Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
konix78
Explorer

changing AD password with RA client

Hi

I am trying to configure possibility for changing AD password with VPN RA client and it is working fine in my lab but is not working on production. I use SMS 81.10 in lab and 80.40 in production, both are configure in the same way, the only difference that I see is on the screenshots. In the lab I don't have option "Use User Directory for security gateways (license required) . What license is required and why do I see this only in one global properties if I run the same blades on both? also can I tick this option without any negative consequences to check if it starts working ?

thanks

0 Kudos
4 Replies
Chris_Atkinson
Employee
Employee

To confirm is LDAPS TCP/636 configured & used in both environments?

Do you see CPSB-UDIR in the output of "cplic print" on your Prod management?

0 Kudos
konix78
Explorer

Hi Chris

 

I apologize for delay , that's information that I collected 

1) license CPSB-UDIR exists on LAB Mgmt srv but doesn't exist  on Prodo MGMT

2) cpopenssl s_client -connect IP:636
both FW show obtained certificate and show status connected

3) on both MGMT srvs I CAN'T fetch fingerprints


4 test_ad_connectivity

LAB
[Expert@Checkpoint-GW-1:0]# cat $FWDIR/tmp/test3.txt
(
:status (SUCCESS_LDAP_WMI)
:err_msg ("ADLOG_SUCCESS;LDAP_SUCCESS")
:ldap_status (LDAP_SUCCESS)
:wmi_status (ADLOG_SUCCESS)


Prodo
[Expert@b-fw01:0]# cat $FWDIR/tmp/test2.txt
(
:status (SUCCESS_WMI)
:err_msg ("ADLOG_SUCCESS;LDAP_PROTOCOL_ERROR")
:ldap_status (LDAP_PROTOCOL_ERROR)
:wmi_status (ADLOG_SUCCESS)

 

0 Kudos
G_W_Albrecht
Legend
Legend

So that is the issue - the CPSB-UDIR license is missing. You should check the license using cplic print for CPSB-UDIR feature, old licenses (>5years) may not contain the CPSB-UDIR - for this reason, the customers can still order a CPSB-UDIR license only to upgrade his legacy license.

CCSE CCTE SMB Specialist
0 Kudos
Wolfgang
Mentor
Mentor

@konix78 you have to configure everything exactly following How to configure password change after expiration (LDAP) for Mobile Access and Remote Access clients check twice your ldap account unit settings and the changes done via GUIdbedit.

0 Kudos