Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Bastien_Lauc
Explorer

Error retrieving results

Hi,

I have a issue when I want create un access role.

I installed Identity collector on my Active Directory Server Windows 2022.

In Identity Sources:

Capture d'écran 2023-10-25 170311.png

The second one is the Active Directory Server backup.

In Gateways:

Capture d'écran 2023-10-25 171212.png

We can see all is connected.

 

I already saw this kb "Error retrieving results" while fetching AD users with an existing Access Role (checkpoint.com) but the result was not conclusive.

My firewall and SMS are both in r81.10

Sorry for the lack of information I can provide, I'm a beginner.

Best Regards,

Bastien

0 Kudos
7 Replies
the_rock
Legend
Legend

Can you please clarify if issue is with access role itself or something else? Im not really clear on that from your post.

Regards,

Andy

0 Kudos
Bastien_Lauc
Explorer

Yes it's a issue with access role

Capture d'écran 2023-10-26 104753.png

As say I already saw this kb "Error retrieving results" while fetching AD users with an existing Access Role (checkpoint.com) but the result was not conclusive.


Best Regards,

Bastien

0 Kudos
PhoneBoy
Admin
Admin

The issue in the SK you linked relates to the LDAPS certificate.
Have you confirmed the certificate in this case is, in fact, not expired?
You should also try troubleshooting per: https://support.checkpoint.com/results/sk/sk113747 

0 Kudos
Bastien_Lauc
Explorer

Hi,

The certificate is no expired.

Capture d'écran 2023-10-26 181243.png

I followed  the sk and I have a problem with adlog a dc :

Adlog is not enabled, therefore cannot display domain controllers status

I saw you said to contact TAC Identity Awareness stopped working - Check Point CheckMates

So I’m gonna do this.
Otherwise, impossible to contact LDAP server

 

Best Regards,

Bastien

0 Kudos
emmap
Employee
Employee

Do you have an LDAP account unit set up so that the mgmt server can talk to the AD servers?

0 Kudos
Bastien_Lauc
Explorer

I use the default account Administrator of the Active Directory for communicate with de mgmt

Capture d'écran 2023-10-26 105426.png

Best Regards,

Bastien

0 Kudos
the_rock
Legend
Legend

It might be worth doing remote with TAC, so they can verify all this.

Andy

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events