- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi All,
One of our customers is using the Terminal Server agent for Citrix and is seeing the following alerts in the logging (and mail).
HeaderDateHour: 22Jun2019 5:32:13; ContentVersion: 5; HighLevelLogKey: N/A; Uuid: {0x0,0x0,0x0,0x0}; SequenceNum: 32; Action: ctl; Origin: XXXXXXX_XXXXXXX; IfDir: >; InterfaceName: N/A;
Alert: mail; OriginSicName: CN=XXXXXXX_XXXXXXX,O=XXXXXXXX.fake.domain.grq7vi; OriginSicName: CN=XXXXXXX_XXXXXXX,O=XXXXXXX.fake.domain.grq7vi; HighLevelLogKey: 18446744073709551615;
status: Bad configuration; ctrl_category: Configuration Status; description: Failed to get users groups for the domain.(+)Verify that this domain name is configured in your LDAP Account Unit.(+)Domain: nt service;
severity: Critical; ProductName: Identity Awareness; ProductFamily: Network;
Identity Awareness is configured as described in the admin guide and seems to be working. But where does this alert coming from and why is Check Point seeing the 'nt service' domain? This is not configured in the Check Point configuration.
Regards,
Martijn
Hi @Piet_vd_Maas_2 ,
This issue was already resolved, on the client side.
Please download and install the latest client from sk134312 - "nt service" should be filtered out automatically.
Hi,
We are not using AD Query. Just the Identity Awareness agent on computers and terminal servers.
Not sure how to exclude accounts with Identity Awareness agents.
Regards,
Martijn
With the AD Query you can exclude user, but not with the (Terminal Server) Identity Agent. Or is there still a way to exclude users?
@Royi_Priov shouldn't exclusions for identity agent work the same way as ADQuery?
Hi @Martijn
The TS agent is monitoring all users logged in on the Citrix machine and sends them (in UPN format - user@domain) to the PDP gateway.
My assumption is that a service account was logged into the Citrix machine and therefore was transferred to the gateway.
The fact that this domain was not configured on Check Point side (which is right!) cause this error, as the authorization phase for this user fails.
I suggest opening case with TAC, to verify this. You can also ask for fixed agent which allows excluding specific users to be sent to the PDP gateway.
Thanks,
Royi.
Hi,
what was the solution? I'm having the same issue. Thanks
Grass
Hi Martijin
What was the solution here? I'm having the same issue with R80.40. Thanks
Grass
We still get the same warnings. Also in R80.40.
HeaderDateHour: 26May2021 14:58:51
ContentVersion: 5
HighLevelLogKey: N/A
Uuid: {0x0,0x0,0x0,0x0}
SequenceNum: 122
Action: ctl
Origin: XXXXXXXXX
IfDir: >
InterfaceName: N/A
Alert: mail
OriginSicName: CN=XXXXXXXXX
status: Bad configuration
ctrl_category: Configuration Status
description: Failed to get users groups for the domain.(+)Verify that this domain name is configured in your LDAP Account Unit.(+)Domain: nt service
severity: Critical
ProductName: Identity Awareness
ProductFamily: Network
Hi @Piet_vd_Maas_2 ,
This issue was already resolved, on the client side.
Please download and install the latest client from sk134312 - "nt service" should be filtered out automatically.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 25 | |
| 13 | |
| 12 | |
| 7 | |
| 6 | |
| 5 | |
| 4 | |
| 4 | |
| 3 | |
| 3 |
Wed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY