<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness - Unsuccessful User Directory Queries in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Unsuccessful-User-Directory-Queries/m-p/152194#M25338</link>
    <description>&lt;P&gt;Remember that however users are acquired, the gateways do the lookup (via LDAP) for the groups.&lt;BR /&gt;Not sure this will help.&lt;/P&gt;</description>
    <pubDate>Fri, 01 Jul 2022 15:14:53 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2022-07-01T15:14:53Z</dc:date>
    <item>
      <title>Identity Awareness - Unsuccessful User Directory Queries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Unsuccessful-User-Directory-Queries/m-p/151429#M24727</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As I was stating in other topics, we're close to get the IA into production.&lt;/P&gt;
&lt;P&gt;We've deployed IC in pairs, so we assure redundancy, we collect log-ins from AD and we got also ISE pxGrig integrated too.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What still bothers me, is the HIGH number of "Unsuccessful User Directory Queries" we're seeing in reports (screenshot below).&lt;/P&gt;
&lt;TABLE border="1" width="100%"&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD width="50%" height="25px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/16999iB661D7D3C42A4437/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/TD&gt;
&lt;TD width="50%" height="25px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.JPG" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17000iD8B112C63D4DC861/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Capture.JPG" alt="Capture.JPG" /&gt;&lt;/span&gt;&lt;/TD&gt;
&lt;/TR&gt;
&lt;/TBODY&gt;
&lt;/TABLE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What I can tell, is that our AD Domain (xyz.int) has 4 main sub-domains (ALV, EU, NA and AP) and our IC's are set to grab log-is from the ALV.xyz.int .&amp;nbsp;&lt;/P&gt;
&lt;P&gt;All good here as we properly see log-ins on each region, and we properly identify the users and machines against AD (groups and everything).&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My guess is that the cross regions log-ins are going to the&amp;nbsp;"Unsuccessful User Directory Queries" figures, because &lt;A href="mailto:user1@eu.xyz.it" target="_blank"&gt;user1@eu.xyz.int&lt;/A&gt;&amp;nbsp;is properly found in the EU Cluster, but the &lt;A href="mailto:user2@na.xyz.int" target="_blank"&gt;user2@na.xyz.int&lt;/A&gt;&amp;nbsp;or&amp;nbsp;&lt;A href="mailto:user2@na.xyz.int" target="_blank"&gt;user3@ap.xyz.int&lt;/A&gt;&amp;nbsp;are not. (actually they all show up like &lt;A href="mailto:user1@xyz.com" target="_blank"&gt;user1@xyz.com&lt;/A&gt;&amp;nbsp;or &lt;A href="mailto:user1@xyz.com" target="_blank"&gt;user2@xyz.com&lt;/A&gt;&amp;nbsp;or&amp;nbsp;&lt;A href="mailto:user1@xyz.com" target="_blank"&gt;user3@xyz.com&lt;/A&gt;&amp;nbsp;) still in the settings we have LDAP/User Catalog defined for all 4 sub-domains.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;As a next step, since we just read about it. we're going to address on our LDAP/User Catalog settings the AD Global Catalog (see&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk134292" target="_self"&gt;sk134292&lt;/A&gt; ) .&lt;BR /&gt;&lt;BR /&gt;Does anyone else faced similar problem, or my understanding for "Unsuccessful User Directory Queries" is caused by smth else?&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;Any ideas or hints are welcomed.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 22 Jun 2022 08:47:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Unsuccessful-User-Directory-Queries/m-p/151429#M24727</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-06-22T08:47:04Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Unsuccessful User Directory Queries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Unsuccessful-User-Directory-Queries/m-p/152056#M25139</link>
      <description>&lt;P&gt;TAC would have to take some debugs to find the root cause for your specific case.&lt;BR /&gt;In one of the SRs I reviewed, the issue was that ISE was sending usernames to the gateway that aren't in Active Directory.&lt;BR /&gt;That would cause the LDAP query to fail, thus that counter to increase.&lt;/P&gt;</description>
      <pubDate>Wed, 29 Jun 2022 19:57:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Unsuccessful-User-Directory-Queries/m-p/152056#M25139</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-06-29T19:57:06Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Unsuccessful User Directory Queries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Unsuccessful-User-Directory-Queries/m-p/152110#M25187</link>
      <description>&lt;P&gt;hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I will also open a TAC to look into this, as most likely it's like you said, usernames are sent by ISE.&lt;/P&gt;
&lt;P&gt;We were thinking to use GlobalCatalog for getting User/Machine groups, could this GC address this user search in AD.&amp;nbsp;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ty,&lt;/P&gt;</description>
      <pubDate>Thu, 30 Jun 2022 10:29:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Unsuccessful-User-Directory-Queries/m-p/152110#M25187</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2022-06-30T10:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Unsuccessful User Directory Queries</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Unsuccessful-User-Directory-Queries/m-p/152194#M25338</link>
      <description>&lt;P&gt;Remember that however users are acquired, the gateways do the lookup (via LDAP) for the groups.&lt;BR /&gt;Not sure this will help.&lt;/P&gt;</description>
      <pubDate>Fri, 01 Jul 2022 15:14:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Unsuccessful-User-Directory-Queries/m-p/152194#M25338</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-07-01T15:14:53Z</dc:date>
    </item>
  </channel>
</rss>

