<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: problem with the operation of the user identification function in Checkpoint by domain accounts in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-the-operation-of-the-user-identification-function/m-p/162918#M29009</link>
    <description>&lt;P&gt;3: Under LDAP account unit: check if the domain is correct. Try to fetch the branches from all DC's. If LDAPS is used, try to fetch fingerprint and see if they changed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also what is the output of:&amp;nbsp;&lt;SPAN&gt;pdp idc groups_update status on the gateways?&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 23 Nov 2022 11:53:16 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2022-11-23T11:53:16Z</dc:date>
    <item>
      <title>problem with the operation of the user identification function in Checkpoint by domain accounts</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-the-operation-of-the-user-identification-function/m-p/162897#M28998</link>
      <description>&lt;P&gt;We have rules for providing basic Internet access:&lt;BR /&gt;1. Through a group in the active directory (access role)&lt;BR /&gt;2. Through a group with ip addresses (network group)&lt;BR /&gt;In the access role, under the tab users there is a group AD &amp;lt;group&amp;gt; with more than 2000 users but normally only 300 users come through.&lt;BR /&gt;When checking the problem user in PDP, the output of the command shows that:&lt;BR /&gt;1. "Groups: All Users" (This user is a member of an AD group)&lt;BR /&gt;2. "Roles: -" (Access Role not defined)&lt;/P&gt;&lt;P&gt;Therefore the given user does not fall under our rule. At the same time the given user is a member of the AD group.&lt;BR /&gt;Conclusion: The traffic doesn't reach the target rule (with active directory), but it goes through other rules (not with active directory), because CheckPoint cannot correctly identify the AD group the user is in.&lt;BR /&gt;We tried sk106964.&lt;BR /&gt;We tried rules with access role raised above allowing rules by ip&lt;BR /&gt;These solutions did not solve our problems.&lt;BR /&gt;Also, we have rules where some users are given internet by active directory, the rules work but after some time internet access is lost, traffic stops going by the rule.&lt;BR /&gt;We have main domain and subdomains, users from subdomains are also present in the main domain&lt;BR /&gt;Please advise, have you faced such problems and were you able to solve them?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 09:54:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-the-operation-of-the-user-identification-function/m-p/162897#M28998</guid>
      <dc:creator>Arturxr</dc:creator>
      <dc:date>2022-11-23T09:54:12Z</dc:date>
    </item>
    <item>
      <title>Re: problem with the operation of the user identification function in Checkpoint by domain accounts</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-the-operation-of-the-user-identification-function/m-p/162899#M29000</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Do you use ADquery as source or IDC collectors? Also the rule with a&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;access role, does the rule not work at all or only for a limited amount of users? Did the rule ever worked before? How are the settings for the LDAP account unit? Everything looks correct over there? Are you able to fetch branches?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;If you use ADquery I would recommend to use IDC collectors. This is the way to go now.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 10:03:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-the-operation-of-the-user-identification-function/m-p/162899#M29000</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2022-11-23T10:03:15Z</dc:date>
    </item>
    <item>
      <title>Re: problem with the operation of the user identification function in Checkpoint by domain accounts</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-the-operation-of-the-user-identification-function/m-p/162911#M29003</link>
      <description>&lt;P&gt;&lt;BR /&gt;1. We use IDC as source&lt;BR /&gt;2. Some rules work for a limited number of users, some do not work at all, did not work correctly before&lt;BR /&gt;3. Tell me, what settings should we check?&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 10:46:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-the-operation-of-the-user-identification-function/m-p/162911#M29003</guid>
      <dc:creator>Arturxr</dc:creator>
      <dc:date>2022-11-23T10:46:16Z</dc:date>
    </item>
    <item>
      <title>Re: problem with the operation of the user identification function in Checkpoint by domain accounts</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-the-operation-of-the-user-identification-function/m-p/162915#M29007</link>
      <description>&lt;P&gt;Please open a TAC request&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 11:37:04 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-the-operation-of-the-user-identification-function/m-p/162915#M29007</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-11-23T11:37:04Z</dc:date>
    </item>
    <item>
      <title>Re: problem with the operation of the user identification function in Checkpoint by domain accounts</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-the-operation-of-the-user-identification-function/m-p/162918#M29009</link>
      <description>&lt;P&gt;3: Under LDAP account unit: check if the domain is correct. Try to fetch the branches from all DC's. If LDAPS is used, try to fetch fingerprint and see if they changed.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also what is the output of:&amp;nbsp;&lt;SPAN&gt;pdp idc groups_update status on the gateways?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 11:53:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-the-operation-of-the-user-identification-function/m-p/162918#M29009</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2022-11-23T11:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: problem with the operation of the user identification function in Checkpoint by domain accounts</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-the-operation-of-the-user-identification-function/m-p/162930#M29011</link>
      <description>&lt;P&gt;Checked that the domain is correct - everything is set up correctly&lt;BR /&gt;Tried to get branches from all dc&lt;BR /&gt;pdp idc groups_update status was disabled, turned it on, then checked with a command:&lt;BR /&gt;pep show user query usr &amp;lt;user&amp;gt;&lt;BR /&gt;The problem was not solved.&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 12:56:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-the-operation-of-the-user-identification-function/m-p/162930#M29011</guid>
      <dc:creator>Arturxr</dc:creator>
      <dc:date>2022-11-23T12:56:19Z</dc:date>
    </item>
    <item>
      <title>Re: problem with the operation of the user identification function in Checkpoint by domain accounts</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-the-operation-of-the-user-identification-function/m-p/162932#M29012</link>
      <description>&lt;P&gt;We have opened a case in the TAC, but we still have not been offered any solution for a long time&lt;/P&gt;</description>
      <pubDate>Wed, 23 Nov 2022 12:57:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/problem-with-the-operation-of-the-user-identification-function/m-p/162932#M29012</guid>
      <dc:creator>Arturxr</dc:creator>
      <dc:date>2022-11-23T12:57:07Z</dc:date>
    </item>
  </channel>
</rss>

