<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Problem with authentification users on Terminal agent MUHv2 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-authentification-users-on-Terminal-agent-MUHv2/m-p/248281#M48507</link>
    <description>&lt;P&gt;I posted how I solved:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/SOLVED-Identity-Agent-Terminal-Server-Users-Not-Authenticated/m-p/248279#M41486" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/SOLVED-Identity-Agent-Terminal-Server-Users-Not-Authenticated/m-p/248279#M41486&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 06 May 2025 22:54:15 GMT</pubDate>
    <dc:creator>israelfds95</dc:creator>
    <dc:date>2025-05-06T22:54:15Z</dc:date>
    <item>
      <title>Problem with authentification users on Terminal agent MUHv2</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-authentification-users-on-Terminal-agent-MUHv2/m-p/167727#M30308</link>
      <description>&lt;P&gt;Hi all&lt;/P&gt;&lt;P&gt;I have problem with authentification users on terminal agent. I have windows server 2022 where is installed MUH agent v2. Agent send identities to PDP Gateway. PDP gateway is cluster HA (active/standby). Users and machines are authentificated by kerberos SSO and it works. Identity agent for windows authetificate user and machine by kerberos but terminal agent use authentification trust for users and kerberos for machine.&amp;nbsp;&amp;nbsp;The problem : when node 2 is active everything works (users are authentificated) but when I switch node 1 to active, authentification trust for users doesnt work. Kerberos for machine works but user is not authentificated. Pdp debug log and terminal agent log:&amp;nbsp;&lt;/P&gt;&lt;P&gt;pdp::UserPasswordAuthenticator::DoneFetchAsync: failed to fetch authentication data for ******. Request ID: . external error: 6 external Error Description: An error was detected while trying to authenticate against the AD server.&lt;/P&gt;&lt;P&gt;I also find log from AD and there is login success for user. Connection from terminal agent to PDP GW works (443), terminal agent is connected but user on node 1 is not able authentificate.&lt;/P&gt;&lt;P&gt;PDP gw log:&amp;nbsp;An error was detected while trying to authenticate against the AD server.&lt;BR /&gt;It may be a problem of bad configuration or connectivity.&lt;BR /&gt;Please refer to the troubleshooting guide for more help&lt;/P&gt;&lt;P&gt;Security GW: &lt;SPAN&gt;&amp;nbsp;R81.10 take 335&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 08:07:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-authentification-users-on-Terminal-agent-MUHv2/m-p/167727#M30308</guid>
      <dc:creator>vonsakfilip</dc:creator>
      <dc:date>2023-01-13T08:07:39Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with authentification users on Terminal agent MUHv2</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-authentification-users-on-Terminal-agent-MUHv2/m-p/167730#M30309</link>
      <description>&lt;P&gt;In such cases the first and easiest step i always do is to perform a ldapsearch on the cli of the gateway to see if it's able to communicate with the AD server.&lt;/P&gt;&lt;P&gt;Edit: Just enabled pdpd debug on a test pdp device and see that Async messages are shown when the gateway connects to the ldap au (ad server) to fetch the users information (group membership and so on).&lt;BR /&gt;To do this, the gateway has to connect to the ldap au and to authenticate and fetch users info.&lt;BR /&gt;Maybe anything does not work at this stage.&lt;BR /&gt;Maybe i am wrong, it's still too early in the morning for me &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 08:53:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-authentification-users-on-Terminal-agent-MUHv2/m-p/167730#M30309</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2023-01-13T08:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with authentification users on Terminal agent MUHv2</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-authentification-users-on-Terminal-agent-MUHv2/m-p/167736#M30310</link>
      <description>&lt;P&gt;I dont see any problem with AD. Both GW are able authentificate machine and users with kerberos on identity agents. I have only problem with node1 in cluster, node2 works fine. Cluster have same configuration a ip address from same subnet. Connection to AD is correct. The problem have only terminal agent on one node of cluster. GW use same account to communicate with AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 09:52:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-authentification-users-on-Terminal-agent-MUHv2/m-p/167736#M30310</guid>
      <dc:creator>vonsakfilip</dc:creator>
      <dc:date>2023-01-13T09:52:46Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with authentification users on Terminal agent MUHv2</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-authentification-users-on-Terminal-agent-MUHv2/m-p/167743#M30314</link>
      <description>&lt;P&gt;I had only used this log entry&lt;/P&gt;&lt;P&gt;pdp::UserPasswordAuthenticator::DoneFetchAsync: failed to fetch authentication data for ******. Request ID: . external error: 6 external Error Description: An error was detected while trying to authenticate against the AD server.&lt;/P&gt;&lt;P&gt;suspects that there might be a communication problem between the cluster node and the AD server. Since you obviously know better than me, I take it all back and wish you good luck &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 13 Jan 2023 10:24:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-authentification-users-on-Terminal-agent-MUHv2/m-p/167743#M30314</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2023-01-13T10:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: Problem with authentification users on Terminal agent MUHv2</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-authentification-users-on-Terminal-agent-MUHv2/m-p/248281#M48507</link>
      <description>&lt;P&gt;I posted how I solved:&amp;nbsp;&lt;A href="https://community.checkpoint.com/t5/General-Topics/SOLVED-Identity-Agent-Terminal-Server-Users-Not-Authenticated/m-p/248279#M41486" target="_blank"&gt;https://community.checkpoint.com/t5/General-Topics/SOLVED-Identity-Agent-Terminal-Server-Users-Not-Authenticated/m-p/248279#M41486&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 06 May 2025 22:54:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Problem-with-authentification-users-on-Terminal-agent-MUHv2/m-p/248281#M48507</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2025-05-06T22:54:15Z</dc:date>
    </item>
  </channel>
</rss>

