<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Collector and CrowdStrike in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/181667#M33253</link>
    <description>&lt;P&gt;Thanks for sharing that&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21488"&gt;@SteveW&lt;/a&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Mon, 22 May 2023 17:25:37 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-05-22T17:25:37Z</dc:date>
    <item>
      <title>Identity Collector and CrowdStrike</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/178068#M32633</link>
      <description>&lt;P&gt;Hi CheckMates&lt;/P&gt;&lt;P&gt;Is anyone having issue with Identity Collectors when CrowdStrike is running on the domain controllers?&lt;/P&gt;&lt;P&gt;I'm running Identity Collectors on two dedicated servers (so not directly on the domain controllers) but since CrowdStrike has been installed on the domain controllers the id collectors stop receiving events from the DCs at least once per day. The Status Description for each DC remains 'connected' but the events stop incrementing. Restarting the Id Collector service on the Collectors kick-starts the process and they start receiving AD events again.&lt;/P&gt;&lt;P&gt;CrowdStrike technical support have reported that this is a known issue because it interrupts the Identity Collector's connection to AD and no RST packet is sent by the domain controller to reset the tcp session.&lt;/P&gt;&lt;P&gt;One suggested workaround is to configure Task Scheduler on the Collectors to periodically restart the service (say, every 6 hours) but this is not ideal.&lt;/P&gt;&lt;P&gt;Is Check Point R&amp;amp;D aware of the problem (hi, Royi Priov) and is there a better solution to keep the Id Collectors running?&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 08:23:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/178068#M32633</guid>
      <dc:creator>SteveW</dc:creator>
      <dc:date>2023-04-14T08:23:28Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and CrowdStrike</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/178090#M32639</link>
      <description>&lt;P&gt;I had someone tell me they had CP case open for this, but no resolution was given. I can ask them what happened with it and report back.&lt;/P&gt;</description>
      <pubDate>Sat, 15 Apr 2023 02:03:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/178090#M32639</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-04-15T02:03:39Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and CrowdStrike</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/178097#M32640</link>
      <description>&lt;P&gt;Was any context provided for why the communication is interrupted?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 14 Apr 2023 13:57:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/178097#M32640</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-04-14T13:57:13Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and CrowdStrike</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/178213#M32667</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Thanks for tagging me.&lt;/P&gt;
&lt;P&gt;Yes, there is a known issue, where crowdstrike is closing IDC connection to DC.&lt;/P&gt;
&lt;P&gt;It was addressed in bug ID IDA-5232 from our side.&lt;/P&gt;
&lt;P&gt;It will be added to the next GA of IDC, but as for now please use the fix from IDA-5232.&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2023 06:59:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/178213#M32667</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2023-04-17T06:59:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and CrowdStrike</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/178226#M32671</link>
      <description>&lt;P&gt;Hi Royi,&lt;/P&gt;&lt;P&gt;Thanks for the update, I will try the bug fix.&lt;/P&gt;&lt;P&gt;Kind regards&lt;/P&gt;&lt;P&gt;Steve&lt;/P&gt;</description>
      <pubDate>Mon, 17 Apr 2023 10:20:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/178226#M32671</guid>
      <dc:creator>SteveW</dc:creator>
      <dc:date>2023-04-17T10:20:44Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and CrowdStrike</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/181515#M33224</link>
      <description>&lt;P&gt;Did that fix your issue? I was going to say we aren't having any problems with it, but CrowdStrike was not installed on the server I have Identity Collector running on. It is installed on the DC however. I also have one other server where both are installed and running fine.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Has this been fixed in Identity Collector version&amp;nbsp;R81.040? Where do I get&amp;nbsp;&lt;SPAN&gt;IDA-5232?&lt;BR /&gt;I can't seem to find that, if I end up running into issues after installing CS on another server.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2023 22:07:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/181515#M33224</guid>
      <dc:creator>r1der</dc:creator>
      <dc:date>2023-05-19T22:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and CrowdStrike</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/181520#M33225</link>
      <description>&lt;P&gt;Next release of IDC is not yet available, contact TAC in the interim.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 20 May 2023 02:51:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/181520#M33225</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-05-20T02:51:33Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and CrowdStrike</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/181660#M33251</link>
      <description>&lt;P&gt;Hi r1der,&lt;/P&gt;&lt;P&gt;My Identity Collectors run on two servers that are separate from my DCs. It's possible that you are not seeing the problem because your Identity Collectors are running on your DCs.&lt;BR /&gt;The workaround I used was to set up a task in Windows Task Scheduler on the Identity Collectors that restarts the CP Id Collector service every 6 hours regardless of whether or not it has failed. And the restart schedule is offset by 6 hours between the two Collectors so they do not both restart the service at the same time.&lt;/P&gt;&lt;P&gt;This workaround has been successful so far so I'll keep using it until the fix is rolled into the GA updates.&lt;/P&gt;&lt;P&gt;You might be able to use something similar if you have multiple ID Collectors for resilience.&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 15:22:58 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/181660#M33251</guid>
      <dc:creator>SteveW</dc:creator>
      <dc:date>2023-05-22T15:22:58Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and CrowdStrike</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/181667#M33253</link>
      <description>&lt;P&gt;Thanks for sharing that&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/21488"&gt;@SteveW&lt;/a&gt;&amp;nbsp;&lt;span class="lia-unicode-emoji" title=":thumbs_up:"&gt;👍&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2023 17:25:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/181667#M33253</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-22T17:25:37Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and CrowdStrike</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/182807#M33529</link>
      <description>&lt;P&gt;Thanks for the update! Good to know the service and that you can just restart it to get it running again.&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 20:55:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/182807#M33529</guid>
      <dc:creator>r1der</dc:creator>
      <dc:date>2023-05-31T20:55:35Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector and CrowdStrike</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/184301#M33866</link>
      <description>&lt;P&gt;Hi Royi,&lt;/P&gt;
&lt;P&gt;Was it ever determined what on Crowdstrike was closing the connection?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Maurice&lt;/P&gt;</description>
      <pubDate>Mon, 19 Jun 2023 18:12:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector-and-CrowdStrike/m-p/184301#M33866</guid>
      <dc:creator>Maurice_Conway</dc:creator>
      <dc:date>2023-06-19T18:12:02Z</dc:date>
    </item>
  </channel>
</rss>

