<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness and AD in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198535#M66675</link>
    <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you try&amp;nbsp; to use command test_ad_ connectivity from gateway?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suggest to review or create the domain object directly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/CLI/test-ad-connectivity.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/CLI/test-ad-connectivity.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Nov 2023 16:03:10 GMT</pubDate>
    <dc:creator>cassiomaciel</dc:creator>
    <dc:date>2023-11-21T16:03:10Z</dc:date>
    <item>
      <title>Identity Awareness and AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198235#M66665</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;I am trying the&amp;nbsp;Identity Awareness blade in my lab. when activating the&amp;nbsp;Identity Awareness blade it says "Domain administrator credentials are required"&lt;/P&gt;&lt;P&gt;The AD account I am using to do that is a domain&amp;nbsp;administrator, but even though i get this: "Standard user cerdentials"!&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="awareness1.JPG" style="width: 602px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23281iF7F4B87EAD79FD0A/image-size/large?v=v2&amp;amp;px=999" role="button" title="awareness1.JPG" alt="awareness1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;These are the groups that the AD account is member of:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="awareness2.JPG" style="width: 407px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23282i81660C599E101B42/image-size/large?v=v2&amp;amp;px=999" role="button" title="awareness2.JPG" alt="awareness2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;What do I miss here?&lt;/P&gt;</description>
      <pubDate>Fri, 17 Nov 2023 07:43:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198235#M66665</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2023-11-17T07:43:15Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198358#M66666</link>
      <description>&lt;P&gt;I wonder why no one is looking at my problem!!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 07:35:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198358#M66666</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2023-11-20T07:35:40Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198359#M66667</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/65882"&gt;@Moudar&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Maybe you can check this page.&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R80.30/WebAdminGuides/EN/CP_R80.30_IdentityAwareness_AdminGuide/html_frameset.htm?topic=documents/R80.30/WebAdminGuides/EN/CP_R80.30_IdentityAwareness_AdminGuide/62050" target="_self"&gt;Identity Awernes Admin Guide&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"&lt;STRONG&gt;Important&lt;/STRONG&gt;&lt;SPAN&gt;&amp;nbsp;- For AD Query you must enter domain administrator credentials. For Browser-Based Authentication standard credentials are sufficient."&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 07:54:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198359#M66667</guid>
      <dc:creator>ikafka</dc:creator>
      <dc:date>2023-11-20T07:54:32Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198382#M66668</link>
      <description>&lt;P&gt;Which Version/Jumbo &amp;amp; SmartConsole build is used in this environment?&lt;/P&gt;
&lt;P&gt;Have you already performed troubleshooting such as&amp;nbsp;&lt;SPAN&gt;sk91040?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Note Identity Collector (rather than ADquery) is the current recommended method for integrating AD with Identity Awareness.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 12:19:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198382#M66668</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-11-20T12:19:47Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198384#M66669</link>
      <description>&lt;P&gt;I am using this version:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt; show version all
Product version Check Point Gaia R81.20
OS build 631
OS kernel version 3.10.0-1160.15.2cpx86_64
OS edition 64-bit&lt;/LI-CODE&gt;&lt;P&gt;when I run: "adlog a dc" I get this:&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;[Expert@A-GW-01:0]# adlog a dc
Domain controllers:
Domain Name               IP Address                Events (last hour)   Connection state
============================================================================================================
a-ldap.a-ldap.lab         192.168.11.101            0                    connection had internal error [ntstatus = 0x80010111]

Ignored domain controllers on this gateway:
No ignored domain controllers found.&lt;/LI-CODE&gt;&lt;P&gt;I am 100% sure that the user is domain admin and the password is right!!&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 13:31:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198384#M66669</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2023-11-20T13:31:16Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198431#M66670</link>
      <description>&lt;P&gt;Pretty sure this is expected behavior in modern environments.&lt;BR /&gt;See:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk91462" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk91462&lt;/A&gt;&lt;BR /&gt;Specifically, if NTMLv2 is enabled (which is the default) this wizard will fail.&lt;/P&gt;</description>
      <pubDate>Mon, 20 Nov 2023 21:53:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198431#M66670</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-20T21:53:12Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198465#M66671</link>
      <description>&lt;LI-CODE lang="markup"&gt;adlogconfig a

 - No configuration exists


[ ] Override configuration
   [ ] Enable Adlog
      [ ] Enable log for login or logoff
      [ ] Use log original creation time
          Association timeout                : 0
          Full Name Query Interval (days, 0=disabled) : 0
          Full Name Fetch Hour               : 0
          Multi-user host Detection Threshold: 7
          Revoked user timeout interval      : 14400
      [X] Enable Multi-User Host persistence DB
          Multi-User Host persistence machine timeout (minutes): 2592000
          Service Account Detection Threshold: 10
      [ ] Automatically Exclude Service Accounts
[ ] Override default communication parameters
          Query Within count                 : 0
          Query Max returned objects in each iteration: 0
[X] Disable password expiration check
[ ] Authentication mode
   [ ] Use NTLMv1
   [X] Use NTLMv2
[ ] Single User Assumption
[ ] Don't report machines
[X] LDAP groups update notifications
          Notifications accumulation time    : 10 (sec)
      [X] Notify only user-related LDAP changes
[ ] Prefer IPv6 DC addresses
[1] WMI query Type&lt;/LI-CODE&gt;&lt;P&gt;As you can see NTLMv2 is enabled.&lt;/P&gt;&lt;P&gt;I will follow sk91462 and come back with results&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 08:30:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198465#M66671</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2023-11-21T08:30:07Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198491#M66672</link>
      <description>&lt;LI-CODE lang="python"&gt;adlogconfig a


[ ] Override configuration
   [ ] Enable Adlog
      [ ] Enable log for login or logoff
      [ ] Use log original creation time
          Association timeout                : 0
          Full Name Query Interval (days, 0=disabled) : 0
          Full Name Fetch Hour               : 0
          -------------------
          Domain name                        : A-LDAP.lab
          Username                           : moudar
          Domain Controllers                 : A-LDAP.A-LDAP.lab
          -------------------
          Multi-user host Detection Threshold: 7
          Revoked user timeout interval      : 14400
      [X] Enable Multi-User Host persistence DB
          Multi-User Host persistence machine timeout (minutes): 2592000
          Service Account Detection Threshold: 10
      [ ] Automatically Exclude Service Accounts
[ ] Override default communication parameters
          Query Within count                 : 0
          Query Max returned objects in each iteration: 0
[X] Disable password expiration check
[ ] Authentication mode
   [X] Use NTLMv1
   [ ] Use NTLMv2
[ ] Single User Assumption
[ ] Don't report machines
[X] LDAP groups update notifications
          Notifications accumulation time    : 10 (sec)
      [X] Notify only user-related LDAP changes
[ ] Prefer IPv6 DC addresses
[1] WMI query Type&lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt; adlogconfig a -test A-LDAP.lab
Testing A-LDAP.A-LDAP.lab:      Internal Error&lt;/LI-CODE&gt;&lt;P&gt;Now I am using NTLMv1 but still have problem with&amp;nbsp;&lt;SPAN&gt;Identity Awareness Configuration wizard:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="identity.JPG" style="width: 599px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/23322i96F173B0708A23ED/image-size/large?v=v2&amp;amp;px=999" role="button" title="identity.JPG" alt="identity.JPG" /&gt;&lt;/span&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 10:54:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198491#M66672</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2023-11-21T10:54:14Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198527#M66673</link>
      <description>&lt;P&gt;I don’t believe the wizard supports LDAPS either, which I assume modern AD servers require.&amp;nbsp;&lt;BR /&gt;However the wizard is not required to configure Identity Awareness.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 15:04:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198527#M66673</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2023-11-21T15:04:46Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198528#M66674</link>
      <description>&lt;P&gt;I became sick of trying to use AD query.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I am using Identity collector and it is running well. But I needed to follow&amp;nbsp;&lt;SPAN&gt;sk113021 to make it connect to the VIP.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 15:09:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198528#M66674</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2023-11-21T15:09:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198535#M66675</link>
      <description>&lt;P&gt;Hi,&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you try&amp;nbsp; to use command test_ad_ connectivity from gateway?&amp;nbsp;&lt;/P&gt;&lt;P&gt;I suggest to review or create the domain object directly.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/CLI/test-ad-connectivity.htm" target="_blank"&gt;https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_IdentityAwareness_AdminGuide/Topics-IDAG/CLI/test-ad-connectivity.htm&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Nov 2023 16:03:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/198535#M66675</guid>
      <dc:creator>cassiomaciel</dc:creator>
      <dc:date>2023-11-21T16:03:10Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness and AD</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/199780#M66676</link>
      <description>&lt;P&gt;Hi Chris,&lt;BR /&gt;Is that recommended (or Best Practice maybe) documented anywhere, so that you can share a link or SK?&lt;/P&gt;&lt;P&gt;I agree with you but want to see if R&amp;amp;D have documented it anywhere.&lt;/P&gt;&lt;P&gt;Don&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Dec 2023 16:37:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-and-AD/m-p/199780#M66676</guid>
      <dc:creator>Don_Paterson</dc:creator>
      <dc:date>2023-12-05T16:37:31Z</dc:date>
    </item>
  </channel>
</rss>

