- Products
- Learn
- Local User Groups
- Partners
- More
Scaling Check Point Automation with Arodonata
7 October @ 5pm CET / 11am EDT
What's New in Check Point SASE
The State of Ransomware Q2 2026:
This Quarter's Trends, and Their Impact on Your Defenses
AI Security Masters
Implementing the AI Security Trifecta
CheckMates Go:
Half is Not Enough
Hi CheckMates community,
We're in the process of migrating from AD Query to Identity Collector for the Identity Awareness blade. We've successfully configured one Identity Collector in our environment. However, when attempting to add the second gateway, we encountered an issue where the system prompted us with "Error: refer to sk113021."
We've already ensured that the network requirements are fully met, and the gateway is reachable as confirmed by successful pings (as shown in the attached image). Additionally, we've verified that all logs related to the Identity Collector are allowed.
Despite these steps, we're still facing the same issue. Has anyone experienced a similar problem, or could you provide insights into what might be causing this? Any help or guidance would be greatly appreciated.
Thank you in advance!
IC
CPlogs
Hi everyone,
I just wanted to provide an update regarding this issue. After installing the HOTFIX and applying the necessary patches, the Identity Collector successfully received the certificate. We simply clicked the Trust button to re-establish the connection, and now everything is working smoothly — all status indicators are green!
Thanks to everyone for your input and support!
Best regards,
PONG
Did you actually go over sk113021? It lists quite a few points other than connectivity. I suggest you review it first, check every possible scenario, and let us know if that helped.
In addition, please look into k170112
Hi @PingPong
Can you reach the InternalFW on port 443?
#telnet <ip> 443 from the identity collector?
Akos
I am also encountering this issue. We’re in the process of migrating from AD Query to Identity Collector for the Identity Awareness blade and have successfully configured one Identity Collector. However, when trying to add the second gateway, we get the same error message referring to "Error: refer to sk113021." We’ve checked that all network requirements are met, the gateway is reachable (confirmed by pings), and that all relevant logs for the Identity Collector are allowed. Despite these checks, the issue persists. Has anyone else faced this problem or have any suggestions on what might be causing it? Any insights would be greatly appreciated! Thanks in advance.
If somebody will open a ticket by TAC, please paste here the solution 🙂
A new IDC build was published on sk134312 if your problem persists with this please contact TAC for assistance
Hi everyone,
I just wanted to provide an update regarding this issue. After installing the HOTFIX and applying the necessary patches, the Identity Collector successfully received the certificate. We simply clicked the Trust button to re-establish the connection, and now everything is working smoothly — all status indicators are green!
Thanks to everyone for your input and support!
Best regards,
PONG
Great job! Thanks for sharing the solution.
Andy
Glad it's working now - Which hotfixes / patches are you referring to?
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 20 | |
| 19 | |
| 19 | |
| 12 | |
| 8 | |
| 8 | |
| 7 | |
| 5 | |
| 5 | |
| 4 |
Mon 28 Sep 2026 @ 03:00 PM (CEST)
La nouvelle réalité des attaques DDoS: autonomie, échelle et avenir de la défenseThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksMon 28 Sep 2026 @ 03:00 PM (CEST)
La nouvelle réalité des attaques DDoS: autonomie, échelle et avenir de la défenseThu 01 Oct 2026 @ 05:00 PM (CEST)
Under the Hood: Check Point WAF | Preventing minus-zero-day attacksAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY