Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Moftsi
Participant

Issue with User Awareness Query on Check Point SMB (Locally Managed)

Hi Everyone,

We are currently configuring User Awareness on a Check Point SMB firewall with local management, but we are unable to query users from our Active Directory (AD) server.

We are using a non-administrator account and have modified the group permissions according to sk93938 (Using Identity Awareness AD Query without Active Directory Administrator privileges on Windows Server 2008 and higher).

Troubleshooting Steps Taken:
We confirmed that the Gateway can ping the AD server.

The Gateway can access the AD server on port 389 (verified through firewall logs).

We also tested authentication using an Administrator account to rule out permission issues, but the problem persists.

Has anyone encountered this issue when using local deployment? Any insights would be greatly appreciated.

Thanks for reading!

0 Kudos
8 Replies
G_W_Albrecht
Legend Legend
Legend

Can you please specify model and firmware of the SMB ? Where is the AD situated, locally at site ?

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Moftsi
Participant

Hi Albrecht,

We using CP 2000 series with firmware 81.10.15

0 Kudos
G_W_Albrecht
Legend Legend
Legend

Where is the AD situated, locally at site ?

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Moftsi
Participant

We using AD server locally site with topo seem like this

z6428227472461_202cb78a60ce88927be9793caa2d1ccb.jpg

0 Kudos
G_W_Albrecht
Legend Legend
Legend

So the issue seems the internal firewall - did you enable IA there also and set it to Identity Sharing ?

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos
Moftsi
Participant

I am just test this option on internal firewall but it seem to not working.

0 Kudos
PhoneBoy
Admin
Admin

That will only work with gateways managed by the same management, which is not the case here since your SMB gateway is locally managed.
I suspect you'll need a TAC case to understand why you're getting an internal error adding the AD server.

0 Kudos
G_W_Albrecht
Legend Legend
Legend

So one solution would be to put SMB GW under same management as internal GW...

CCSP - CCSE / CCTE / CTPS / CCME / CCSM Elite / SMB Specialist
0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events