- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: Identity Awareness not getting group membershi...
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Identity Awareness not getting group membership with Identity Collector
Hi
Please help with troubleshooting of Identity Awareness on the vSEC gateway version 81.10 Take 335 JHF 95.
I have configured Identity Awareness with Identity Collector and MS Active Directory
When I made an Access Role for Domain Users and added it to the Source field of Access Control policy the test account didn't get access to the destination.
While troubleshooting this I noticed that gateway gets event of logged in test account but there is no information about its group membership.
When I try to login with my own account it gets that account is member of the group and access rule works.
Checking logs of blade "Identity Awareness" in SmartConsole I see that there are many users that are members of this group and many others - not.
Why it is and how to fix that? Thanks
- Labels:
-
Identity Awareness
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @ArtemDanko
"Domain Users" is the default primary group for users in a domain.
Due to Microsoft's Implementation of the Active Directory server not returning primary groups, this group does not return in the response to our LDAP query.
See https://support.checkpoint.com/results/sk/sk32479 .
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello @ArtemDanko
"Domain Users" is the default primary group for users in a domain.
Due to Microsoft's Implementation of the Active Directory server not returning primary groups, this group does not return in the response to our LDAP query.
See https://support.checkpoint.com/results/sk/sk32479 .
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
K, just to make sure we are all on the same page here...are you saying that SOME users work fine, ie there are logs about their group membership and some dont work, though they belong to the same group?
Andy
