- CheckMates
- :
- Products
- :
- Quantum
- :
- SMB Gateways (Spark)
- :
- Active directory user base policies are not workin...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Active directory user base policies are not working
The Active Directory user-based policies are not working in the local managed firewall, although the user groups from Active Directory are displaying correctly and syncing properly. When I apply a policy to the Active Directory user group, the rule does not work; only IP-based rules are functioning. What could be the cause of this issue? I have attached an image showing the error in the user awareness session.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Which firmware version/build is used and are you using this with the Identity Collector??
You may need to investigate the issue further with TAC note also sk105977.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Thank you for the replying. Firmware version is R81.10.10 and this firewall not using identity collector. Only apply policies from user groups in active directory.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Which version do you use?
Can you please attach screenshot of the access rule?
Thanks,
Dafna
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Thank you for replying. This is a Check Point 1570 security appliance, and the firmware version is R81.10.10. I have attached the access rules. According to the image, only the traffic matching rule number 5 is being processed; the other rules above it are being bypassed. Additionally, this firewall is not using an identity collector.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Which AD server do you use? (which version)
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi,
Windows Server 2016 active directory.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
What it he method of the user auth?
https://support.checkpoint.com/results/sk/sk178604
Bear in mind: Identity Agent is not supported on 1500, 1600, and 1800 Quantum Spark Appliances.
On a Locally Managed appliances, there is no Identity Awareness option to add Active Directory (AD) users/ Organization Units inside the source column in policy rules. There is an Identity Awareness option to add Active Directory (AD) groups, but not to add specific users. The Users tab on the left contains only internal users, which are not from Active Directory. See sk105977.
Akos
\m/_(>_<)_\m/
