<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Mobile Access setup, failing to integrate AD in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-setup-failing-to-integrate-AD/m-p/195529#M4473</link>
    <description>&lt;P&gt;Thanks, will check it out!&lt;/P&gt;</description>
    <pubDate>Wed, 18 Oct 2023 11:54:22 GMT</pubDate>
    <dc:creator>796570686578</dc:creator>
    <dc:date>2023-10-18T11:54:22Z</dc:date>
    <item>
      <title>Mobile Access setup, failing to integrate AD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-setup-failing-to-integrate-AD/m-p/195518#M4471</link>
      <description>&lt;P&gt;Hey everyone,&lt;/P&gt;&lt;P&gt;In a Lab environment I am trying to setup Mobile Access with AD Integration so I can test some configurations for a customer.&lt;/P&gt;&lt;P&gt;I setup a Gateway and Management Server using R81.20 and Jumbo Hotfix Take 26. Also I have an AD Controller on a different subnet. ( See my professional drawing of the topology in the attachments)&lt;/P&gt;&lt;P&gt;Mgmt: 172.16.101.10&lt;/P&gt;&lt;P&gt;FW: 172.16.101.30 &amp;amp; 172.16.102.30&lt;/P&gt;&lt;P&gt;DC: 172.16.102.100&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now to the actual problem:&lt;/P&gt;&lt;P&gt;I open the Firewall Object in Smart Console -&amp;gt; check "Mobile Access" -&amp;gt; select allowed clients to connect -&amp;gt; Active Directory Integration.&lt;/P&gt;&lt;P&gt;Now in the Active directory Integration I specify all the required parameters&lt;/P&gt;&lt;P&gt;- Domain Name&lt;/P&gt;&lt;P&gt;- Username&lt;/P&gt;&lt;P&gt;- Password&lt;/P&gt;&lt;P&gt;- Domain Controller&lt;/P&gt;&lt;P&gt;and then hit Connect. After some time I get an error message saying " Smart Dashboard could not connect - Could not communicate with server".&lt;/P&gt;&lt;P&gt;Now I have obviously checked the following:&lt;/P&gt;&lt;P&gt;- Configured Firewall Rule to allow any traffic to and from DC&lt;/P&gt;&lt;P&gt;- Necessary routes are in place&lt;/P&gt;&lt;P&gt;- No NAT rules&lt;/P&gt;&lt;P&gt;- I can ping between MGMT and DC without any issues&lt;/P&gt;&lt;P&gt;- No relevant Logs in Smart Dashboard&lt;/P&gt;&lt;P&gt;- Performed a tcpdump on the Management Server and the Firewall on all interfaces, there is not traffic to my DC(172.16.102.100) at all?!?!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now what is interesting, I configured an LDAP Account Unit Object for the same DC and it works without any issues...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now I am pretty much at a loss on why it is not working.. Do you have any ideas on what my issue might be?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 10:28:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-setup-failing-to-integrate-AD/m-p/195518#M4471</guid>
      <dc:creator>796570686578</dc:creator>
      <dc:date>2023-10-18T10:28:26Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access setup, failing to integrate AD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-setup-failing-to-integrate-AD/m-p/195521#M4472</link>
      <description>&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk113747" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk113747: How to troubleshoot Identity Awareness AD Query &lt;STRONG&gt;connectivity&lt;/STRONG&gt; issues&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.checkpoint.com/results/sk/sk100406" target="_blank" rel="noopener"&gt;&lt;SPAN&gt;sk100406: How to use the 'test_ad_&lt;STRONG&gt;connectivity&lt;/STRONG&gt;' tool&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 10:42:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-setup-failing-to-integrate-AD/m-p/195521#M4472</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-10-18T10:42:45Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access setup, failing to integrate AD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-setup-failing-to-integrate-AD/m-p/195529#M4473</link>
      <description>&lt;P&gt;Thanks, will check it out!&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 11:54:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-setup-failing-to-integrate-AD/m-p/195529#M4473</guid>
      <dc:creator>796570686578</dc:creator>
      <dc:date>2023-10-18T11:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access setup, failing to integrate AD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-setup-failing-to-integrate-AD/m-p/195532#M4474</link>
      <description>&lt;P&gt;So I checked the SKs you mentioned.&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;test_ad_connectivity test -&amp;gt; Success&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;LI-CODE lang="markup"&gt;(
        :status (SUCCESS_LDAP_WMI)
        :err_msg ("ADLOG_SUCCESS;LDAP_SUCCESS")
        :ldap_status (LDAP_SUCCESS)
        :wmi_status (ADLOG_SUCCESS)
        :timestamp ("Wed Oct 18 14:09:57 2023")
)&lt;/LI-CODE&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;adlog a dc -&amp;gt; can't test this since I am not able to configure the DC for AD Query&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;ldapsearch -&amp;gt; Success &lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;I just don't understand why these tests work, why I can configure the Account Unit, but it does not work when configuring a Blade like Mobile Access or Identity Awareness...&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 18 Oct 2023 12:21:14 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-setup-failing-to-integrate-AD/m-p/195532#M4474</guid>
      <dc:creator>796570686578</dc:creator>
      <dc:date>2023-10-18T12:21:14Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access setup, failing to integrate AD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-setup-failing-to-integrate-AD/m-p/195906#M4475</link>
      <description>&lt;P&gt;Better contact TAC to get this resolved!&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 12:12:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-setup-failing-to-integrate-AD/m-p/195906#M4475</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2023-10-23T12:12:18Z</dc:date>
    </item>
    <item>
      <title>Re: Mobile Access setup, failing to integrate AD</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-setup-failing-to-integrate-AD/m-p/195916#M4476</link>
      <description>&lt;P&gt;I was able to get it to work. The VM of my Management Server and AD also had an Interface on a different Subnet which acted as a Management Interface. This was also the Primary IP of my Management Server and once I integrated AD via the IP on that Interface, it worked on the first try...&lt;/P&gt;</description>
      <pubDate>Mon, 23 Oct 2023 13:07:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/Mobile-Access-setup-failing-to-integrate-AD/m-p/195916#M4476</guid>
      <dc:creator>796570686578</dc:creator>
      <dc:date>2023-10-23T13:07:31Z</dc:date>
    </item>
  </channel>
</rss>

