Hi guys,
I want to test in my home LAB the IDC solution. I didnt work with IA in the past, so asking for a help here 🙂
My goal is to allow connection based on Access Roles for specific users in order to allow them to reach the needed internal resources.
I have R81.10 gateway and MDS with Take 87. Windows Server 2019 is acting like DC and AD. IDC agent is installed on Windows Server. The connection between DC/AD and GW is working, all is green. I have created in AD some test users which are used to log-in to the Windows 7 machine over test domain. So far, all as expected. But once I want to check on Check Point GW if user was recognized as successfully logged to the Windows 7 machine, the firewall logs says that: "Group membership of the required account (user or machine) could not be retrieved from the AD. Make sure the account exists in the AD."
Logs for IA blade:
The same errors are seen for each and every user, doesnt matter if user was already created or created couple of minutes ago.
Looks like some configuration issue on FW which I didnt recognize yet.
There is only 1 Account Unit configured, with following settings:
I checked sk106133, but looks like I didnt find a match there...
Since this is my home LAB, I can do any debugs in order to figure out what is going on.
Anyone who is experienced with IA and IDC specifically, and is able to help me to fix the issue ?
Thanks for the help !
Kind regards,
Jozko Mrkvicka