- Products
- Learn
- Local User Groups
- Partners
- More
MVP 2026: Submissions
Are Now Open!
What's New in R82.10?
Watch NowOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi.
Our domain controllers require integrity checks for RPC-calls, and it does not seem like Check Point Management\Security Gateway honors the requirement, and then fails to connect. This error is logged on our domain controllers:
The server-side authentication level policy does not allow the user REDACTEDUSER from address REDACTEDIP to activate DCOM server. Please raise the activation authentication level at least to RPC_C_AUTHN_LEVEL_PKT_INTEGRITY in client application.
Where REDACTEDUSER is the user account specified in domain controller authentication in the LDAP Account Unit, and REDACTEDIP is gateway and security gateway-adresses.
Here is a link to Microsoft-information regarding different RPC authentication-levels:
[MS-RPCE]: Authentication Levels | Microsoft Docs
Is there a way to enable this, or is it just not supported?
The only place I think we made actual RPC calls is when ADQuery is used (versus Identity Collector).
Otherwise, we're just making LDAP calls.
Are you using ADQuery?
Yes, we have Active Directory Query activated, but we also have a collector up and running. Does Collector replace all functionality from AD Query? If yes, then I guess we could just disable it and not worry about this.
Running "adlog a dc" also gives the following error from the same DCs which gives RPC-warnings for Check Point: "connection had internal error [ntstatus = 0x80010111"
They both do the same thing, albeit using entirely different mechanisms.
Identity Collector is a LOT more scalable and doesn't cause as much load on the Active Directory servers.
Is there a way to fix this with AD Query?
We use Identity Collector, but we have this error when we try to update rule base(Access Role) and this needs to pull list of users from "LDAP Account Units"(with "Active Directory Query" disabled)
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 19 | |
| 16 | |
| 7 | |
| 5 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 4 | |
| 4 |
Tue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsTue 16 Dec 2025 @ 05:00 PM (CET)
Under the Hood: CloudGuard Network Security for Oracle Cloud - Config and Autoscaling!Thu 18 Dec 2025 @ 10:00 AM (CET)
Cloud Architect Series - Building a Hybrid Mesh Security Strategy across cloudsAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY