<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Identity Collector in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239842#M40022</link>
    <description>&lt;P&gt;And when you click "fetch branches", what does it show?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Tue, 28 Jan 2025 14:30:14 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2025-01-28T14:30:14Z</dc:date>
    <item>
      <title>Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239815#M40014</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;I am trying to use IDC (Windows AD) with remote access VPN.&lt;/P&gt;
&lt;P&gt;IDC has green gateway and green AD server.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kort.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29463iEF2C7D319D2BD2FA/image-size/large?v=v2&amp;amp;px=999" role="button" title="kort.png" alt="kort.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kort.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29464i46EF9446D813BE26/image-size/large?v=v2&amp;amp;px=999" role="button" title="kort.png" alt="kort.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;Whe using Checkpoint Endpoint Security App on Windows machine it connects well if users are locally created on SMS, but if users are on AD it logs:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kort.png" style="width: 597px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29465i49F04D48620DBA6B/image-size/large?v=v2&amp;amp;px=999" role="button" title="kort.png" alt="kort.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;that user is created on AD and added in a policy rule using an Access role:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kort.png" style="width: 797px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29467i38168A931C3C3FE7/image-size/large?v=v2&amp;amp;px=999" role="button" title="kort.png" alt="kort.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kort.png" style="width: 736px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29468i7011C927E7C32AF7/image-size/large?v=v2&amp;amp;px=999" role="button" title="kort.png" alt="kort.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;On the remote access community under Participats user groups = all users&lt;/P&gt;
&lt;P&gt;Windows machine can reach SMS and gateway and vice versa.&lt;/P&gt;
&lt;P&gt;Running&amp;nbsp;&lt;STRONG&gt;pdp idc status&lt;/STRONG&gt;:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;pdp idc status
Identity Collector IP: 192.168.10.212
Identity Sources:
        No information about identity sources&lt;/LI-CODE&gt;
&lt;P&gt;and&amp;nbsp;&lt;STRONG&gt;cpstat identityServer -f idc&lt;/STRONG&gt;:&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;cpstat identityServer -f idc



Identity Collector Sources
-----------------------------------------------------------
|Type|Name|Host|Status|IDC IP|Events Recieved|Total Events|
-----------------------------------------------------------
-----------------------------------------------------------&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I think IDC is not sending events to the gateway but why?&lt;/P&gt;
&lt;P&gt;What do I miss here?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 13:00:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239815#M40014</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2025-01-28T13:00:59Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239819#M40015</link>
      <description>&lt;P&gt;Did you follow &lt;A href="https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Clients-AG/Identity-Collector-Requirements.htm?tocpath=Identity%20Collector%7C_____1" target="_blank"&gt;https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Clients-AG/Identity-Collector-Requirements.htm?tocpath=Identity%20Collector%7C_____1&lt;/A&gt; ?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 13:31:49 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239819#M40015</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-01-28T13:31:49Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239820#M40016</link>
      <description>&lt;P&gt;Do you have proper LDAP account unit configured? The reason I asked that question is what Phoneboy said in a different post couple of years back:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Identity&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN class="mark2xja33d9i" data-markjs="true" data-ogac="" data-ogab="" data-ogsc="" data-ogsb=""&gt;Collector&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;changes how the gateways acquire users (using Security Logs instead of WMI).&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;The actual groups are still pulled the same way as with ADQuery: via LDAP queries from the relevant gateways.&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Which means you should verify the information needed to perform these lookups is correct:&amp;nbsp;&lt;/SPAN&gt;&lt;A title="https://support.checkpoint.com/results/sk/sk180392" href="https://support.checkpoint.com/results/sk/sk180392" target="_blank" rel="noopener noreferrer" data-auth="NotApplicable" data-linkindex="2" data-ogsc=""&gt;https://support.checkpoint.com/results/sk/sk180392&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 13:40:42 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239820#M40016</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-28T13:40:42Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239829#M40017</link>
      <description>&lt;P&gt;Running ldapsearch command shows that LDAP account Unit is correctly configured as of my knowledge!&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt; ldapsearch -h 192.168.10.212 -p 389 -D "CN=CP-User,CN=Users,DC=alpha,DC=cp" -w Admin123 -b "DC=alpha,D
C=cp" "(sAMAccountName=CP-User)"
CN=CP-User,CN=Users,DC=alpha,DC=cp
objectClass=top
objectClass=person
objectClass=organizationalPerson
objectClass=user
cn=CP-User
givenName=CP-User
distinguishedName=CN=CP-User,CN=Users,DC=alpha,DC=cp
instanceType=4
whenCreated=20250121161255.0Z
whenChanged=20250121161349.0Z
displayName=CP-User
uSNCreated=36933
memberOf=CN=Event Log Readers,CN=Builtin,DC=alpha,DC=cp
memberOf=CN=Distributed COM Users,CN=Builtin,DC=alpha,DC=cp
uSNChanged=36945
name=CP-User
objectGUID=NOT ASCII
userAccountControl=66048
badPwdCount=0
codePage=0
countryCode=0
badPasswordTime=0
lastLogoff=0
lastLogon=133825288336186747
pwdLastSet=133819495752215514
primaryGroupID=513
objectSid=NOT ASCII
accountExpires=9223372036854775807
logonCount=6
sAMAccountName=CP-User
sAMAccountType=805306368
userPrincipalName=CP-User@alpha.cp
objectCategory=CN=Person,CN=Schema,CN=Configuration,DC=alpha,DC=cp
dSCorePropagationData=16010101000000.0Z
lastLogonTimestamp=133819496297529642
1 match&lt;/LI-CODE&gt;</description>
      <pubDate>Tue, 28 Jan 2025 14:07:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239829#M40017</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2025-01-28T14:07:06Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239830#M40018</link>
      <description>&lt;P&gt;i did follow that, plus and firewall on windows machine is disabled&lt;/P&gt;
&lt;P&gt;IDC is installed on same machine as AD!? does that create problems?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 14:09:38 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239830#M40018</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2025-01-28T14:09:38Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239831#M40019</link>
      <description>&lt;P&gt;Yea, that looks good to me. Just wondering, from the smart console, unless its S1C mgmt instance, if its on prem, can you fetch branches okay from the ldap unit?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 14:10:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239831#M40019</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-28T14:10:00Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239841#M40021</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kort.png" style="width: 550px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/29471i620412384B6C11ED/image-size/large?v=v2&amp;amp;px=999" role="button" title="kort.png" alt="kort.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 14:28:40 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239841#M40021</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2025-01-28T14:28:40Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239842#M40022</link>
      <description>&lt;P&gt;And when you click "fetch branches", what does it show?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 14:30:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239842#M40022</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-28T14:30:14Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239843#M40023</link>
      <description>&lt;P&gt;Not at all - it is rather very usual to do that, as you need a Win Server for IC. Why not contact TAC ? Issues like yours are usually some config glitche(s) that can be resolved in a RAS quickly.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 14:31:29 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239843#M40023</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2025-01-28T14:31:29Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239844#M40024</link>
      <description>&lt;P&gt;That would not create any issues, most clients I saw install IDC, they did on same machine, as long as communication is there.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 14:33:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239844#M40024</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-28T14:33:22Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239846#M40025</link>
      <description>&lt;P&gt;Do you use LDAPs or Simple LDAP on port 389?&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 14:35:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239846#M40025</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2025-01-28T14:35:33Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239848#M40027</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;I have always deployed IDC on the AD server without problems. However once it did not work and TAC told us that is not recommended, we should install IDC on a different windows server. Tried moving the IDC to a different server and issue was fixed, so you can try and check.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Regards&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 14:40:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239848#M40027</guid>
      <dc:creator>RS_Daniel</dc:creator>
      <dc:date>2025-01-28T14:40:16Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239849#M40028</link>
      <description>&lt;P&gt;This is a lab so yes 389 is used.&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 14:40:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239849#M40028</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2025-01-28T14:40:45Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239850#M40029</link>
      <description>&lt;P&gt;it shows the same: DC=alpha,DC=cp&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 14:41:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239850#M40029</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2025-01-28T14:41:26Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239858#M40031</link>
      <description>&lt;P&gt;I will try that!&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 14:52:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239858#M40031</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2025-01-28T14:52:13Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239860#M40032</link>
      <description>&lt;P&gt;Its not bad idea at all. Personally, I always seee customers do it on same machine and works fine.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 14:59:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239860#M40032</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-28T14:59:07Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239871#M40035</link>
      <description>&lt;P&gt;I have now tried on other server, and i get the same result:&lt;/P&gt;
&lt;LI-CODE lang="ruby"&gt; pdp idc status
Identity Collector IP: 192.168.10.212
Identity Sources:
        No information about identity sources

Identity Collector IP: 192.168.10.187
Identity Sources:
        No information about identity sources&lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;The new server with no AD is .187&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 15:44:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239871#M40035</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2025-01-28T15:44:43Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239873#M40036</link>
      <description>&lt;P&gt;And you also disabled windows fw on that machine as well?&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 15:47:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239873#M40036</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-28T15:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239874#M40037</link>
      <description>&lt;P&gt;Yes&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 15:49:12 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239874#M40037</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2025-01-28T15:49:12Z</dc:date>
    </item>
    <item>
      <title>Re: Identity Collector</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239876#M40038</link>
      <description>&lt;P&gt;I would do below.&lt;/P&gt;
&lt;P&gt;&lt;A href="https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Clients-AG/Identity-Collector-Debug.htm#:~:text=In%20most%20cases%2C%20the%20debugging,enabled%20on%20the%20service%20side.&amp;amp;text=The%20default%20debug%20level%20is,of%20logs%20in%20Identity%20Collector" target="_blank"&gt;https://sc1.checkpoint.com/documents/Identity_Awareness_Clients_Admin_Guide/Content/Topics-IA-Clients-AG/Identity-Collector-Debug.htm#:~:text=In%20most%20cases%2C%20the%20debugging,enabled%20on%20the%20service%20side.&amp;amp;text=The%20default%20debug%20level%20is,of%20logs%20in%20Identity%20Collector&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;Also, make sure you have latest version of IC as well:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk113021" target="_blank"&gt;sk113021 - Identity Collector fails to connect / add / edit a Security Gateway&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;I see customer I worked with few months ago had same issue and turned out to be certificate problem, but not sure which one exactly : - (&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 28 Jan 2025 15:56:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Identity-Collector/m-p/239876#M40038</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2025-01-28T15:56:45Z</dc:date>
    </item>
  </channel>
</rss>

