<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Awareness - Could not connect to AD server in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/71070#M82487</link>
    <description>&lt;P&gt;The client your connecting from, the firewall(cluster) and SmartCenter should be able to connect to the AD server. The client workstation proxies on behalf of the management station and the firewall also verifies it can communicate to the AD server.&amp;nbsp; If you go into expert mode on firewall and run following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nslookup&lt;/P&gt;&lt;P&gt;&amp;gt; set type=srv&lt;/P&gt;&lt;P&gt;&amp;gt;_ldap._tcp.&amp;lt;domain_name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It should return back the AD servers in the environment.&amp;nbsp; If it does not then you need to fix either (a) reverse lookup for your domain (b) the dns server on the firewall.&amp;nbsp; I have seen where people will use the ISP dns servers and this breaks AD query.&amp;nbsp; Also, I would suggest you look at Identity Collector (sk108235) it is much more stable way of doing identity awareness and is less resource intensive on both your firewall and AD server(s).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Sun, 22 Dec 2019 19:49:44 GMT</pubDate>
    <dc:creator>Juan_Concepcion</dc:creator>
    <dc:date>2019-12-22T19:49:44Z</dc:date>
    <item>
      <title>Identity Awareness - Could not connect to AD server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/71065#M82484</link>
      <description>&lt;P&gt;Hello everyone,&lt;/P&gt;&lt;P&gt;I tried to test the Identity Awareness Blade on my lab and connect to a AD server but always got the error message on SmartDashboard (R80.30):&lt;/P&gt;&lt;P&gt;"SmartDashboard could not connect to x.x.x.x - Could not communicate with server."&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Bildschirmfoto 2019-12-22 um 16.41.27.jpg" style="width: 400px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/3832iBE88D27187CA8F16/image-size/medium?v=v2&amp;amp;px=400" role="button" title="Bildschirmfoto 2019-12-22 um 16.41.27.jpg" alt="Bildschirmfoto 2019-12-22 um 16.41.27.jpg" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I did several troubleshooting things like mentioned on the link below:&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113747" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk113747&lt;/A&gt;&lt;/P&gt;&lt;P&gt;I can connect to the AD server without any error from the cli on my security gateway using "&lt;STRONG&gt;test_ad_connectivity" and "ldapsearch" but from SmartDashboard it does not work.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I moved on with checking the box "Ignore the errors and continue to configure the LDAP account" and put in the login DN which worked fine. I also activated Browser-based Authentication which I could test successfully from my test client.&lt;/P&gt;&lt;P&gt;I did a packet capture on the AD server to check if there is any traffic from the security gateway to the AD server during the activation of AD Query within the Wizard, but there are no packets arrived on the AD server.&lt;/P&gt;&lt;P&gt;I also tried to add a LDAP Account Unit before activating the Identity Awareness blade, so that you can choose it from the dropdown within the configuration wizard. Adding the LDAP Account Unit worked also without errors, but during the AD Query activation it failed again to connect like before.&lt;/P&gt;&lt;P&gt;Anyone had similar issues or any experiences with that error?&lt;/P&gt;</description>
      <pubDate>Sun, 22 Dec 2019 15:45:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/71065#M82484</guid>
      <dc:creator>Daniel_Kuhl1</dc:creator>
      <dc:date>2019-12-22T15:45:02Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Could not connect to AD server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/71067#M82485</link>
      <description>2 things to check:&lt;BR /&gt;  Can your client directly access the AD server?&lt;BR /&gt;  Can your Management server directly access the AD server?&lt;BR /&gt;Have you enabled NTLMv2 and pushed policy?&lt;BR /&gt;From expert mode run: adlogconfig a&lt;BR /&gt;Check the setting for NTLMv2  make sure it is enabled, if not enable it and push policy!</description>
      <pubDate>Sun, 22 Dec 2019 17:47:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/71067#M82485</guid>
      <dc:creator>Maarten_Sjouw</dc:creator>
      <dc:date>2019-12-22T17:47:28Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Could not connect to AD server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/71068#M82486</link>
      <description>&lt;P&gt;Firewall rules?&lt;/P&gt;
&lt;P&gt;Source: SmartConsole IP &amp;nbsp;&lt;/P&gt;
&lt;P&gt;Destination: AD Server IP&lt;/P&gt;
&lt;P&gt;Service: Port 135 AD query&lt;/P&gt;
&lt;P&gt;More read here:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://community.checkpoint.com/docs/DOC-2740-r80x-ports-used-for-communication-by-various-check-point-modules" target="_blank" rel="noopener"&gt; R80.x - Ports Used for Communication by Various Check Point Modules&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Dec 2019 18:34:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/71068#M82486</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2019-12-22T18:34:47Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Could not connect to AD server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/71070#M82487</link>
      <description>&lt;P&gt;The client your connecting from, the firewall(cluster) and SmartCenter should be able to connect to the AD server. The client workstation proxies on behalf of the management station and the firewall also verifies it can communicate to the AD server.&amp;nbsp; If you go into expert mode on firewall and run following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;nslookup&lt;/P&gt;&lt;P&gt;&amp;gt; set type=srv&lt;/P&gt;&lt;P&gt;&amp;gt;_ldap._tcp.&amp;lt;domain_name&amp;gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It should return back the AD servers in the environment.&amp;nbsp; If it does not then you need to fix either (a) reverse lookup for your domain (b) the dns server on the firewall.&amp;nbsp; I have seen where people will use the ISP dns servers and this breaks AD query.&amp;nbsp; Also, I would suggest you look at Identity Collector (sk108235) it is much more stable way of doing identity awareness and is less resource intensive on both your firewall and AD server(s).&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sun, 22 Dec 2019 19:49:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/71070#M82487</guid>
      <dc:creator>Juan_Concepcion</dc:creator>
      <dc:date>2019-12-22T19:49:44Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Could not connect to AD server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/71284#M82488</link>
      <description>Hi Maarten, thanks a lot for your reply. I could solve the issue now. As I already thought it was a simple error. The problem was that I was not able to connect to the AD server from the management client pc.</description>
      <pubDate>Sat, 28 Dec 2019 06:42:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/71284#M82488</guid>
      <dc:creator>Daniel_Kuhl1</dc:creator>
      <dc:date>2019-12-28T06:42:22Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Could not connect to AD server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/71285#M82489</link>
      <description>Hi Heiko, thanks a lot for your reply. The link you posted was very helpful for troubleshooting and I bookmarked it for future usage.</description>
      <pubDate>Sat, 28 Dec 2019 06:43:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/71285#M82489</guid>
      <dc:creator>Daniel_Kuhl1</dc:creator>
      <dc:date>2019-12-28T06:43:49Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Could not connect to AD server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/78851#M82490</link>
      <description>&lt;P&gt;Hey Daniel!&lt;/P&gt;&lt;P&gt;I'm having the same issue with the Identity Awareness blade. But my problem is with the AD server setting on the CheckPoint.&lt;/P&gt;&lt;P&gt;The&amp;nbsp;Identity Awareness wizard is detecting mu domain but it is trying to connect to a AD server that has been decommissioned long ago.&lt;/P&gt;</description>
      <pubDate>Thu, 19 Mar 2020 19:39:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/78851#M82490</guid>
      <dc:creator>sauloaraujo</dc:creator>
      <dc:date>2020-03-19T19:39:15Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Could not connect to AD server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/83363#M82491</link>
      <description>Were you able to solve the issue? Seems like you need to re-initialize (disable/enable) Identity Awareness... (I'm only guessing because I don't know your environment)</description>
      <pubDate>Mon, 27 Apr 2020 15:43:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/83363#M82491</guid>
      <dc:creator>Daniel_Kuhl1</dc:creator>
      <dc:date>2020-04-27T15:43:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Could not connect to AD server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/83387#M82492</link>
      <description>&lt;P&gt;Hi Daniel,&lt;/P&gt;&lt;P&gt;Yes, I managed to get it sorted.&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;</description>
      <pubDate>Mon, 27 Apr 2020 19:49:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/83387#M82492</guid>
      <dc:creator>sauloaraujo</dc:creator>
      <dc:date>2020-04-27T19:49:17Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Could not connect to AD server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/83463#M82493</link>
      <description>&lt;P&gt;What did you do to get it solved? Maybe others can benefit from your experiences.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 10:16:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/83463#M82493</guid>
      <dc:creator>Daniel_Kuhl1</dc:creator>
      <dc:date>2020-04-28T10:16:15Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Could not connect to AD server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/83542#M82494</link>
      <description>&lt;P&gt;You're right, Daniel.&lt;/P&gt;&lt;P&gt;So, one of the Active Directory servers was decommissioned on the environment, that was the cause of the issue.&lt;/P&gt;&lt;P&gt;First, I checked the Identity Awareness settings on the SmartConsole:&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Gateway Cluster Properties &amp;gt; Identity Awareness &amp;gt; Active Directory Query &amp;gt; Settings&lt;/STRONG&gt; and confirmed the name of the Object that define the &lt;STRONG&gt;Active Directory Domains&lt;/STRONG&gt;.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 432px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5852i9AE5447DAE00F282/image-dimensions/432x314?v=v2" width="432" height="314" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 348px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5851i716D74449114A678/image-dimensions/348x312?v=v2" width="348" height="312" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Then, I located the &lt;STRONG&gt;FIDELITY.LOCAL__AD&lt;/STRONG&gt; object and removed the decommissioned server from the servers list.&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Capture.PNG" style="width: 352px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/5853iE76D3916AE0B1398/image-dimensions/352x501?v=v2" width="352" height="501" role="button" title="Capture.PNG" alt="Capture.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;After publishing the changes and installing the policies, the issue was resolved.&lt;/P&gt;&lt;P&gt;Hope that it was helpful.&lt;/P&gt;&lt;P&gt;Cheers!&lt;/P&gt;&lt;P&gt;Saulo&lt;/P&gt;</description>
      <pubDate>Tue, 28 Apr 2020 19:55:44 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/83542#M82494</guid>
      <dc:creator>sauloaraujo</dc:creator>
      <dc:date>2020-04-28T19:55:44Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Could not connect to AD server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/83692#M82495</link>
      <description>Thank you Saulo!</description>
      <pubDate>Thu, 30 Apr 2020 07:12:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/83692#M82495</guid>
      <dc:creator>Daniel_Kuhl1</dc:creator>
      <dc:date>2020-04-30T07:12:31Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Awareness - Could not connect to AD server</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/118810#M82496</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Like you, we have 3 domain controllers, but in our scenario, one of the servers was not decommissioned, but just crashed one day.&lt;/P&gt;&lt;P&gt;The purpose of listing the 3 DCs in the LDAP unit is for redundancy.&lt;/P&gt;&lt;P&gt;However, when that server crashed, IA completely failed and did not work anymore.&amp;nbsp; Remote Access users could not be authenticated until that server was restarted.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do I need to specifically set "If you can't access this DC, use that DC instead" anywhere, to get this to work?&lt;/P&gt;&lt;P&gt;Isn't that the point of listing multiple DCs in the LDAP unit?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 19 May 2021 14:10:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Identity-Awareness-Could-not-connect-to-AD-server/m-p/118810#M82496</guid>
      <dc:creator>PointOfChecking</dc:creator>
      <dc:date>2021-05-19T14:10:59Z</dc:date>
    </item>
  </channel>
</rss>

