- Products
- Learn
- Local User Groups
- Partners
- More
Quantum Spark Management Unleashed!
Check Point Named Leader
2025 Gartner® Magic Quadrant™ for Hybrid Mesh Firewall
HTTPS Inspection
Help us to understand your needs better
CheckMates Go:
SharePoint CVEs and More!
Hello, which engineer has encountered this problem, can you help to solve it?
Hi Zhen,
Have you tried re-entering the password for the account you are using under the LDAP account unit configuration?
Also the account you are using to access AD is the account unlocked?
Regards
Mark
Hi,Mark
Hello, the current password is the password of the account being used, and the account has been unlocked. I can use the remote desktop of windowns to connect to the AD domain server
Regards
Zhen
Hi Zhen,
Have you tried re-entering the password into the configuration? Only reason I ask is that I have had similar experiences when pasting a password into the password fields. It populates the field, but actually keeps locking the account out.
It may be worth a shot? Another thing I would look for is the correct entry on the "Login DN" for the account you are using
It may be worth presenting your LDAP account unit config so we can take a look.
From what you have said the account you are using is a domain admin?
Regards
Mark
Hi,Mark
Hello, is this way of writing correct?
Regards
Zhen
Hi Zhen,
The login DN looks correct. Although I would recommend not using the built in administrator account. I would always create a "service account" for this purpose. That doesn't have more permissions than are needed for the account role.
Did you attempt to re-enter the password?
Regards
Mark
Hi,Mark
The password has been reentered,Now this account has been upgraded to have administrator privileges, there is still an error
Regards
Zhen
Thanks Zhen. Are there any errors within the logs using the below query.
Blade:"Identity Awareness".
Regards
Mark
Hi,Mark
Regards
Zhen
Can you confirm that you can perform a native ldap query against the DC outside of Check Point with the account that you are performing the action with?
If you can, this confirms that your AD Domain Controller and account are adequate for LDAP. If the ldap bind fails outside of Check Point, this may indicate an issue with the domain controller.
Regards
Mark
Is there a FW between the management server and the AD server?
Second to that do you have a rule allowing the gateway to access the AD server? As the log says check SK58881.
Last question, is your management a Multi Domain server?
Hello, there is no FW between them. Secondly, there are rules that allow gateway to access AD server. Secondly, instead of multi-domain server, a DNS is set up on the server
Has this ever worked?
Does the user have full admin rights? Did anyone change anything there?
The user has administrative rights, and nothing else has changed
Hi Zhen,
If everything checks on from an Active Directory domain controller point of view and the Check Point configuration is also correct (time, DNS servers, domain) etc. It then may be quicker to raise a call with TAC to investigate further.
Regards
Mark
Thank you very much
Can you check the time,are DC and checkpoint times same?
Hi,
Have you resolve this issue? Can you share the solution you have made? My client is experiencing this issue also.
Thanks,
Karel
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
User | Count |
---|---|
9 | |
7 | |
6 | |
6 | |
5 | |
5 | |
5 | |
5 | |
5 | |
5 |
Fri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAFri 12 Sep 2025 @ 10:00 AM (CEST)
CheckMates Live Netherlands - Sessie 38: Harmony Email & CollaborationTue 16 Sep 2025 @ 02:00 PM (EDT)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - AmericasWed 17 Sep 2025 @ 04:00 PM (AEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - APACWed 17 Sep 2025 @ 03:00 PM (CEST)
Securing Applications with Check Point and AWS: A Unified WAF-as-a-Service Approach - EMEAThu 18 Sep 2025 @ 03:00 PM (CEST)
Bridge the Unmanaged Device Gap with Enterprise Browser - EMEAAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY