<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Collector - Identity Sources configuration in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/157922#M27474</link>
    <description>&lt;P&gt;This is what customer told me as the answer to my question if he remembered if we did automatic or manual...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"I can’t recall but I think it found all of them.&amp;nbsp; I know it pulled the wrong info (site name) and I had to manually enter that."&lt;/P&gt;</description>
    <pubDate>Fri, 23 Sep 2022 15:28:00 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2022-09-23T15:28:00Z</dc:date>
    <item>
      <title>Identity Collector - Identity Sources configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/157916#M27468</link>
      <description>&lt;P&gt;So i'm preparing to move from AD query to Identity Collector.&lt;/P&gt;&lt;P&gt;Installed the software on 2 domain controllers for redundancy.&lt;/P&gt;&lt;P&gt;All working fine for the domain controller on which the software is installed, but the other one is not.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Identity Sources.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/17870iD0EBFF85011C2F0E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Identity Sources.jpg" alt="Identity Sources.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; "Unable to connect, please check connectivity ....."&lt;/P&gt;&lt;P&gt;Actually, i added our 4 DC as identity sources but only planning to install IC on 2 of them since this is enough for redundancy purpose.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Are you supposed to only add the DC where Identity Collector has been installed on, as identity source?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 14:40:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/157916#M27468</guid>
      <dc:creator>Dave</dc:creator>
      <dc:date>2022-09-23T14:40:54Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - Identity Sources configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/157917#M27469</link>
      <description>&lt;P&gt;You should be able to add all of them actually. Did you check connectivity with other 3?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 14:51:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/157917#M27469</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-23T14:51:40Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - Identity Sources configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/157918#M27470</link>
      <description>&lt;P&gt;They are all in the same subnet so i would assume this would have been a no brainer. Seems not &lt;span class="lia-unicode-emoji" title=":smiling_face_with_smiling_eyes:"&gt;😊&lt;/span&gt;&lt;/P&gt;&lt;P&gt;So on one DC, let's say DC4 in my case, i should be able to see events from all 4 DC, that's what you are saying?&lt;/P&gt;&lt;P&gt;Then i'm asking myself what is blocking this.....&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 15:03:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/157918#M27470</guid>
      <dc:creator>Dave</dc:creator>
      <dc:date>2022-09-23T15:03:07Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - Identity Sources configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/157919#M27471</link>
      <description>&lt;P&gt;Agree, specially if its same subnet : - ). How did you add them? Manually or option "fetch automatically"?&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 15:07:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/157919#M27471</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-23T15:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - Identity Sources configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/157920#M27472</link>
      <description>&lt;P&gt;"fetch automatically" is how i added them&lt;/P&gt;&lt;P&gt;If i double click on the identity source where IC is installed, it passes the test and connection is fine.&lt;/P&gt;&lt;P&gt;If i double click on any other identity source where IC is not installed on, it fails the test with the message "unable to connect, please check"&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 15:17:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/157920#M27472</guid>
      <dc:creator>Dave</dc:creator>
      <dc:date>2022-09-23T15:17:33Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - Identity Sources configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/157921#M27473</link>
      <description>&lt;P&gt;Let me confirm with client we did this for, as they also have 4 DCs I believe and all shows fine, but IC is only installed on one of them.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 15:20:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/157921#M27473</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-23T15:20:00Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - Identity Sources configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/157922#M27474</link>
      <description>&lt;P&gt;This is what customer told me as the answer to my question if he remembered if we did automatic or manual...&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;"I can’t recall but I think it found all of them.&amp;nbsp; I know it pulled the wrong info (site name) and I had to manually enter that."&lt;/P&gt;</description>
      <pubDate>Fri, 23 Sep 2022 15:28:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/157922#M27474</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-23T15:28:00Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - Identity Sources configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/158122#M27540</link>
      <description>&lt;P&gt;Got it figured out &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The issue was Windows Firewall blocking dynamic ports communication between DCs, once we opened that up, everything became green and connected.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Advice to Checkpoint: please add this in the documentation of Identity Collector as a note (Windows Firewall rule which needs to allow incoming DCOM ports communication between DCs) so people don't have to loose too much time troubleshooting this.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 07:50:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/158122#M27540</guid>
      <dc:creator>Dave</dc:creator>
      <dc:date>2022-09-27T07:50:06Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - Identity Sources configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/158129#M27543</link>
      <description>&lt;P&gt;Thanks for sharing the solution,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/30940"&gt;@Dave&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 08:38:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/158129#M27543</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-09-27T08:38:50Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - Identity Sources configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/158157#M27550</link>
      <description>&lt;P&gt;Good old Windows : - ). Thanks a lot for letting us know, it will help others, for sure!!&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2022 12:30:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/158157#M27550</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-09-27T12:30:52Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - Identity Sources configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/158342#M27597</link>
      <description>&lt;P&gt;Unfortunately, the story doesn't end here because another issue popped up.&lt;/P&gt;&lt;P&gt;So i had foreseen to run identity collector as a service under another service account, freshly created and with the domain user permissions, user is part of group 'Event Log Readers' group.&lt;/P&gt;&lt;P&gt;As soon as i run cpidc.exe as a service and under this new service account, everything stops working, all identity sources are yellow and no identities are collected anymore.&lt;/P&gt;&lt;P&gt;When i remove the service account and let the service run under my domain admin account, everthing changes instantly to green again and identities are collected.&lt;/P&gt;&lt;P&gt;This for sure has to do with user rights in Windows, but it seems like having a domain user with group membership of 'Event Log Readers' group is not enough?&lt;/P&gt;&lt;P&gt;Please help me understand what i'm missing &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 28 Sep 2022 15:14:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/158342#M27597</guid>
      <dc:creator>Dave</dc:creator>
      <dc:date>2022-09-28T15:14:24Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - Identity Sources configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/158386#M27605</link>
      <description>&lt;P&gt;Most probably the permissions mismatch. If you looked through&amp;nbsp;&lt;SPAN&gt;sk108235 and&amp;nbsp;sk179544 and did not find the trigger for the issue, I would advise engaging with TAC to drill down.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 29 Sep 2022 06:48:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/158386#M27605</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-09-29T06:48:03Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - Identity Sources configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/158407#M27611</link>
      <description>&lt;P&gt;Yes permission issue most probably, only hard to find what's missing...&lt;/P&gt;&lt;P&gt;This simple domain user account, should it also need to be part of the 'Distributed DCOM users' group?&lt;/P&gt;&lt;P&gt;Or the 'Event Log Readers' group should be enough?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;H2&gt;&amp;nbsp;&lt;/H2&gt;</description>
      <pubDate>Thu, 29 Sep 2022 07:51:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/158407#M27611</guid>
      <dc:creator>Dave</dc:creator>
      <dc:date>2022-09-29T07:51:16Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector - Identity Sources configuration</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/242562#M47110</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;there are like 7 DCOM-In inbound rules with local port 135.&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29743iCA26633EC231229F/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;which of them needs to be allowed?&lt;/P&gt;&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Thu, 27 Feb 2025 14:38:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-Identity-Sources-configuration/m-p/242562#M47110</guid>
      <dc:creator>freeman91</dc:creator>
      <dc:date>2025-02-27T14:38:26Z</dc:date>
    </item>
  </channel>
</rss>

