<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Domain 'nt service' in alert mail in Firewall &amp; Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/115666#M84809</link>
    <description>&lt;P&gt;Hi Martijin&lt;/P&gt;&lt;P&gt;What was the solution here? I'm having the same issue with R80.40. Thanks&lt;/P&gt;&lt;P&gt;Grass&lt;/P&gt;</description>
    <pubDate>Fri, 09 Apr 2021 10:55:07 GMT</pubDate>
    <dc:creator>GrassF</dc:creator>
    <dc:date>2021-04-09T10:55:07Z</dc:date>
    <item>
      <title>Domain 'nt service' in alert mail</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/58890#M84802</link>
      <description>&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;One of our customers is using the Terminal Server agent for Citrix and is seeing the following alerts in the logging (and mail).&lt;/P&gt;&lt;P&gt;&lt;EM&gt;HeaderDateHour: 22Jun2019 5:32:13; ContentVersion: 5; HighLevelLogKey: N/A; Uuid: {0x0,0x0,0x0,0x0}; SequenceNum: 32; Action: ctl; Origin: XXXXXXX_XXXXXXX; IfDir: &amp;gt;; InterfaceName: N/A; &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Alert: mail; OriginSicName: CN=XXXXXXX_XXXXXXX,O=XXXXXXXX.fake.domain.grq7vi; OriginSicName: CN=XXXXXXX_XXXXXXX,O=XXXXXXX.fake.domain.grq7vi; HighLevelLogKey: 18446744073709551615; &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;status: Bad configuration; ctrl_category: Configuration Status; description: Failed to get users groups for the domain.(+)Verify that this domain name is configured in your LDAP Account Unit.(+)Domain: nt service; &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;severity: Critical; ProductName: Identity Awareness; ProductFamily: Network;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;Identity Awareness is configured as described in the admin guide and seems to be working. But where does this alert coming from and why is Check Point seeing the 'nt service' domain? This is not configured in the Check Point configuration.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 11:12:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/58890#M84802</guid>
      <dc:creator>Martijn</dc:creator>
      <dc:date>2019-07-24T11:12:27Z</dc:date>
    </item>
    <item>
      <title>Re: Domain 'nt service' in alert mail</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/59065#M84803</link>
      <description>It looks like the agent is picking up a user called "NT Domain" for some reason and it can't be looked up via LDAP.&lt;BR /&gt;Might be worth adding that to the list of exclusions in Identity Awareness.</description>
      <pubDate>Sat, 27 Jul 2019 00:32:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/59065#M84803</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-07-27T00:32:03Z</dc:date>
    </item>
    <item>
      <title>Re: Domain 'nt service' in alert mail</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/59129#M84804</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;We are not using AD Query. Just the Identity Awareness agent on computers and terminal servers.&lt;/P&gt;&lt;P&gt;Not sure how to exclude accounts with Identity Awareness agents.&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Martijn&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 06:16:30 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/59129#M84804</guid>
      <dc:creator>MvdGraaf</dc:creator>
      <dc:date>2019-07-29T06:16:30Z</dc:date>
    </item>
    <item>
      <title>Re: Domain 'nt service' in alert mail</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/59130#M84805</link>
      <description>&lt;P&gt;With the AD Query you can exclude user, but not with the (Terminal Server) Identity Agent. Or is there still a way to exclude users?&lt;/P&gt;</description>
      <pubDate>Mon, 29 Jul 2019 06:28:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/59130#M84805</guid>
      <dc:creator>Piet_vd_Maas_2</dc:creator>
      <dc:date>2019-07-29T06:28:37Z</dc:date>
    </item>
    <item>
      <title>Re: Domain 'nt service' in alert mail</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/59252#M84806</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;shouldn't exclusions for identity agent work the same way as ADQuery?&lt;/P&gt;</description>
      <pubDate>Tue, 30 Jul 2019 15:34:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/59252#M84806</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-07-30T15:34:07Z</dc:date>
    </item>
    <item>
      <title>Re: Domain 'nt service' in alert mail</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/59313#M84807</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/3058"&gt;@Martijn&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The TS agent is monitoring all users logged in on the Citrix machine and sends them (in UPN format - user@domain) to the PDP gateway.&lt;/P&gt;
&lt;P&gt;My assumption is that a service account was logged into the Citrix machine and therefore was transferred to the gateway.&lt;/P&gt;
&lt;P&gt;The fact that this domain was not configured on Check Point side (which is right!) cause this error, as the authorization phase for this user fails.&lt;/P&gt;
&lt;P&gt;I suggest opening case with TAC, to verify this. You can also ask for fixed agent which allows excluding specific users to be sent to the PDP gateway.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;Royi.&lt;/P&gt;</description>
      <pubDate>Wed, 31 Jul 2019 07:16:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/59313#M84807</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2019-07-31T07:16:50Z</dc:date>
    </item>
    <item>
      <title>Re: Domain 'nt service' in alert mail</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/115665#M84808</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;what was the solution? I'm having the same issue. Thanks&lt;/P&gt;&lt;P&gt;Grass&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 10:53:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/115665#M84808</guid>
      <dc:creator>GrassF</dc:creator>
      <dc:date>2021-04-09T10:53:21Z</dc:date>
    </item>
    <item>
      <title>Re: Domain 'nt service' in alert mail</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/115666#M84809</link>
      <description>&lt;P&gt;Hi Martijin&lt;/P&gt;&lt;P&gt;What was the solution here? I'm having the same issue with R80.40. Thanks&lt;/P&gt;&lt;P&gt;Grass&lt;/P&gt;</description>
      <pubDate>Fri, 09 Apr 2021 10:55:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/115666#M84809</guid>
      <dc:creator>GrassF</dc:creator>
      <dc:date>2021-04-09T10:55:07Z</dc:date>
    </item>
    <item>
      <title>Re: Domain 'nt service' in alert mail</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/119466#M84810</link>
      <description>&lt;P&gt;We still get the same warnings. Also in R80.40.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HeaderDateHour: 26May2021 14:58:51&lt;BR /&gt;ContentVersion: 5&lt;BR /&gt;HighLevelLogKey: N/A&lt;BR /&gt;Uuid: {0x0,0x0,0x0,0x0}&lt;BR /&gt;SequenceNum: 122&lt;BR /&gt;Action: ctl&lt;BR /&gt;Origin: XXXXXXXXX&lt;BR /&gt;IfDir: &amp;gt;&lt;BR /&gt;InterfaceName: N/A&lt;BR /&gt;Alert: mail&lt;BR /&gt;OriginSicName: CN=XXXXXXXXX&lt;BR /&gt;status: Bad configuration&lt;BR /&gt;ctrl_category: Configuration Status&lt;BR /&gt;description: Failed to get users groups for the domain.(+)Verify that this domain name is configured in your LDAP Account Unit.(+)Domain: nt service&lt;BR /&gt;severity: Critical&lt;BR /&gt;ProductName: Identity Awareness&lt;BR /&gt;ProductFamily: Network&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 13:45:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/119466#M84810</guid>
      <dc:creator>Piet_vd_Maas_2</dc:creator>
      <dc:date>2021-05-26T13:45:18Z</dc:date>
    </item>
    <item>
      <title>Re: Domain 'nt service' in alert mail</title>
      <link>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/119470#M84811</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/11069"&gt;@Piet_vd_Maas_2&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;This issue was already resolved, on the&amp;nbsp;&lt;STRONG&gt;client side&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;Please download and install the latest client from&amp;nbsp;sk134312 - "nt service" should be filtered out automatically.&lt;/P&gt;</description>
      <pubDate>Wed, 26 May 2021 14:23:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-Security-Management/Domain-nt-service-in-alert-mail/m-p/119470#M84811</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2021-05-26T14:23:22Z</dc:date>
    </item>
  </channel>
</rss>

