<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: identity collector - gateway can't see user/machine details in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/203202#M38232</link>
    <description>&lt;P&gt;Hi!&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had this issue. I just installed and configured the Identity Collector and missed the LDAP part.&lt;BR /&gt;You need to have a "LDAP Account Unit" to map usernames from Identity Collector to the Domain for the Microsoft_AD.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
    <pubDate>Tue, 16 Jan 2024 11:08:28 GMT</pubDate>
    <dc:creator>maad-pul</dc:creator>
    <dc:date>2024-01-16T11:08:28Z</dc:date>
    <item>
      <title>identity collector - gateway can't see user/machine details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162162#M28796</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;Just installed and configured Identity Collector for one of our two domains.&lt;/P&gt;&lt;P&gt;Everything looks fine on the IDC, I can see events and users-machines correlations.&lt;/P&gt;&lt;P&gt;however when running pdp m ip x.x.x.x there are many details missing:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="1.JPG" style="width: 688px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18419iC1E1E8F912020A4C/image-size/large?v=v2&amp;amp;px=999" role="button" title="1.JPG" alt="1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Also in SmartConsole logs I see this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2.JPG" style="width: 788px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18418i26B9B6A51EE7E34D/image-size/large?v=v2&amp;amp;px=999" role="button" title="2.JPG" alt="2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Anyone familiar with this issue?&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 19:11:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162162#M28796</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2022-11-15T19:11:41Z</dc:date>
    </item>
    <item>
      <title>Re: identity collector - gateway can't see user/machine details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162169#M28797</link>
      <description>&lt;P&gt;There was a recent post on similar and issue was windows firewall on IC itself, but dont believe thats problem here. Make sure below is checked as per my screenshot.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18421i7B60A1EB654394DE/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 20:13:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162169#M28797</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-15T20:13:41Z</dc:date>
    </item>
    <item>
      <title>Re: identity collector - gateway can't see user/machine details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162170#M28798</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;There's no firewall on the IDC.&lt;/P&gt;&lt;P&gt;However, "Ignore machine identities" was not checked.&lt;/P&gt;&lt;P&gt;Sounds like it really should not be checked or else it would ignore the machine identity.&lt;/P&gt;&lt;P&gt;Also, how is this related to users not being propagated?&lt;/P&gt;&lt;P&gt;can you explain please?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 20:19:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162170#M28798</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2022-11-15T20:19:21Z</dc:date>
    </item>
    <item>
      <title>Re: identity collector - gateway can't see user/machine details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162173#M28799</link>
      <description>&lt;P&gt;Anyway, I tried what you suggested and it didn't work.&lt;/P&gt;&lt;P&gt;Only now, I don't see machine details at all:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="3.JPG" style="width: 453px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/18423i9FF1FFB26D4B0B92/image-size/large?v=v2&amp;amp;px=999" role="button" title="3.JPG" alt="3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 20:23:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162173#M28799</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2022-11-15T20:23:54Z</dc:date>
    </item>
    <item>
      <title>Re: identity collector - gateway can't see user/machine details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162175#M28800</link>
      <description>&lt;P&gt;Sorry man, my bad, I confused 2 different things. I was thinking of "log out", rather than "log in" events. For what you are after, yes, option should be unchecked, apologies.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I found below links about it, but not sure either one applies 100% to your scenario:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106133" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk106133&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Management/Identity-Awareness-We-are-detecting-error-quot-Make-sure-the/td-p/24416" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Management/Identity-Awareness-We-are-detecting-error-quot-Make-sure-the/td-p/24416&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Let me check on my end and see what could be missing.&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 20:40:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162175#M28800</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-15T20:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: identity collector - gateway can't see user/machine details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162176#M28801</link>
      <description>&lt;P&gt;No problem &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Already went through these links, they didn't help unfortunately...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 20:57:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162176#M28801</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2022-11-15T20:57:49Z</dc:date>
    </item>
    <item>
      <title>Re: identity collector - gateway can't see user/machine details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162184#M28802</link>
      <description>&lt;P&gt;Have you done any troubleshooting on the LDAP piece of this?&lt;BR /&gt;The groups come from an LDAP lookup from the gateway, not from Identity Collector.&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 01:25:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162184#M28802</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2022-11-16T01:25:35Z</dc:date>
    </item>
    <item>
      <title>Re: identity collector - gateway can't see user/machine details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162195#M28806</link>
      <description>&lt;P&gt;The LDAP object is working fine when adquery is used. It's only when switching to IDC that it's not working.&lt;/P&gt;&lt;P&gt;After switching to IDC I unchecked the "AD query" option in the LDAP object, that's the only change I've made.&lt;/P&gt;&lt;P&gt;I rechecked the server and credentials in the LDAP and they're OK. What else can I check?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 05:27:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162195#M28806</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2022-11-16T05:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: identity collector - gateway can't see user/machine details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162217#M28814</link>
      <description>&lt;P&gt;That made me remember...when you say unchecked "ad query", are you referring to actual setting on the identity awareness tab on the firewall object itself?&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 12:35:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162217#M28814</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-16T12:35:28Z</dc:date>
    </item>
    <item>
      <title>Re: identity collector - gateway can't see user/machine details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162219#M28815</link>
      <description>&lt;P&gt;Both.&amp;nbsp;&lt;/P&gt;&lt;P&gt;I've tried all combinations:&lt;/P&gt;&lt;P&gt;IDC + ADQuery on fiewall object&lt;/P&gt;&lt;P&gt;IDC without ADQuery on firewall object&lt;/P&gt;&lt;P&gt;IDC without ADQuery on fiewall object and on LDAP object.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 12:48:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162219#M28815</guid>
      <dc:creator>Jonathan</dc:creator>
      <dc:date>2022-11-16T12:48:28Z</dc:date>
    </item>
    <item>
      <title>Re: identity collector - gateway can't see user/machine details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162224#M28817</link>
      <description>&lt;P&gt;So odd...I work with customer who has AD query enabled WITH IC as well and no issues at all. Mind you, I believe TAC recommends to turn off AD query if you use IC (which makes sense), but either way, it should work, 100%. Do you see any logs related to this on your AD server at all?&lt;/P&gt;
&lt;P&gt;Below is what TAC gave me once to debug identity awareness issue, so this also might be worth a shot.&lt;/P&gt;
&lt;P&gt;(•)•) Identity awareness debugs&lt;BR /&gt;# cd $FWDIR/log&lt;BR /&gt;# rm pdpd.elg.*&lt;BR /&gt;# echo "=debug_start=" &amp;gt;&amp;gt; $FWDIR/log/pdpd.elg&lt;BR /&gt;(•) To turn pdp debug on:&lt;BR /&gt;# adlog a d on&lt;BR /&gt;# pdp debug on&lt;BR /&gt;# pep debug on&lt;BR /&gt;# pdp debug set all all&lt;BR /&gt;(•) Replicate the issue&lt;BR /&gt;(•) To turn them off:&lt;BR /&gt;# adlog a d off&lt;BR /&gt;# pdp debug unset all all&lt;BR /&gt;# pdp debug off&lt;BR /&gt;# pep debug off&lt;BR /&gt;# pdp d reset&lt;BR /&gt;# pep d unset all all&lt;BR /&gt;Collect debug:&lt;BR /&gt;$FWDIR/log/pdpd.elg&lt;BR /&gt;# tar zcvf pdpd_debugs.tgz pdpd.elg*&lt;BR /&gt;# tar zcvf pepd_debugs.tgz pepd.elg*&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 13:16:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/162224#M28817</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2022-11-16T13:16:53Z</dc:date>
    </item>
    <item>
      <title>Re: identity collector - gateway can't see user/machine details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/202901#M38180</link>
      <description>&lt;P&gt;Hi Jonathan,&lt;/P&gt;&lt;P&gt;Did you get this working?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Fri, 12 Jan 2024 08:55:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/202901#M38180</guid>
      <dc:creator>maad-pul</dc:creator>
      <dc:date>2024-01-12T08:55:02Z</dc:date>
    </item>
    <item>
      <title>Re: identity collector - gateway can't see user/machine details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/203197#M38231</link>
      <description>&lt;P&gt;Is this issue resolved? if yes, can you share the solution here, please?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 10:07:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/203197#M38231</guid>
      <dc:creator>chethan_m</dc:creator>
      <dc:date>2024-01-16T10:07:37Z</dc:date>
    </item>
    <item>
      <title>Re: identity collector - gateway can't see user/machine details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/203202#M38232</link>
      <description>&lt;P&gt;Hi!&amp;nbsp;&lt;/P&gt;&lt;P&gt;I had this issue. I just installed and configured the Identity Collector and missed the LDAP part.&lt;BR /&gt;You need to have a "LDAP Account Unit" to map usernames from Identity Collector to the Domain for the Microsoft_AD.&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 11:08:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/203202#M38232</guid>
      <dc:creator>maad-pul</dc:creator>
      <dc:date>2024-01-16T11:08:28Z</dc:date>
    </item>
    <item>
      <title>Re: identity collector - gateway can't see user/machine details</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/203247#M38241</link>
      <description>&lt;P&gt;I do have LDAP account unit in place. For me the issue is slightly different.&amp;nbsp;&lt;/P&gt;&lt;P&gt;The individual user authentication works fine but when I use LDAP user groups instead of individual users in Access Roles the network access doesn't work.&lt;/P&gt;&lt;P&gt;When I do "pdp monitor all" I can users populated and but not their associated user groups on AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Jan 2024 15:55:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/identity-collector-gateway-can-t-see-user-machine-details/m-p/203247#M38241</guid>
      <dc:creator>chethan_m</dc:creator>
      <dc:date>2024-01-16T15:55:24Z</dc:date>
    </item>
  </channel>
</rss>

