<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness - Identity Collector - Make sure the account exists in the AD in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-Make-sure-the-account/m-p/178416#M32684</link>
    <description>&lt;P&gt;Do you see the gateway try to do LDAP lookups at all (i.e. connections to the LDAP server)?&lt;BR /&gt;What does&amp;nbsp;&lt;SPAN&gt;pdp debug on say? (Review&amp;nbsp;$FWDIR/log/pdpd.elg)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 18 Apr 2023 22:12:19 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2023-04-18T22:12:19Z</dc:date>
    <item>
      <title>Identity Awareness - Identity Collector - Make sure the account exists in the AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-Make-sure-the-account/m-p/178142#M32683</link>
      <description>&lt;P&gt;Hi guys,&lt;/P&gt;
&lt;P&gt;I want to test in my home LAB the IDC solution. I didnt work with IA in the past, so asking for a help here &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;My goal is to allow connection based on Access Roles for specific users in order to allow them to reach the needed internal resources.&lt;/P&gt;
&lt;P&gt;I have R81.10 gateway and MDS with Take 87. Windows Server 2019 is acting like DC and AD. IDC agent is installed on Windows Server. The connection between DC/AD and GW is working, all is green. I have created in AD some test users which are used to log-in to the Windows 7 machine over test domain. So far, all as expected. But once I want to check on Check Point GW if user was recognized as successfully logged to the Windows 7 machine, the firewall logs says that: "&lt;STRONG&gt;Group membership of the required account (user or machine) could not be retrieved from the AD. Make sure the account exists in the AD.&lt;/STRONG&gt;"&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20518iF0A195DC4083E542/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Logs for IA blade:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20516i18AEC4F998535B60/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The same errors are seen for each and every user, doesnt matter if user was already created or created couple of minutes ago.&lt;BR /&gt;Looks like some configuration issue on FW which I didnt recognize yet.&lt;/P&gt;
&lt;P&gt;There is only 1 Account Unit configured, with following settings:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 504px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20512i475DA9C7189A173B/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 504px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20513i3C68D998405C4B5E/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 504px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20514i449990DC0AE934CF/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 504px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20515i8A9DAB3490EADCAA/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;I checked&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106133" target="_blank" rel="noopener"&gt;sk106133&lt;/A&gt;, but looks like I didnt find a match there...&lt;/P&gt;
&lt;P&gt;Since this is my home LAB, I can do any debugs in order to figure out what is going on.&lt;/P&gt;
&lt;P&gt;Anyone who is experienced with IA and IDC specifically, and is able to help me to fix the issue ?&lt;/P&gt;
&lt;P&gt;Thanks for the help !&lt;/P&gt;</description>
      <pubDate>Sat, 15 Apr 2023 12:54:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-Make-sure-the-account/m-p/178142#M32683</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2023-04-15T12:54:42Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Identity Collector - Make sure the account exists in the AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-Make-sure-the-account/m-p/178416#M32684</link>
      <description>&lt;P&gt;Do you see the gateway try to do LDAP lookups at all (i.e. connections to the LDAP server)?&lt;BR /&gt;What does&amp;nbsp;&lt;SPAN&gt;pdp debug on say? (Review&amp;nbsp;$FWDIR/log/pdpd.elg)&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 18 Apr 2023 22:12:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-Make-sure-the-account/m-p/178416#M32684</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-18T22:12:19Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Identity Collector - Make sure the account exists in the AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-Make-sure-the-account/m-p/178625#M32714</link>
      <description>&lt;P&gt;connection to LDAP (which is in fact DC) is established over port 389:&lt;/P&gt;
&lt;DIV id="tinyMceEditor_1386360272e4e12JozkoMrkvicka_0" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV id="tinyMceEditor_1386360272e4e12JozkoMrkvicka_1" class="mceNonEditable lia-copypaste-placeholder"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="image.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20578i3A5B1CE52EF521B0/image-size/large?v=v2&amp;amp;px=999" role="button" title="image.png" alt="image.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Did also tcpdump and connection over 389 is OK.&lt;/P&gt;
&lt;P&gt;pdp debugs are attached.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 13:51:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-Make-sure-the-account/m-p/178625#M32714</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2023-04-20T13:51:42Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Identity Collector - Make sure the account exists in the AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-Make-sure-the-account/m-p/178660#M32722</link>
      <description>&lt;P&gt;Unfortunately, that doesn't have anything useful.&lt;BR /&gt;Maybe try the test_ad_connectivity tool:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk100406" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk100406&lt;/A&gt;&lt;BR /&gt;Make sure to use that -l (that's a lowercase L) to only perform the LDAP tests as WMI isn't relevant in this case.&lt;/P&gt;</description>
      <pubDate>Thu, 20 Apr 2023 22:04:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-Make-sure-the-account/m-p/178660#M32722</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-04-20T22:04:35Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Identity Collector - Make sure the account exists in the AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-Make-sure-the-account/m-p/178678#M32723</link>
      <description>&lt;P&gt;Hey&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1702"&gt;@JozkoMrkvicka&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In the 2nd LDAP screenshot, at LDAP Servers, you should have an user defined, and an Login DN as below example. That AD user that I'm using to read, it's a simple user, no specific rights.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot .png" style="width: 506px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/20583i161ED45532E733E9/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot .png" alt="Screenshot .png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Have a look on&amp;nbsp;sk31841 as it might clarify it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We have no issues with AD users, as the log-in events are learned and CheckPoint GW reads the user/machine groups properly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thank you,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 04:03:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-Make-sure-the-account/m-p/178678#M32723</guid>
      <dc:creator>Sorin_Gogean</dc:creator>
      <dc:date>2023-04-21T04:03:00Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Identity Collector - Make sure the account exists in the AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-Make-sure-the-account/m-p/178693#M32726</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/16983"&gt;@Sorin_Gogean&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;You were right. I left the Login DN blank which is the cause of the issues in my case.&lt;/P&gt;
&lt;P&gt;I am using default Administrator user in LAB and forgot to fill "Login DN".&lt;/P&gt;
&lt;P&gt;Once "Login DN" was filled and policy pushed, all users are correctly recognized by FW and associated Access Roles are assigned.&lt;/P&gt;
&lt;P&gt;Thank you for help !&lt;/P&gt;</description>
      <pubDate>Fri, 21 Apr 2023 09:03:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Identity-Collector-Make-sure-the-account/m-p/178693#M32726</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2023-04-21T09:03:30Z</dc:date>
    </item>
  </channel>
</rss>

