<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Collector in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190179#M35089</link>
    <description>&lt;P&gt;I think quick remote session with TAC would probably solve your issue, I feel like its something basic thats missing.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 22 Aug 2023 16:34:48 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-08-22T16:34:48Z</dc:date>
    <item>
      <title>Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/189979#M35036</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;We tried to set up an Identity Collector host to replace the original AD Query function of the firewall.&lt;/P&gt;&lt;P&gt;After the erection is complete. We found it in the log column of "Source user name". No user account information appears. In the IA-related Log, we saw the following error message:&lt;BR /&gt;"Failed to get user groups for the domain.&lt;BR /&gt;Verify that this domain name is configured in your LDAP Account Unit."&lt;/P&gt;&lt;P&gt;We have closed the local firewall of the AD and Identity Collector hosts, but still cannot collect user information.&lt;/P&gt;&lt;P&gt;Our AD version is Windows Server 2019. Can someone who has encountered the same problem give guidance.&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 12:31:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/189979#M35036</guid>
      <dc:creator>GigaYang</dc:creator>
      <dc:date>2023-08-21T12:31:47Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/189985#M35040</link>
      <description>&lt;P&gt;When you open IC software, does gateway show as connected status? Also, did you make sure AD query is fully off?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 13:19:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/189985#M35040</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-21T13:19:28Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190000#M35047</link>
      <description>&lt;P&gt;Identity Collector changes how the gateways acquire users (using Security Logs instead of WMI).&lt;BR /&gt;The actual groups are still pulled the same way as with ADQuery: via LDAP queries from the relevant gateways.&lt;BR /&gt;Which means you should verify the information needed to perform these lookups is correct:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk180392" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk180392&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 15:09:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190000#M35047</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-08-21T15:09:49Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190006#M35049</link>
      <description>&lt;P&gt;After I add a LDAP account unit object. The problem has been solved.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 16:05:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190006#M35049</guid>
      <dc:creator>GigaYang</dc:creator>
      <dc:date>2023-08-21T16:05:43Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190007#M35050</link>
      <description>&lt;P&gt;Good job!&lt;/P&gt;</description>
      <pubDate>Mon, 21 Aug 2023 16:10:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190007#M35050</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-21T16:10:15Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190163#M35079</link>
      <description>&lt;P&gt;We made some architectural adjustments today. The Identity Collector host is placed on a different network segment from the Gateway management interface. As a result, the Identity Collector cannot establish a connection with the Gateway, but the Allow Log is displayed. Has anyone encountered such a situation?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 14:46:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190163#M35079</guid>
      <dc:creator>GigaYang</dc:creator>
      <dc:date>2023-08-22T14:46:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190164#M35080</link>
      <description>&lt;P&gt;Do you have proper rules configured? Does ping work back and forth?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 14:52:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190164#M35080</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-22T14:52:23Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190165#M35081</link>
      <description>&lt;P&gt;Yes,&lt;/P&gt;&lt;P&gt;We have set the firewall rule from IC to gateway over TCP 443. And ping is work well.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 15:07:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190165#M35081</guid>
      <dc:creator>GigaYang</dc:creator>
      <dc:date>2023-08-22T15:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190167#M35082</link>
      <description>&lt;P&gt;Does gateway show as green in IC software? Also, can you pull identity source on the software itself? I will send screenshots later of what Im referring to.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 15:08:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190167#M35082</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-22T15:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190171#M35083</link>
      <description>&lt;P&gt;K, as promised, I attached document of what I was referring to.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 15:44:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190171#M35083</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-22T15:44:34Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190173#M35084</link>
      <description>&lt;P&gt;Hi Rock,&lt;/P&gt;&lt;P&gt;When IC Server and Gateway are in the same subnet. IC can function normally. But when we re-set up the IC in another subnet, the two cannot be connected. But I'm sure the IC can connect to the Gateway via TCP 443.&lt;/P&gt;&lt;P&gt;When unable to connect, the Gateway status on the IC is red. I'll provide footage later.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 15:58:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190173#M35084</guid>
      <dc:creator>GigaYang</dc:creator>
      <dc:date>2023-08-22T15:58:00Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190175#M35085</link>
      <description>&lt;P&gt;That sort of makes sense, since as we all know, when hosts are on the same subnet, all that needs to happen is they know about one another's ARP, no routing needed, so its logical it works.&lt;/P&gt;
&lt;P&gt;If it fails on different subnets, confirm the routing, as well as access policy. Do basic zdebug, as well as fw up_execute as well&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-up_execute.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_CLI_ReferenceGuide/Topics-CLIG/FWG/fw-up_execute.htm&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 16:07:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190175#M35085</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-22T16:07:46Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190176#M35086</link>
      <description>&lt;P&gt;Hi Rock, attach file is my setting.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 16:10:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190176#M35086</guid>
      <dc:creator>GigaYang</dc:creator>
      <dc:date>2023-08-22T16:10:28Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190177#M35087</link>
      <description>&lt;P&gt;Right, so we need to find out WHY it fails, so only way to know is by running basic captures, simple debugs and see where its "stuck"&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 16:13:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190177#M35087</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-22T16:13:19Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190178#M35088</link>
      <description>&lt;P&gt;Attach file is fw monitor and zdebug result.&amp;nbsp;I think the connection between the Gateway and the IC host is normal.&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 16:33:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190178#M35088</guid>
      <dc:creator>GigaYang</dc:creator>
      <dc:date>2023-08-22T16:33:07Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190179#M35089</link>
      <description>&lt;P&gt;I think quick remote session with TAC would probably solve your issue, I feel like its something basic thats missing.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 22 Aug 2023 16:34:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/190179#M35089</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-08-22T16:34:48Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/192148#M35485</link>
      <description>&lt;P&gt;Finally we found two problems:&lt;BR /&gt;1. PDP Problem: After we disable the AD Query function, the Monitor's device status will never change.&lt;BR /&gt;2. The VPN certificate has expired.&lt;/P&gt;&lt;P&gt;After weReboot the device and re-sign the certificate. The problem is solved.&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 04:32:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/192148#M35485</guid>
      <dc:creator>GigaYang</dc:creator>
      <dc:date>2023-09-11T04:32:29Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/192192#M35501</link>
      <description>&lt;P&gt;Good job!&lt;/P&gt;</description>
      <pubDate>Mon, 11 Sep 2023 11:58:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Collector/m-p/192192#M35501</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-11T11:58:03Z</dc:date>
    </item>
  </channel>
</rss>

