<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AD Query in Remote Access connection in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-Query-in-Remote-Access-connection/m-p/114459#M8938</link>
    <description>&lt;P&gt;We migrate from R80.30 to R80.40. In R80.30 Remote Access uses AD Query information, now the information is not processed.&lt;/P&gt;&lt;P&gt;The AD Query is working fine for the other contexts, but it's not applied to VPN connection.&lt;/P&gt;&lt;P&gt;In PDPd and PEPd&amp;nbsp;logs I can see the AD connection for the machine in the VPN, but I think it's not processed by the identity Awareness.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;EM&gt;[25387 4059584320]@CPFW01[24 Mar 9:15:20] [TRACKER]: #40148 -&amp;gt; INCOMING -&amp;gt; ADQUERY_ASSOCIATION -&amp;gt; &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Association&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;ip: 10.18.172.35&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;user: &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;machine: d580-55931&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;domain: interno.trt18.jus.br&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;reason: 0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;In the PDPd log I found this:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;[25387 4059584320]@CPFW01[24 Mar 9:15:20] [SESSION_UTILS (TD::Events)] pdp::PDPSessionConciliation::shouldOverrideSuperSessionByPriority: existing super session 6bd521f4 office mode IP score (1) &amp;gt; new association office mode IP score (0) - reject new association&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Is there a way for identity awareness to use AD Query Data in Remote Access connection?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
    <pubDate>Wed, 24 Mar 2021 13:14:28 GMT</pubDate>
    <dc:creator>saulosouza</dc:creator>
    <dc:date>2021-03-24T13:14:28Z</dc:date>
    <item>
      <title>AD Query in Remote Access connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-Query-in-Remote-Access-connection/m-p/114459#M8938</link>
      <description>&lt;P&gt;We migrate from R80.30 to R80.40. In R80.30 Remote Access uses AD Query information, now the information is not processed.&lt;/P&gt;&lt;P&gt;The AD Query is working fine for the other contexts, but it's not applied to VPN connection.&lt;/P&gt;&lt;P&gt;In PDPd and PEPd&amp;nbsp;logs I can see the AD connection for the machine in the VPN, but I think it's not processed by the identity Awareness.&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;&lt;EM&gt;[25387 4059584320]@CPFW01[24 Mar 9:15:20] [TRACKER]: #40148 -&amp;gt; INCOMING -&amp;gt; ADQUERY_ASSOCIATION -&amp;gt; &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;Association&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;ip: 10.18.172.35&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;user: &lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;machine: d580-55931&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;domain: interno.trt18.jus.br&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;reason: 0&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;In the PDPd log I found this:&lt;/P&gt;&lt;P class="lia-indent-padding-left-30px"&gt;[25387 4059584320]@CPFW01[24 Mar 9:15:20] [SESSION_UTILS (TD::Events)] pdp::PDPSessionConciliation::shouldOverrideSuperSessionByPriority: existing super session 6bd521f4 office mode IP score (1) &amp;gt; new association office mode IP score (0) - reject new association&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Is there a way for identity awareness to use AD Query Data in Remote Access connection?&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 13:14:28 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-Query-in-Remote-Access-connection/m-p/114459#M8938</guid>
      <dc:creator>saulosouza</dc:creator>
      <dc:date>2021-03-24T13:14:28Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query in Remote Access connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-Query-in-Remote-Access-connection/m-p/114483#M8939</link>
      <description>&lt;P&gt;Remote Access clients don't require AD Query because we're authenticating the user directly.&lt;BR /&gt;However, it needs to be enabled as an identity source on the gateway object (it's not by default).&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 16:18:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-Query-in-Remote-Access-connection/m-p/114483#M8939</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-24T16:18:10Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query in Remote Access connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-Query-in-Remote-Access-connection/m-p/114484#M8940</link>
      <description>&lt;P&gt;Thank you, I have already enabled Remote access as a source. The login is fine, what I want is the information of AD query, when is available.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 16:27:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-Query-in-Remote-Access-connection/m-p/114484#M8940</guid>
      <dc:creator>saulosouza</dc:creator>
      <dc:date>2021-03-24T16:27:00Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query in Remote Access connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-Query-in-Remote-Access-connection/m-p/114663#M8941</link>
      <description>&lt;P&gt;What’s happening is explained here:&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk146835&amp;amp;partition=Basic&amp;amp;product=Identity" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk146835&amp;amp;partition=Basic&amp;amp;product=Identity&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;Specifically “&lt;SPAN&gt;Some identity sources such as Identity Agent, Terminal Server, Captive Portal, and Remote Access VPN &lt;/SPAN&gt;&lt;STRONG&gt;cannot be appended&lt;/STRONG&gt;&lt;SPAN&gt; to others. In these cases, the conciliation decision is only &lt;/SPAN&gt;&lt;STRONG&gt;override&lt;/STRONG&gt;&lt;SPAN&gt; or &lt;/SPAN&gt;&lt;STRONG&gt;reject&lt;/STRONG&gt;&lt;SPAN&gt;.”&lt;BR /&gt;Note this is new behavior as of R80.40.&lt;BR /&gt;Not 100% sure you can change this, a TAC case will be required.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 25 Mar 2021 21:49:39 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-Query-in-Remote-Access-connection/m-p/114663#M8941</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2021-03-25T21:49:39Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query in Remote Access connection</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-Query-in-Remote-Access-connection/m-p/225876#M8942</link>
      <description>&lt;P&gt;Hi PhoneBoy,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Old post but I am in a similar situation. Then do you mean that Remote Access clients authenticate directly against the AD and not through AD Query which uses WMI to look into&amp;nbsp;&lt;SPAN class="mc-variable Vars_Other.tp_active_directory variable"&gt;Active Directory&lt;/SPAN&gt;&lt;SPAN&gt;&amp;nbsp;Security Event Logs?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regards,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Julián&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 06 Sep 2024 12:23:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/AD-Query-in-Remote-Access-connection/m-p/225876#M8942</guid>
      <dc:creator>fjulianom</dc:creator>
      <dc:date>2024-09-06T12:23:46Z</dc:date>
    </item>
  </channel>
</rss>

