- CheckMates
- :
- Products
- :
- General Topics
- :
- Re: Identity Awareness Sk113021
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Identity Awareness Sk113021
Hi All,
We have Check Point R81.10 security gateways with Identity Awareness configured. We installed the agent on a separate server to fetch logs from the Active Directory, displaying machine names and source usernames accurately. However, on one of the security gateways, it shows 'failed' and refers to SK113021. I attempted to address this issue following the guidance in the document, but it did not resolve the problem. Please any help
Thanks
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
- Do you mean that, when you want to link (SIC) the gateway to the IA Collector?
- The IA collectos is the latest version?
- That interface whicf in use for this connection is a Cluster interface?
Akos
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Do you mean that, when you want to link (SIC) the gateway to the IA Collector?
- Yes when I add the gateway on the IA Collector
- The IA collectors is the latest version?
- Yea downloaded from the SMS and working fine for the other gateways
- That interface which in use for this connection is a Cluster interface?
- not the cluster the private IP of the VS
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Are we talking about a VS on a VSX cluster?
If yes, the IA is communicating on one of the interfaces of the VS. Can the VS reach the IA colletctor somehow. The ping, telnet of 443 works?
Akos
\m/_(>_<)_\m/
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Yes VS in vsx member the other two VS are okay only one of the vs has an issue. Connectivity is okay
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
If you run a capture from say one that works and one that does not to the IC ip address, what do you see as far as difference?
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hey bro,
How you been? Can you please send a screenshot of it? Just blur out any sensitive data.
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Interestingly enough, I just did some testing in the lab and realized 2 of my gateways were complaining about shared secret, though absolutely nothing was changed. When I rebooted machine where IC is installed, all worked fine.
Have you tried that?
Andy
