<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: SMB integrate AD issue in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-integrate-AD-issue/m-p/223881#M11233</link>
    <description>&lt;P&gt;Is there a way to force the sync with AD to occur?&lt;BR /&gt;Because it seems like that's the issue here...that a new group was created and it is not available on the appliance.&lt;/P&gt;</description>
    <pubDate>Fri, 16 Aug 2024 18:07:36 GMT</pubDate>
    <dc:creator>PhoneBoy</dc:creator>
    <dc:date>2024-08-16T18:07:36Z</dc:date>
    <item>
      <title>SMB integrate AD issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-integrate-AD-issue/m-p/223705#M11226</link>
      <description>&lt;P&gt;Hi there,&lt;/P&gt;&lt;P&gt;I am currently encountering an AD issue at a client’s site. I would like to know if anyone else has experienced the following:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;I integrated SMB with AD and added a user account in AD with domain admin and schema admin permissions.&lt;/LI&gt;&lt;LI&gt;I created a new group in AD.&lt;/LI&gt;&lt;LI&gt;I added a remote access user in SMB, but the newly created group in AD cannot be found. Interestingly, existing groups can be found.&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;It seems like an AD issue. Are there any additional settings required in AD?&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 03:20:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-integrate-AD-issue/m-p/223705#M11226</guid>
      <dc:creator>patrick2</dc:creator>
      <dc:date>2024-08-15T03:20:24Z</dc:date>
    </item>
    <item>
      <title>Re: SMB integrate AD issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-integrate-AD-issue/m-p/223719#M11227</link>
      <description>&lt;P&gt;Hi &lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/114206"&gt;@patrick2&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To get closer to the issue:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Do you use Identity Collecor, or how do you connect the SMB to the AD?&lt;/LI&gt;
&lt;/UL&gt;
&lt;P&gt;If you want to browse the whole tree in the Access Role object, you can find all ot the groups, except the newly created one?&lt;/P&gt;
&lt;P&gt;Here:&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="2024-08-15 09_40_13-Cloud Demo Server [ID_531263718]-R81.20-SmartConsole.png" style="width: 640px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/27248i9CDC86859DBF0AA7/image-dimensions/640x375?v=v2" width="640" height="375" role="button" title="2024-08-15 09_40_13-Cloud Demo Server [ID_531263718]-R81.20-SmartConsole.png" alt="2024-08-15 09_40_13-Cloud Demo Server [ID_531263718]-R81.20-SmartConsole.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Ad Query is not a supported way as earlier was. &lt;A href="https://support.checkpoint.com/results/sk/sk60301" target="_self"&gt;&lt;SPAN&gt;Check Point recommends to use Identity Collector as the Identity Source instead of AD Query&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;There is an sk:&amp;nbsp;&lt;A href="https://support.checkpoint.com/results/sk/sk106133" target="_blank"&gt;https://support.checkpoint.com/results/sk/sk106133&lt;/A&gt;&amp;nbsp;maybe it can help to start the investigation way.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 07:50:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-integrate-AD-issue/m-p/223719#M11227</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-15T07:50:08Z</dc:date>
    </item>
    <item>
      <title>Re: SMB integrate AD issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-integrate-AD-issue/m-p/223784#M11228</link>
      <description>&lt;P&gt;What firmware version?&lt;BR /&gt;Sounds like a caching issue.&amp;nbsp;&lt;BR /&gt;This may require a TAC case.&lt;/P&gt;</description>
      <pubDate>Thu, 15 Aug 2024 17:27:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-integrate-AD-issue/m-p/223784#M11228</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-15T17:27:59Z</dc:date>
    </item>
    <item>
      <title>Re: SMB integrate AD issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-integrate-AD-issue/m-p/223820#M11229</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Do you use centrally or locally managed SMB?&lt;/P&gt;
&lt;P&gt;Please note that, by default, AD groups are automatically synced every 24 hours.&lt;/P&gt;
&lt;P&gt;Thanks,&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp;Dafna&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 05:13:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-integrate-AD-issue/m-p/223820#M11229</guid>
      <dc:creator>Dafna</dc:creator>
      <dc:date>2024-08-16T05:13:51Z</dc:date>
    </item>
    <item>
      <title>Re: SMB integrate AD issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-integrate-AD-issue/m-p/223821#M11230</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;SPAN&gt;Akos&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;1.I use Active Directory Queries in SMB to integrate AD and do not use the Identity Collector function.&lt;/P&gt;&lt;P&gt;2.Yes, I can find all the groups except for the newly created ones.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 05:14:07 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-integrate-AD-issue/m-p/223821#M11230</guid>
      <dc:creator>patrick2</dc:creator>
      <dc:date>2024-08-16T05:14:07Z</dc:date>
    </item>
    <item>
      <title>Re: SMB integrate AD issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-integrate-AD-issue/m-p/223822#M11231</link>
      <description>&lt;P&gt;Hi PhoneBoy&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;R81.10.10 (996002993)&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 05:14:43 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-integrate-AD-issue/m-p/223822#M11231</guid>
      <dc:creator>patrick2</dc:creator>
      <dc:date>2024-08-16T05:14:43Z</dc:date>
    </item>
    <item>
      <title>Re: SMB integrate AD issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-integrate-AD-issue/m-p/223881#M11233</link>
      <description>&lt;P&gt;Is there a way to force the sync with AD to occur?&lt;BR /&gt;Because it seems like that's the issue here...that a new group was created and it is not available on the appliance.&lt;/P&gt;</description>
      <pubDate>Fri, 16 Aug 2024 18:07:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-integrate-AD-issue/m-p/223881#M11233</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2024-08-16T18:07:36Z</dc:date>
    </item>
    <item>
      <title>Re: SMB integrate AD issue</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-integrate-AD-issue/m-p/223900#M11239</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/7"&gt;@PhoneBoy&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The &lt;EM&gt;#pdp update all&lt;/EM&gt; command maybe helps&lt;/P&gt;
&lt;P&gt;Command: root-&amp;gt;update&lt;/P&gt;
&lt;P&gt;Available options:&lt;BR /&gt;&lt;STRONG&gt;all - recalculate all users and machines group membership&lt;/STRONG&gt;&lt;BR /&gt;specific - recalculate group membership for a user/machine&lt;BR /&gt;refetch_interval - LDAP user info refetch interval&lt;BR /&gt;update_rate - the max number of sessions updated within a minute&lt;/P&gt;
&lt;P&gt;Akos&lt;/P&gt;</description>
      <pubDate>Sat, 17 Aug 2024 09:30:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/SMB-integrate-AD-issue/m-p/223900#M11239</guid>
      <dc:creator>AkosBakos</dc:creator>
      <dc:date>2024-08-17T09:30:19Z</dc:date>
    </item>
  </channel>
</rss>

