- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi, im trying to activate my identity Awareness blade on R80 gateway, in the wizard the connection with my AD result ok, but when Im trying to create a Access Role requesting a list of users of the domain controller, it doesn't work.
When I use the test_ad_connectivity -x itsvsa.com.ve -o my_test2.txt -s -w command on expert mode, I can see these results:
[Expert@gwr801:0]# cat my_test2.txt
(
:status (SUCCESS_WMI)
:err_msg ("ADLOG_SUCCESS;LDAP_OPERATIONS_ERROR")
:ldap_status (LDAP_OPERATIONS_ERROR)
:wmi_status (ADLOG_SUCCESS)
:timestamp ("Fri Nov 23 10:37:19 2018")
Using another diagnostic commands, the output shows connection with the active directory, in fact I can observe data for machines on =the domain an users of certainf OUs. but in the Securty Management I can not obtaing the user list, to create access roles based rules.
other ouptputs:
Hi Antonio,
Please make sure that your PC in which you are opening smart console should be also in same domain.
First, there is no such gateway version R80: you are either using R80.10 or R80.20.
That said for this question it's not terribly relevant.
One relevant question: are you using Identity Collector or ADQuery?
Your gateway shows the users it has been told about by the AD server.
A seperate LDAP lookup must be performed on each user (and management) to get the groups associated with each user.
thank you Dameon, in fact, R80.10 its the release what I was working on. I activate the ip forwargind on my PC host for the lab and try again, and obtain successful results, listing the users, machines and othe info from the domain controller. But I still seeing the error message LDAP_OPERATIONS_ERROR
the error message, is obtained when I run the script $FWDIR/bin/test_ad_connectivity on the gateway, and when I do the same on the SC, obtain a general error.
Right now, I can go ahead with my lab environment, we can build rules on the Url Filter Layer based on Identity captured from the AD. When I procced to the production deployment I probably need checkpoint support if the behavior persist on the real configuration.
thanks to all
Check $FWDIR/log/test_ad_connectivity.elg to see if you can see more details.
You need to allow your workstation IP address to be allowed somewhere (LDAP). SmartConsole is using your internal IP of desktop.
CLI of mamagement is using IP of management server.
The SmartConsole machine is not connecting to the AD server anymore in R80+, only the management server and the gateway are doing this now.
In a Multi-domain environment the MDS and Domain server are both making connections (at least they were in R80.10, I need to see about this in R80.20).
thanks for your support, really, we solve the issue, activating the IP forwarding on my PC, to give connection from the SC to the AD. However, when I run the test, right now the SC list the user for me, to add access control rules, but the test_connection script still sayng the same message, LDAP OPERATIONS ERROR
This is probably because the -w option "Specifies that only the WMI connectivity test (no LDAP) should be performed". LDAP worked for me without this option or with -l
test_ad_connectivity -x itsvsa.com.ve -o my_test2.txt -s -l
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 12 | |
| 9 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 3 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY