Hi @Sanjay_S ,
It sounds like the communication to the AD server indeed is not working. When creating an access role, the communication is between mgmt server and the AD, while Identity Awareness enforcement requires the GW to communicate with the AD server.
You have mentioned port 636, which points to the fact you are probably using LDAP over SSL.
Have you tried to refetch the fingerprint inside the LDAP account unit object? please do so, and install policy afterwards.
If the issue still exists, I suggest contacting Check Point support.
Thanks,
Royi Priov
R&D Group manager, Infinity Identity