp;&amp;nbsp; We're just using network and user authentication to validate access not machine identity.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Also, the domain controllers its trying to get to are not configured in our LDAP account unit by design.&amp;nbsp;&amp;nbsp; We are only using domain controllers in domain A, not B or C to validate users.&amp;nbsp;&amp;nbsp;&amp;nbsp; Those domain controllers exist for off site customers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the case I did want to use those other domain controllers from other domains, I assume I would have to use MDS for management (multiple domains).&amp;nbsp;&amp;nbsp; IOW, if someone LDAP used a domain from domain B, a DC in domain A wouldn't find it even if I had it listed as a DC.&amp;nbsp; You can't control which DC is used for each rule.&amp;nbsp; Maybe, that will change in R81.20?&lt;/P&gt;</description>
      <pubDate>Fri, 29 Apr 2022 13:00:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/147464#M24130</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2022-04-29T13:00:18Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness and ADS machine identity propagation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/196331#M36632</link>
      <description>&lt;P&gt;No, I'm still seeing all these messages.&lt;/P&gt;
&lt;P&gt;Failed to get users groups for the domain.&lt;BR /&gt;Verify that this domain name is configured in your LDAP Account Unit.&lt;BR /&gt;Domain: somegroup.local&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;the answer maybe to add these domains to the IDC, there's a few differentusers who log in.&lt;/P&gt;
&lt;P&gt;After adding the new domain to IDC and adding an account unit for the new domain, I'm still seeing these in R81.20&lt;/P&gt;
&lt;P&gt;Machine Identity propagation Failed Login&amp;nbsp;&amp;nbsp;Failed to get users groups for the domain.&lt;BR /&gt;Verify that this domain name is configured in your LDAP Account Unit.&amp;nbsp; (Yes, it is so ?)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 08 Nov 2023 19:31:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/196331#M36632</guid>
      <dc:creator>Daniel_Kavan</dc:creator>
      <dc:date>2023-11-08T19:31:09Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness and ADS machine identity propagation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/202080#M38018</link>
      <description>&lt;P&gt;Getting the same error here, actually a lot of them... ? Propagation deactivation option would be helpful&lt;/P&gt;&lt;P&gt;Any other leads ?&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 14:51:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/202080#M38018</guid>
      <dc:creator>Phil_Pasquier</dc:creator>
      <dc:date>2024-01-03T14:51:39Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness and ADS machine identity propagation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/241918#M46984</link>
      <description>&lt;P&gt;We also see this in our environment. Is there a solution for this.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 09:53:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/241918#M46984</guid>
      <dc:creator>JacWev</dc:creator>
      <dc:date>2025-02-21T09:53:26Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness and ADS machine identity propagation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/241921#M46985</link>
      <description>&lt;P&gt;Hi. Checked the SR history I had and we fixed it with:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Image_2024-01-11_07-39-38.png" style="width: 897px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29683i06425A611D7B68E0/image-size/large?v=v2&amp;amp;px=999" role="button" title="Image_2024-01-11_07-39-38.png" alt="Image_2024-01-11_07-39-38.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 10:02:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/241921#M46985</guid>
      <dc:creator>Phil_Pasquier</dc:creator>
      <dc:date>2025-02-21T10:02:49Z</dc:date>
    </item>
    <item>
      <title>Re: Identity awareness and ADS machine identity propagation</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/241922#M46986</link>
      <description>&lt;P&gt;Ah Great.... ( and fast answer )&amp;nbsp;&lt;/P&gt;&lt;P&gt;I will look a solution for a terminal server.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Feb 2025 10:11:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-awareness-and-ADS-machine-identity-propagation/m-p/241922#M46986</guid>
      <dc:creator>JacWev</dc:creator>
      <dc:date>2025-02-21T10:11:07Z</dc:date>
    </item>
  </channel>
</rss>

