<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Domain Controllers not detected by Identity Collector in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Controllers-not-detected-by-Identity-Collector/m-p/265832#M52353</link>
    <description>&lt;P&gt;Reference document(s):&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Clients-AG/Introduction.htm?tocpath=_____2" target="_self"&gt;Identity Awareness Clients Administration Guide&lt;/A&gt;&amp;nbsp;,&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk108235" target="_self"&gt;Identity Collector - Technical Overview&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I created an Access Role on the firewall as follows:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="accessrole.png" style="width: 791px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32519i55180E5869FA8CDE/image-size/large?v=v2&amp;amp;px=999" role="button" title="accessrole.png" alt="accessrole.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am noticing in the logs that our Domain Controllers are NOT hitting this rule which is defined by the above Access Role. Logging into the firewall I run these commands:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;pdp monitor machine_exact &amp;lt;my computer&amp;gt;
&lt;UL&gt;
&lt;LI&gt;Works as expected&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;pdp monitor machine_exact &amp;lt;domain controller&amp;gt;
&lt;UL&gt;
&lt;LI&gt;Blank response&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Checking the Logs:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;blade:"Identity Awareness" AND origin:&amp;lt;firewall&amp;gt; AND &amp;lt;my computer&amp;gt;
&lt;UL&gt;
&lt;LI&gt;Results are returned&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;blade:"Identity Awareness" AND origin:&amp;lt;firewall&amp;gt; AND &amp;lt;domain controller&amp;gt;
&lt;UL&gt;
&lt;LI&gt;No results&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this a limitation of the Identity Collector that it cannot report on Domain Controllers? Or is this something else like a misconfiguration? Could not find any verbiage in my searching mentioning this is a limitation.&lt;/P&gt;
&lt;P&gt;R82-JHF 44 / Identity Collector&amp;nbsp;82.129.0000&lt;/P&gt;</description>
    <pubDate>Fri, 19 Dec 2025 17:45:06 GMT</pubDate>
    <dc:creator>CaseyB</dc:creator>
    <dc:date>2025-12-19T17:45:06Z</dc:date>
    <item>
      <title>Domain Controllers not detected by Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Controllers-not-detected-by-Identity-Collector/m-p/265832#M52353</link>
      <description>&lt;P&gt;Reference document(s):&amp;nbsp;&lt;A href="https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Clients-AG/Introduction.htm?tocpath=_____2" target="_self"&gt;Identity Awareness Clients Administration Guide&lt;/A&gt;&amp;nbsp;,&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk108235" target="_self"&gt;Identity Collector - Technical Overview&lt;/A&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I created an Access Role on the firewall as follows:&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="accessrole.png" style="width: 791px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/32519i55180E5869FA8CDE/image-size/large?v=v2&amp;amp;px=999" role="button" title="accessrole.png" alt="accessrole.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P class="lia-indent-padding-left-60px"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I am noticing in the logs that our Domain Controllers are NOT hitting this rule which is defined by the above Access Role. Logging into the firewall I run these commands:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;pdp monitor machine_exact &amp;lt;my computer&amp;gt;
&lt;UL&gt;
&lt;LI&gt;Works as expected&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;pdp monitor machine_exact &amp;lt;domain controller&amp;gt;
&lt;UL&gt;
&lt;LI&gt;Blank response&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;Checking the Logs:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;blade:"Identity Awareness" AND origin:&amp;lt;firewall&amp;gt; AND &amp;lt;my computer&amp;gt;
&lt;UL&gt;
&lt;LI&gt;Results are returned&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;LI&gt;blade:"Identity Awareness" AND origin:&amp;lt;firewall&amp;gt; AND &amp;lt;domain controller&amp;gt;
&lt;UL&gt;
&lt;LI&gt;No results&lt;/LI&gt;
&lt;/UL&gt;
&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is this a limitation of the Identity Collector that it cannot report on Domain Controllers? Or is this something else like a misconfiguration? Could not find any verbiage in my searching mentioning this is a limitation.&lt;/P&gt;
&lt;P&gt;R82-JHF 44 / Identity Collector&amp;nbsp;82.129.0000&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2025 17:45:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Controllers-not-detected-by-Identity-Collector/m-p/265832#M52353</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-12-19T17:45:06Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Controllers not detected by Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Controllers-not-detected-by-Identity-Collector/m-p/265833#M52354</link>
      <description>&lt;P&gt;As info about Idc config is missing here I just can speculate what’s going on.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Most likely you’re using AD polling as identity source, not sylog or ISE (pxGrid)&lt;BR /&gt;So basically, the reason you’re not seeing the Domain Controller show up is because the Identity Collector relies on security events that are generated when clients authenticate to the domain. When a normal client logs in, a security event is created that ties the user identity to the machine and its IP address. The Identity Collector uses these events to build the user-to-IP and machine mappings.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Domain Controllers themselves do not generate these kinds of user login events for their own identity. They operate as infrastructure components and typically run under system accounts, so there are no relevant security events that Identity Awareness can use to identify the DC as an endpoint. Therefore, this behavior is expected and not a misconfiguration.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;As an alternative approach, we are currently in a testing phase using 802.1X together with Cisco ISE. In this setup, session information is shared via pxGrid (Security Group Tags / SGT) which can then be consumed by the Identity Engine / Identity Collector. This approach does work and provides visibility even for servers or infrastructure devices that do not have interactive user logins.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2025 18:52:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Controllers-not-detected-by-Identity-Collector/m-p/265833#M52354</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2025-12-19T18:52:22Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Controllers not detected by Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Controllers-not-detected-by-Identity-Collector/m-p/265834#M52355</link>
      <description>&lt;P&gt;Yes, we are using AD polling as the identity source.&lt;/P&gt;
&lt;P&gt;An RDP event to the Domain Controller wouldn't generate a login event that could be used either?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2025 19:08:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Controllers-not-detected-by-Identity-Collector/m-p/265834#M52355</guid>
      <dc:creator>CaseyB</dc:creator>
      <dc:date>2025-12-19T19:08:26Z</dc:date>
    </item>
    <item>
      <title>Re: Domain Controllers not detected by Identity Collector</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Controllers-not-detected-by-Identity-Collector/m-p/265835#M52356</link>
      <description>&lt;P&gt;&lt;SPAN&gt;Yes, that’s correct.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Even if you RDP to a Domain Controller, the resulting logon event is still associated with the user and the client IP, not with the Domain Controller itself as an endpoint identity.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;From an Identity Awareness / AD polling perspective, the event only tells the collector:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;&lt;SPAN&gt;which user logged in&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;from which source IP (the client/workstation)&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;It does not create a machine identity for the Domain Controller. Therefore, this type of event cannot be used to identify the DC itself in Identity Awareness or to match an Access Role.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Also, while the logon is recorded in the Security Event Log (not the Application log), it still does not change the behavior — Domain Controllers are not treated as identity-aware endpoints.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;As we don’t use ad polling maybe my statement is not absolutely correct in all details but in general it should apply.&lt;/P&gt;</description>
      <pubDate>Fri, 19 Dec 2025 19:18:05 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Domain-Controllers-not-detected-by-Identity-Collector/m-p/265835#M52356</guid>
      <dc:creator>Vincent_Bacher</dc:creator>
      <dc:date>2025-12-19T19:18:05Z</dc:date>
    </item>
  </channel>
</rss>

