- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hello together
I have the following Situation Chechpoint 8.10 in a Cluster Configuration, all Traffic is working fine.
The was LDAP configured in the Past to conennct to 5 different Windows Domain Controller All Domain Controller are in sysnc and on the Entered in the Firewall.
We check all the Connection include (Fetch) and we get no Issue. So what is the Problem ?
On the Log we can see normaly IP Address and the current User based on LDAP and Windows on a Role.
But for some Users the is no Entry just Empty, only the IP Address is visible.
Permission is not read no Access to the Destination.
For other Users in the same Windows Group it works, the come from a other Subnet.
And other Users on a different Subnet we have the same Issue.
Any Idear.
best regars
Alexander
do you have http inspection active?
Hi Alessandro
I assume that you mean HTTPS Inspection Trust, finally not, all the Traffic of Source and Destination is inside on different Zones.
The current Configuration was imported from a Cisco PXI.
Yesterday we found out that on the 3rd. Firewall who is not part on the Cluster Identity Awareness is enabled , we remove the
Because some Users are connect to this Firewall, and not to the Cluster.
Best regards
Alexander
Do you have the recent GA Jumbo Take 169 installed ?
Hi
Have to check no remote access at the Moment.
Best regards
Alexander
is client machine a windows OS ? if yes, could you try just lock and unlock that machine and check if show user identity on log?
If your Domain controller has a short rotate event log you could be losting events of logon.
are you using AD query or identity collector?
Hi Alessandro
Just to come back, there is no role working on the Environment who show us the Computer name and the User Name, only Computer name will be displayed.
But if we, create a new Policy and searching for the can Browse the Active Directory and see all Object.
What I think is that he place first the Network Object on the Policy and the next Policy is using the Role.
So if the Policy with the Network Object is match, why should he check the Policy with the Role.
Sorry have to come back tomorrow.
No access at the moment.
Hello together
We have some news ☹
First the Issue is only with two Users in the same Group, other Users in the same Groups are working.
What did we do we add the missing Windows Domain Controller (total 5) to the LDAP Configuration, Result we can see now all Users from a other Location
who are not visible before. Remark have nothing to do with the Issue himself.
We change the Settings to read the LDAP Server from the Firewall himself (existing Object as Zone) to the to the real Name of the Servers (Host Object).
What did we assume the Firewall can read the LDAP Server because we have Hits on the Policy.
Test if User 1 is connected with PC 1 hi is not visible on the Log.
If the same User change to PC2 and log in we can see a Part of his Name in the Log Example Alex.B and not Alexander, Bauer.
Did we see in the Log the Display Name of the User from the Active Directory ?
Best regards
Alexander
Both PCs is on same domain, correct?
on each PC open a prompt and type the command "set", looking for line with LOGONSERVER and confirm if is the same DC.
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 15 | |
| 8 | |
| 8 | |
| 8 | |
| 7 | |
| 5 | |
| 5 | |
| 4 | |
| 4 | |
| 3 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY