Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
yasindu
Participant

Active directory user base policies are not working

The Active Directory user-based policies are not working in the local managed firewall, although the user groups from Active Directory are displaying correctly and syncing properly. When I apply a policy to the Active Directory user group, the rule does not work; only IP-based rules are functioning. What could be the cause of this issue? I have attached an image showing the error in the user awareness session.

0 Kudos
7 Replies
Chris_Atkinson
Employee Employee
Employee

Which firmware version/build is used and are you using this with the Identity Collector??

You may need to investigate the issue further with TAC note also sk105977.

CCSM R77/R80/ELITE
0 Kudos
yasindu
Participant

Hi,

Thank you for the replying. Firmware version is R81.10.10 and this firewall not using identity collector. Only apply policies from user groups in active directory.

0 Kudos
Dafna
Employee
Employee

Hi,

Which version do you use?

Can you please attach screenshot of the access rule?

 

Thanks,

   Dafna

0 Kudos
yasindu
Participant

Hi,

Thank you for replying. This is a Check Point 1570 security appliance, and the firmware version is R81.10.10. I have attached the access rules. According to the image, only the traffic matching rule number 5 is being processed; the other rules above it are being bypassed. Additionally, this firewall is not using an identity collector.

0 Kudos
Dafna
Employee
Employee

Which AD server do you use? (which version)

0 Kudos
yasindu
Participant

Hi,

Windows Server 2016 active directory.

0 Kudos
AkosBakos
Advisor

What it he method of the user auth?

https://support.checkpoint.com/results/sk/sk178604

Bear in mind: Identity Agent is not supported on 1500, 1600, and 1800 Quantum Spark Appliances.

On a Locally Managed appliances, there is no Identity Awareness option to add Active Directory (AD) users/ Organization Units inside the source column in policy rules. There is an Identity Awareness option to add Active Directory (AD) groups, but not to add specific users. The Users tab on the left contains only internal users, which are not from Active Directory. See sk105977.

Akos

----------------
\m/_(>_<)_\m/
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events