<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PDP proccess don t take username using Identity Collector in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-proccess-don-t-take-username-using-Identity-Collector/m-p/193848#M36033</link>
    <description>&lt;P&gt;I meant from ISE. What's the Username collected from ISE?&amp;nbsp;&lt;SPAN&gt;sAMAccountName or&amp;nbsp;UserPrincipalName?&lt;BR /&gt;PDP needs something to make ldap query for group membership resolution.&lt;BR /&gt;Error message from Smartlog in your post may point to the issue that the wrong one is used.&lt;BR /&gt;In case the Attr received leads to errors when trying to resolve group memberships, sometimes UserLoginAttr is to be modified in the Checkpoint Database using guidbedit.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="identity-collector-ldap.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22613iF198DBDC323C072E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="identity-collector-ldap.png" alt="identity-collector-ldap.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;In case pdp process queries using wrong attr, user cannot be found, leading to same error message as above.&lt;BR /&gt;&lt;BR /&gt;To clarify, you might want to debug.&lt;/P&gt;&lt;P&gt;Then first enable debug on the PDP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="cpp"&gt;fw debug fwd off PDP_LOG_SIZE=50000000
fw debug fwd off PDP_NUM_LOGS=20
fw kill pdpd
pdp debug off
pdp debug reset
pdp debug set all all&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;replicate issue&lt;/P&gt;&lt;P&gt;disable debug&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="cpp"&gt;fw debug fwd off PDP_LOG_SIZE=10000000
fw debug fwd off PDP_NUM_LOGS=10
pdp debug off
pdp debug reset
fw kill pdpd&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and then you are able to analyse the collected files in $FWDIR/logs/pdpd.elg*&lt;BR /&gt;In case my idea is correct, you could see hints pointing to that.&lt;BR /&gt;Or maybe pointing to a different root cause.&lt;/P&gt;</description>
    <pubDate>Fri, 29 Sep 2023 06:02:38 GMT</pubDate>
    <dc:creator>Vincent_Bacher</dc:creator>
    <dc:date>2023-09-29T06:02:38Z</dc:date>
    <item>
      <title>PDP proccess don t take username using Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-proccess-don-t-take-username-using-Identity-Collector/m-p/193738#M35998</link>
      <description>&lt;P&gt;Good day!&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have:&lt;/P&gt;&lt;P&gt;1. SG 81.20&lt;/P&gt;&lt;P&gt;2. IC 81.040&lt;/P&gt;&lt;P&gt;3. Cisco ISE 3.0&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;GW taking logs from Identity Collector -&amp;gt; Identity collector taking logs from Cisco ISE -&amp;gt; Cisco ISE taking Identites and logs from Active Directory&amp;nbsp;&lt;/P&gt;&lt;P&gt;In SMS (Smarconsole):&lt;/P&gt;&lt;P&gt;1) We have LDAP account unit object of LDAP&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2) We have only Identity Collector identity source&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In IC:&lt;/P&gt;&lt;P&gt;1) We have only ISE group in the Query pool. ISE machine is green. Log collected with Username.&amp;nbsp;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22593iFF7927D5708BA8E6/image-size/medium?v=v2&amp;amp;px=400" role="button" title="1.png" alt="1.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22598i6B6956E4723AF603/image-size/medium?v=v2&amp;amp;px=400" role="button" title="2.png" alt="2.png" /&gt;&lt;/span&gt;&lt;P&gt; &lt;/P&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;3) In GW&amp;nbsp;&lt;/P&gt;&lt;P&gt;pdp don t take username, because of it rules don t work properly (ise-1 computer that admins ise, just example)&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22595i668A669440E03DC0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="3.png" alt="3.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="4.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22596iDBC507C79DE27B21/image-size/medium?v=v2&amp;amp;px=400" role="button" title="4.png" alt="4.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In smartconsole we see this on every login&amp;nbsp;attempt:&lt;/P&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="5.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22597i3A10C5FEF6ED9D73/image-size/medium?v=v2&amp;amp;px=400" role="button" title="5.png" alt="5.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt; &lt;SPAN&gt;I checked every setting on everything, but I still don’t understand what could be wrong.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt; &lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 08:28:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-proccess-don-t-take-username-using-Identity-Collector/m-p/193738#M35998</guid>
      <dc:creator>DmitriyDubovik</dc:creator>
      <dc:date>2023-09-28T08:28:53Z</dc:date>
    </item>
    <item>
      <title>Re: PDP proccess don t take username using Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-proccess-don-t-take-username-using-Identity-Collector/m-p/193746#M36000</link>
      <description>&lt;P&gt;Do you receive&amp;nbsp;&lt;SPAN&gt;sAMAccountName or&amp;nbsp;UserPrincipalName as user name?&lt;BR /&gt;I remember in the past to be forced to define the ldap search query accordingly in Guidbedit to be able to get correct ldap search results.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 09:42:34 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-proccess-don-t-take-username-using-Identity-Collector/m-p/193746#M36000</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2023-09-28T09:42:34Z</dc:date>
    </item>
    <item>
      <title>Re: PDP proccess don t take username using Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-proccess-don-t-take-username-using-Identity-Collector/m-p/193748#M36001</link>
      <description>&lt;P&gt;nothing at all&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 10:30:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-proccess-don-t-take-username-using-Identity-Collector/m-p/193748#M36001</guid>
      <dc:creator>DmitriyDubovik</dc:creator>
      <dc:date>2023-09-28T10:30:44Z</dc:date>
    </item>
    <item>
      <title>Re: PDP proccess don t take username using Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-proccess-don-t-take-username-using-Identity-Collector/m-p/193787#M36019</link>
      <description>&lt;P&gt;Can you verify ldap account unit is configured properly in smart console? You still need that even with IC set up.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 16:17:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-proccess-don-t-take-username-using-Identity-Collector/m-p/193787#M36019</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-09-28T16:17:37Z</dc:date>
    </item>
    <item>
      <title>Re: PDP proccess don t take username using Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-proccess-don-t-take-username-using-Identity-Collector/m-p/193802#M36023</link>
      <description>&lt;P&gt;Gateways must be able to query Active Directory to obtain the groups the user is associated with.&lt;BR /&gt;This points to an issue in your LDAP configuration.&lt;BR /&gt;For troubleshooting that, see:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk100406" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk100406&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 28 Sep 2023 19:13:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-proccess-don-t-take-username-using-Identity-Collector/m-p/193802#M36023</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-09-28T19:13:10Z</dc:date>
    </item>
    <item>
      <title>Re: PDP proccess don t take username using Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-proccess-don-t-take-username-using-Identity-Collector/m-p/193848#M36033</link>
      <description>&lt;P&gt;I meant from ISE. What's the Username collected from ISE?&amp;nbsp;&lt;SPAN&gt;sAMAccountName or&amp;nbsp;UserPrincipalName?&lt;BR /&gt;PDP needs something to make ldap query for group membership resolution.&lt;BR /&gt;Error message from Smartlog in your post may point to the issue that the wrong one is used.&lt;BR /&gt;In case the Attr received leads to errors when trying to resolve group memberships, sometimes UserLoginAttr is to be modified in the Checkpoint Database using guidbedit.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;DIV class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="identity-collector-ldap.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/22613iF198DBDC323C072E/image-size/medium?v=v2&amp;amp;px=400" role="button" title="identity-collector-ldap.png" alt="identity-collector-ldap.png" /&gt;&lt;/span&gt;&lt;/DIV&gt;&lt;DIV class=""&gt;&amp;nbsp;&lt;/DIV&gt;&lt;P&gt;In case pdp process queries using wrong attr, user cannot be found, leading to same error message as above.&lt;BR /&gt;&lt;BR /&gt;To clarify, you might want to debug.&lt;/P&gt;&lt;P&gt;Then first enable debug on the PDP&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="cpp"&gt;fw debug fwd off PDP_LOG_SIZE=50000000
fw debug fwd off PDP_NUM_LOGS=20
fw kill pdpd
pdp debug off
pdp debug reset
pdp debug set all all&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;replicate issue&lt;/P&gt;&lt;P&gt;disable debug&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="cpp"&gt;fw debug fwd off PDP_LOG_SIZE=10000000
fw debug fwd off PDP_NUM_LOGS=10
pdp debug off
pdp debug reset
fw kill pdpd&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;and then you are able to analyse the collected files in $FWDIR/logs/pdpd.elg*&lt;BR /&gt;In case my idea is correct, you could see hints pointing to that.&lt;BR /&gt;Or maybe pointing to a different root cause.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Sep 2023 06:02:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-proccess-don-t-take-username-using-Identity-Collector/m-p/193848#M36033</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2023-09-29T06:02:38Z</dc:date>
    </item>
    <item>
      <title>Re: PDP proccess don t take username using Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-proccess-don-t-take-username-using-Identity-Collector/m-p/196101#M36586</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk147417" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk147417&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;problem solved here&lt;/P&gt;</description>
      <pubDate>Wed, 25 Oct 2023 07:20:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-proccess-don-t-take-username-using-Identity-Collector/m-p/196101#M36586</guid>
      <dc:creator>DmitriyDubovik</dc:creator>
      <dc:date>2023-10-25T07:20:41Z</dc:date>
    </item>
    <item>
      <title>Re: PDP proccess don t take username using Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-proccess-don-t-take-username-using-Identity-Collector/m-p/200667#M37695</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Are the tshoot commands similar for "SMB" machines?&lt;/P&gt;
&lt;P&gt;I have a "negotiation" problem between my GW 1590 SMB, and my SRV AD which has the IDC installed.&lt;/P&gt;
&lt;P&gt;On these machines, is it viable to "restart" the PDP process with the command, "fw kill pdpd"?&lt;/P&gt;
&lt;P&gt;Greetings.&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2023 23:03:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/PDP-proccess-don-t-take-username-using-Identity-Collector/m-p/200667#M37695</guid>
      <dc:creator>Matlu</dc:creator>
      <dc:date>2023-12-14T23:03:19Z</dc:date>
    </item>
  </channel>
</rss>

