- Products
- Learn
- Local User Groups
- Partners
- More
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
Join our TechTalk: Malware 2021 to Present Day
Building a Preventative Cyber Program
Be a CloudMate!
Check out our cloud security exclusive space!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Greetings all !
I use a security group in my AD to pinpoint workstations eligible for FDE. Thus I have rule, where an AD security group is the dynamic "target" - This has worked out perfectly so far.
Alas (otherwise i wouldnt be writing this post) the "link" seems broken to the AD security group.
I can see worksstations in my AD - but when looking into the deployment rules - the reflection of the group are missing several members .
As i understand - using security group for deployment secures dynamic updates - where virtual groups lack that ability.
I have other rules depending on the AD connection - whích works fine - but those are based on virtual groups instead of Security groups.
I have tried removing said group and reapply it - to no avail.
I feel confident the connection between server and AD is at least partial working - since i can browse my AD from endpoint server.
Hope this makes sense !
Any ideas?
Kind regards
Peter
SOLVED !!
So - found out my ad scanners was "frozen" ... not progressing - but neither failing (the Gui suggested the scan was in progress - but no progress was to be seen)
After contacting suppport - I ended up with the below suggestion.
1. Enter SSH to the Endpoint Management Server.
2. cpstop
3. cd $UEPMDIR/engine/uepm-jms-data
4. rm *
5. cpstart
Which did the trick - my scanners once again pulls data every 5 minutes - JOY !!
kind regards
Peter
I would suggest to contact TAC to resolve this issue !
Do you have an AD Scanner running?
Secondly, the AD Scanner only checks in a frequency of 120 Minutes (TAC told me there is no shorter time span possible) for any changes in AD and syncs that into the CP DB.
This means that if you change a AD security group and add a Client - it can be up to 120min Delay in worst cases until CP notices that ..
BR ME
SOLVED !!
So - found out my ad scanners was "frozen" ... not progressing - but neither failing (the Gui suggested the scan was in progress - but no progress was to be seen)
After contacting suppport - I ended up with the below suggestion.
1. Enter SSH to the Endpoint Management Server.
2. cpstop
3. cd $UEPMDIR/engine/uepm-jms-data
4. rm *
5. cpstart
Which did the trick - my scanners once again pulls data every 5 minutes - JOY !!
kind regards
Peter
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY