Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Howard_Gyton
Advisor

R80.30 - Identity Awareness failure

Hi,

Occasionally some of our users report they can no long access resources they normally can, and it appears that Identity Awareness has failed.

What we notice is the following output from "adlog a dc":

adlog a dc
Domain controllers:
Domain Name IP Address Events (last hour) Connection state
============================================================================================================
<domain> <ip> 39519 has connection
<domain> <ip> 5939 has connection
<domain> <ip> 0 has connection - warning: 0 events in the last minute

Ignored domain controllers on this gateway:
No ignored domain controllers found.

In the above output, I have rebooted the top two DC's, and only the third has the original problem.  I have left that machine in that state so that we can hopefully found out what is going on.  The only thing we have found that "fixes" it is to reboot all three DC's in sequence.  Then its okay again for a number of months.

I have also tried restarting a number of likely services, such as that below, but that nothing that has made a difference so far.  I have also checked for the following events in the "Security" log, and they are there: 4624, 4768, 4769 and 4770

Has anyone else come across this?

We already have a ticket open with our support partner, I'm just looking for some feedback from the community.

0 Kudos
2 Replies
Chris_Atkinson
Employee Employee
Employee

As a side note please look at moving to Identity Collector in place of AD query.

CCSM R77/R80/ELITE
Howard_Gyton
Advisor

Yes, I've just been reading up on that.  It seems pretty straightforward to install.  We already have the MUH agents installed on our Terminal Servers, and the setup seems very similar.

Migration doesn't seem too difficult either.  It can be configured on the firewalls, then run some connection tests on the clients, and if those pass, untick "AD Query", and push policy.

https://community.checkpoint.com/t5/General-Topics/Move-from-Identity-Awareness-AD-Query-to-ID-Colle...

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82

    Thu 25 Apr 2024 @ 11:00 AM (SGT)

    APAC: CPX 2024 Recap

    Tue 30 Apr 2024 @ 03:00 PM (CDT)

    EMEA: CPX 2024 Recap

    Wed 01 May 2024 @ 02:00 PM (EDT)

    South US: HTTPS Inspection Best Practices

    Thu 02 May 2024 @ 11:00 AM (SGT)

    APAC: What's new in R82
    CheckMates Events