<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IA VSX authentication issue in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/IA-VSX-authentication-issue/m-p/26380#M5362</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;General theory:&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;Identity collector is “eating” event viewer messages written in AD server.&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;Firewall is still required to check if the user is in the proper group or it’s disabled. Those checks are&amp;nbsp; ldap traffic from firewall to DC.&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;Customer moved from clusterXL to VSX.&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;Normal firewall to ldap traffic pass on VS0. Here VS0 didn’t have access to DC. Only VS1 had access.&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;In order to solve this problem under VS config -&amp;gt; Other -&amp;gt; legacy configuration -&amp;gt; authentication server accessibility&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;&lt;STRONG&gt;Change the default from shared to private.&lt;/STRONG&gt;&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;Credit goes to Kobi Kagan from israeli support team.&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;See attached screenshot&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;Aner.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 27 May 2018 16:09:19 GMT</pubDate>
    <dc:creator>aner_sagi</dc:creator>
    <dc:date>2018-05-27T16:09:19Z</dc:date>
    <item>
      <title>IA VSX authentication issue</title>
      <link>https://community.checkpoint.com/t5/General-Topics/IA-VSX-authentication-issue/m-p/26380#M5362</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;General theory:&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;Identity collector is “eating” event viewer messages written in AD server.&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;Firewall is still required to check if the user is in the proper group or it’s disabled. Those checks are&amp;nbsp; ldap traffic from firewall to DC.&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;Customer moved from clusterXL to VSX.&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;Normal firewall to ldap traffic pass on VS0. Here VS0 didn’t have access to DC. Only VS1 had access.&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;In order to solve this problem under VS config -&amp;gt; Other -&amp;gt; legacy configuration -&amp;gt; authentication server accessibility&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;&lt;STRONG&gt;Change the default from shared to private.&lt;/STRONG&gt;&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;Credit goes to Kobi Kagan from israeli support team.&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;See attached screenshot&lt;/P&gt;&lt;P dir="ltr" style="margin: 0cm 0cm 0.0001pt; font-size: 12pt; color: #000000; text-indent: 0px;"&gt;Aner.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 27 May 2018 16:09:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/IA-VSX-authentication-issue/m-p/26380#M5362</guid>
      <dc:creator>aner_sagi</dc:creator>
      <dc:date>2018-05-27T16:09:19Z</dc:date>
    </item>
  </channel>
</rss>

