- CheckMates
- :
- Products
- :
- General Topics
- :
- Column "source user name" does not show anything i...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Column "source user name" does not show anything in Logview
Hello experts,
I am running R81 with blade Identity Awareness.
I enabled this blade , and connect successfully to LDAP server. Then I create access-role (get user from LDAP), and put it in the policy rule like this:
But when I log in into PC with above account (hai2), then I access to some-where. In the logview, (colum Source User Name) it does not show anything about my access-role
Please help me; thank all!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Two things spring to mind:
1. Can you confirm that the users are actually matching the policy you created
2. Make sure "hide user identities" is not enabled in SmartView
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Ruan,
Yes, I confirm I use exactly user name (which put in rule) to login PC (192.168.1.100).
"hide user identities" => I haven't known where it is, but when I show pdp like this : It said that no information found!
[Expert]# pdp monitor ip 192.168.1.100 ==>(IP of PC I use above)
no information was found for 192.168.1.100
I dont know why
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Apologies for responding for old thread, but I have same issue with a customer. I have no clue what to even look for, as IA blade is configured properly, all the settings were verified, but we are totally puzzled as to why "source user name" does not show anything.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I suggest checking if the Successful Logon events are being logged on domain controllers. i think those are event numbers 4624.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Its Azure AD, so not 100% certain how it works on that end : - (
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Have you seen this post:
https://community.checkpoint.com/t5/Security-Gateways/Identity-Awareness-using-Azure-AD/td-p/84940
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
We have call with CP on this soon, so lets hope we fix it, will update : - )
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
do you have some news about that?
Please let me know, because I have this kind of problem with a customer firewall.
Thank you!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi bro,
I re-install blade Indentity Awareness, and select account which have domain admin right, then it works. Good luck.
