<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: linux authetication and ADQuery in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/linux-authetication-and-ADQuery/m-p/117355#M21855</link>
    <description>&lt;P&gt;Yes, to me it sounded logical, however out of the box it didn't worked. I am not very good in this subject hence the question if anyone has it working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My impression that linux would generate event with different ID, while ADQuery tracks only specific events&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sk60501 -&amp;nbsp;&lt;/SPAN&gt;The necessary events are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Windows 2003 servers: 672, 673, 674&lt;/LI&gt;
&lt;LI&gt;Windows 2008 servers: 4624, 4768, 4769, 4770.&lt;/LI&gt;
&lt;LI&gt;Windows 2012 servers:&amp;nbsp;4624*, 4768*, 4769*, 4770*&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 30 Apr 2021 13:18:52 GMT</pubDate>
    <dc:creator>abihsot__</dc:creator>
    <dc:date>2021-04-30T13:18:52Z</dc:date>
    <item>
      <title>linux authetication and ADQuery</title>
      <link>https://community.checkpoint.com/t5/General-Topics/linux-authetication-and-ADQuery/m-p/117313#M21851</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does anyone have such setup, where user authenticates to linux machine with AD credentials and identities are picked up by ADQuery?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 07:01:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/linux-authetication-and-ADQuery/m-p/117313#M21851</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2021-04-30T07:01:29Z</dc:date>
    </item>
    <item>
      <title>Re: linux authetication and ADQuery</title>
      <link>https://community.checkpoint.com/t5/General-Topics/linux-authetication-and-ADQuery/m-p/117352#M21853</link>
      <description>&lt;P&gt;Logically this should work the same as a Windows machine. If your Linux machines are authenticating to AD, ADQ is a registered DCOM connection from the GW's participating in IA to your AD servers. It has nothing to do with linux. Via that DCOM connection AD will push all logins/logouts to your GW to compile the local database to match against the access role you would use in policy.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This should be explained further in&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk60301#How%20AD%20Query%20(ADQ)%20works" target="_self"&gt;&lt;SPAN&gt;sk60301&lt;/SPAN&gt;&lt;/A&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 12:54:15 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/linux-authetication-and-ADQuery/m-p/117352#M21853</guid>
      <dc:creator>Mike_A</dc:creator>
      <dc:date>2021-04-30T12:54:15Z</dc:date>
    </item>
    <item>
      <title>Re: linux authetication and ADQuery</title>
      <link>https://community.checkpoint.com/t5/General-Topics/linux-authetication-and-ADQuery/m-p/117355#M21855</link>
      <description>&lt;P&gt;Yes, to me it sounded logical, however out of the box it didn't worked. I am not very good in this subject hence the question if anyone has it working.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;My impression that linux would generate event with different ID, while ADQuery tracks only specific events&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;sk60501 -&amp;nbsp;&lt;/SPAN&gt;The necessary events are:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Windows 2003 servers: 672, 673, 674&lt;/LI&gt;
&lt;LI&gt;Windows 2008 servers: 4624, 4768, 4769, 4770.&lt;/LI&gt;
&lt;LI&gt;Windows 2012 servers:&amp;nbsp;4624*, 4768*, 4769*, 4770*&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 30 Apr 2021 13:18:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/linux-authetication-and-ADQuery/m-p/117355#M21855</guid>
      <dc:creator>abihsot__</dc:creator>
      <dc:date>2021-04-30T13:18:52Z</dc:date>
    </item>
  </channel>
</rss>

