<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: [SOLVED] - Identity Agent Terminal Server - Users Not Authenticated in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/SOLVED-Identity-Agent-Terminal-Server-Users-Not-Authenticated/m-p/248341#M41499</link>
    <description>&lt;P&gt;Thanks for sharing!&lt;BR /&gt;Identity Agents do require trusting the certificate issued by the gateway (signed via the Internal CA).&lt;/P&gt;</description>
    <pubDate>Wed, 07 May 2025 13:45:11 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2025-05-07T13:45:11Z</dc:date>
    <item>
      <title>[SOLVED] - Identity Agent Terminal Server - Users Not Authenticated</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SOLVED-Identity-Agent-Terminal-Server-Users-Not-Authenticated/m-p/248279#M41486</link>
      <description>&lt;P class=""&gt;When installing &lt;STRONG&gt;Identity Agent Terminal Server v2&lt;/STRONG&gt; on the Terminal Server, the users identified by the agent show as &lt;STRONG&gt;"Not Authenticated."&lt;BR /&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IATS-users-Not-Authenticated.png" style="width: 939px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30420iB190A72568251895/image-size/large?v=v2&amp;amp;px=999" role="button" title="IATS-users-Not-Authenticated.png" alt="IATS-users-Not-Authenticated.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;P class=""&gt;Even though the &lt;STRONG&gt;Identity Agent Terminal Server&lt;/STRONG&gt; is correctly configured — with &lt;STRONG&gt;Identity Awareness Blade settings properly set&lt;/STRONG&gt;, firewall rules allowing communication with &lt;STRONG&gt;Active Directory&lt;/STRONG&gt;, the &lt;STRONG&gt;LDAP Account Unit&lt;/STRONG&gt; successfully connected, and &lt;STRONG&gt;Identity Awareness&lt;/STRONG&gt; successfully authenticating users via &lt;STRONG&gt;Identity Agent Full and Light, AD Query, and Browser Authentication&lt;/STRONG&gt; — users logged into the Terminal Server and authenticated in AD still face no apparent configuration issues.&lt;BR /&gt;&lt;BR /&gt;Identity Agent Terminal Server v2 connected, users identified&amp;nbsp;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="iats-connected.png" style="width: 971px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30425i2A2D338F80511072/image-size/large?v=v2&amp;amp;px=999" role="button" title="iats-connected.png" alt="iats-connected.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P class=""&gt;Running &lt;STRONG&gt;pdp monitor ip&lt;/STRONG&gt; does not show any &lt;STRONG&gt;LogUsername, Groups, or Roles&lt;/STRONG&gt; information.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pdp-monitor-ip-no-group-logusername-roles.png" style="width: 960px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30421iE2CF934BD698C2DD/image-size/large?v=v2&amp;amp;px=999" role="button" title="pdp-monitor-ip-no-group-logusername-roles.png" alt="pdp-monitor-ip-no-group-logusername-roles.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P class=""&gt;The &lt;STRONG&gt;SmartConsole displays the error:&lt;/STRONG&gt;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P class=""&gt;&lt;EM&gt;"An error was detected while trying to authenticate against the AD server. It may be a problem of bad configuration or connectivity."&lt;/EM&gt;&lt;BR /&gt;which creates confusion when troubleshooting, but leads to double-checking all configurations and ensuring the blade, rules, and LDAP Account Unit are correctly set up.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sm-iats-error-ad.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30423i9022872A20D849DE/image-size/large?v=v2&amp;amp;px=999" role="button" title="sm-iats-error-ad.png" alt="sm-iats-error-ad.png" /&gt;&lt;/span&gt;&lt;BR /&gt;When opening a case with &lt;STRONG&gt;TAC&lt;/STRONG&gt;, further investigation in the agent ts logs revealed the issue was related to the &lt;STRONG&gt;Certificate note trusted&lt;/STRONG&gt;&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="imagem (2).png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30424i4800DCA20530EE35/image-size/large?v=v2&amp;amp;px=999" role="button" title="imagem (2).png" alt="imagem (2).png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P class=""&gt;The firewall’s CA was being used correctly and was valid; however, when installing the &lt;STRONG&gt;Identity Agent Terminal Server&lt;/STRONG&gt;, upon connection, a prompt appears to &lt;STRONG&gt;trust the CA&lt;/STRONG&gt;. Before proceeding, it is necessary to &lt;STRONG&gt;install the CA into the Trusted Root Certification Authorities&lt;/STRONG&gt;.&lt;BR /&gt;&lt;BR /&gt;To view the CA, click &lt;STRONG&gt;“view certificate”&lt;/STRONG&gt; and install the CA &lt;STRONG&gt;&amp;nbsp;into the Trusted Root Certification Authorities&lt;/STRONG&gt;..&lt;/P&gt;&lt;P class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="install-ca-intalation-iats.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30426i3EEE120D549A2AD6/image-size/large?v=v2&amp;amp;px=999" role="button" title="install-ca-intalation-iats.png" alt="install-ca-intalation-iats.png" /&gt;&lt;/span&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;&lt;P class=""&gt;After that, the &lt;STRONG&gt;Identity Agent will authenticate successfully&lt;/STRONG&gt;.&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="solved-iats-users-authenticated.png" style="width: 935px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30427iF47A5CC91319E1DB/image-size/large?v=v2&amp;amp;px=999" role="button" title="solved-iats-users-authenticated.png" alt="solved-iats-users-authenticated.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P class=""&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="pdp-monitor-ip-showing-right-info.png" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/30428iD17FEA7292E426C3/image-size/large?v=v2&amp;amp;px=999" role="button" title="pdp-monitor-ip-showing-right-info.png" alt="pdp-monitor-ip-showing-right-info.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 May 2025 22:49:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SOLVED-Identity-Agent-Terminal-Server-Users-Not-Authenticated/m-p/248279#M41486</guid>
      <dc:creator>israelfds95</dc:creator>
      <dc:date>2025-05-06T22:49:52Z</dc:date>
    </item>
    <item>
      <title>Re: [SOLVED] - Identity Agent Terminal Server - Users Not Authenticated</title>
      <link>https://community.checkpoint.com/t5/General-Topics/SOLVED-Identity-Agent-Terminal-Server-Users-Not-Authenticated/m-p/248341#M41499</link>
      <description>&lt;P&gt;Thanks for sharing!&lt;BR /&gt;Identity Agents do require trusting the certificate issued by the gateway (signed via the Internal CA).&lt;/P&gt;</description>
      <pubDate>Wed, 07 May 2025 13:45:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/SOLVED-Identity-Agent-Terminal-Server-Users-Not-Authenticated/m-p/248341#M41499</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2025-05-07T13:45:11Z</dc:date>
    </item>
  </channel>
</rss>

