<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP &amp;amp; IDC all logs are &amp;quot;failed log in&amp;quot; in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206908#M39079</link>
    <description>&lt;P&gt;Forgot that, 100% true.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Thu, 22 Feb 2024 19:17:28 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2024-02-22T19:17:28Z</dc:date>
    <item>
      <title>LDAP &amp; IDC all logs are "failed log in"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206874#M39073</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We have installed IDC and everything looks good. The problem is that all logs coming to SMS are "Failed log in", even if the log in was successful the log still&amp;nbsp;"Failed log in"?!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="idc.JPG" style="width: 657px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24614i9C940AE26AC6E695/image-size/large?v=v2&amp;amp;px=999" role="button" title="idc.JPG" alt="idc.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;All of the above logs were successful but logs in SMS say "failed log in"&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="log3.JPG" style="width: 976px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24615i858E7109373818BE/image-size/large?v=v2&amp;amp;px=999" role="button" title="log3.JPG" alt="log3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Any ideas!&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 16:11:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206874#M39073</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-02-22T16:11:52Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP &amp; IDC all logs are "failed log in"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206883#M39074</link>
      <description>&lt;P&gt;Will check in lab, I think there is setting for this.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 16:48:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206883#M39074</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T16:48:24Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP &amp; IDC all logs are "failed log in"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206889#M39075</link>
      <description>&lt;P&gt;Make sure option I pointed out is CHECKED.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot_1.png" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24617i304023ED993F11BB/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Screenshot_1.png" alt="Screenshot_1.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt; &lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 17:18:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206889#M39075</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T17:18:30Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP &amp; IDC all logs are "failed log in"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206905#M39077</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/65882"&gt;@Moudar&lt;/a&gt;&amp;nbsp;Let us know if that does not work, I can do more lab tests.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 19:11:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206905#M39077</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T19:11:50Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP &amp; IDC all logs are "failed log in"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206906#M39078</link>
      <description>&lt;P&gt;You also need to configure the relevant LDAP Account Unit in Smart Console.&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 19:13:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206906#M39078</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2024-02-22T19:13:17Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP &amp; IDC all logs are "failed log in"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206908#M39079</link>
      <description>&lt;P&gt;Forgot that, 100% true.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 19:17:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206908#M39079</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T19:17:28Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP &amp; IDC all logs are "failed log in"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206915#M39084</link>
      <description>&lt;P&gt;It is already configured as you said!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="settings-collector.JPG" style="width: 405px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24619iD863F625A5888C9C/image-size/large?v=v2&amp;amp;px=999" role="button" title="settings-collector.JPG" alt="settings-collector.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 20:29:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206915#M39084</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-02-22T20:29:17Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP &amp; IDC all logs are "failed log in"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206916#M39085</link>
      <description>&lt;P&gt;so if I have 4 different AD servers, everyone needs to have a LDAP account unit?&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 20:28:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206916#M39085</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-02-22T20:28:22Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP &amp; IDC all logs are "failed log in"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206917#M39086</link>
      <description>&lt;P&gt;It should be checked.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 20:29:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206917#M39086</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T20:29:20Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP &amp; IDC all logs are "failed log in"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206918#M39087</link>
      <description>&lt;P&gt;I dont believe its required, but probably recommended.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Thu, 22 Feb 2024 20:29:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206918#M39087</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-22T20:29:54Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP &amp; IDC all logs are "failed log in"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206976#M39119</link>
      <description>&lt;P&gt;Account Units are per domain, not servers. You can create an AU with your domain and have 4 servers participate in it.&lt;/P&gt;
&lt;P&gt;The firewalls need to be able to interrogate the AD servers to map the logon informations sent by the collectors.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 05:44:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/206976#M39119</guid>
      <dc:creator>Alex-</dc:creator>
      <dc:date>2024-02-23T05:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP &amp; IDC all logs are "failed log in"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/207001#M39122</link>
      <description>&lt;P&gt;I know in the past it was always mentioned to have one server per AU, but I had seen people do multiple, works fine.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Feb 2024 10:06:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/207001#M39122</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-23T10:06:57Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP &amp; IDC all logs are "failed log in"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/207254#M39166</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="LDAP-AU.JPG" style="width: 377px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24652i748FB300E86266F1/image-size/large?v=v2&amp;amp;px=999" role="button" title="LDAP-AU.JPG" alt="LDAP-AU.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;As you can see our servers are in an LDAP AU, but still getting only "Failed log in" logs&amp;nbsp; and "log out" logs but no "log in" logs!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="collector-logs.JPG" style="width: 367px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24653iB65E7B8F46E98E0E/image-size/large?v=v2&amp;amp;px=999" role="button" title="collector-logs.JPG" alt="collector-logs.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;a rule to allow traffic looks like this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="collector rule.JPG" style="width: 826px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24654i68C683CCBB818F67/image-size/large?v=v2&amp;amp;px=999" role="button" title="collector rule.JPG" alt="collector rule.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 11:06:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/207254#M39166</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-02-27T11:06:42Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP &amp; IDC all logs are "failed log in"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/207279#M39185</link>
      <description>&lt;P&gt;LDAP account unit seems fine to me. I would open TAC case to have all this double checked via remote session, might not be a bad idea.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 27 Feb 2024 14:17:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/LDAP-amp-IDC-all-logs-are-quot-failed-log-in-quot/m-p/207279#M39185</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2024-02-27T14:17:19Z</dc:date>
    </item>
  </channel>
</rss>

