- CheckMates
- :
- Products
- :
- Quantum
- :
- Remote Access VPN
- :
- AD query failing for identity Awareness
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
AD query failing for identity Awareness
Hello Team,
We have recently had to rebuild our r77.30 firewall (due to a failed upgrade attempt, SMS is already r81).
We have connectivity from r77.30 gw to our RSA server but get the following error:
We have tried several sets of creds which we know to be correct (i.e. admin level) but continue to get this error message.
Can anyone help please?
- Labels:
-
Windows
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
For simplicity, the service account you use with the IDA should be a Domain Admin. It is possible to use a non-Domain Admin account, but then you need to start doing schema updates and changes within your Domain. Not familiar with pointing IDA at a RSA server vs a domain/domain controller.
Also do need to point out that R77.30 has been End of Support for a while now. R80.40 is our oldest/supported version with R81.10 being our Recommended version.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Matt, the account we are testing with are both Domain Admin.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Windows Server 2016 or 2019? Microsoft changed things within Windows Server 2022 and my IDA wouldn't authenticate anymore. I changed to the Identity Collector at that point. IDC is moving towards being the recommended method going forward too.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Put it this way...as @Matt_Ricketts said, R77.30 has been unsupported way before Covid-19 I think, but regardless, even if you were on R55 or R81.20 version, you HAVE TO use domain account with full admin privileges to make this work. I spent way too many hours with TAC on the phone going through sk93938 and we could never get that working...ever.
https://support.checkpoint.com/results/sk/sk93938
Andy
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks Rock, the accounts we are testing with are domain accounts with full admin privileges.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
In response to various security vulnerabilities, Microsoft has made numerous changes to WMI.
This effectively "breaks" ADQuery and we've been recommending people move to Identity Collector for some time.
For details on Identity Collector, see: https://support.checkpoint.com/results/sk/sk108235
Yes, you can run Identity Collector under R77.30, but it's been End of Support for other three years now.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Excellent point indeed...I had customer who was hesitant to move to IDC, but once I gave them all the good reasons to and they saw issues with windows updates on their AD server, they finally accepted to move away from AD query and are super content now with identity collector, no issues on 3 months since the change.
