Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
RobinJohnsen89
Explorer

Identity Awareness using Azure AD

Hi

I have tried configuring Azure AD as an Identity provider for Identity Awareness Access rules.

The Identity Provider object Azure is looking good.

The Azure AD object gives a green "connected" label when clicking "test connection".

All looking good. Until...

When I try to create a new access role and I browse Azure AD for users, the smartconsole throws an error saying "Failed to fetch objects from the Data Center. Please try again soon. If the issue persists, contact Check Point Support".

If I go to the drop down menu and select our on-prem AD it works as intended.

Now if I jump back and forth between the two, a couple of times, suddenly Azure AD works, and I am able to see my groups and users in Azure AD.

I can see the errors and successes in the cpm.elg log, but googling the errors gives me nothing.

 

When it is able to browse Azure AD i get this info message in the cpm.elg log:

INFO cloud.connection.GetAllCloudElementsCodeQueryHandler [xxxxxxxxxxxxxx-xxxxxxx]: finished processing.. number of results: 100, totalCount=4314

 

When it failes I get this error message in the cpm.elg log:

ERROR cloud.connection.GetAllCloudElementsCodeQueryHandler [xxxxxxxxxxxxxxxx-xxxxxxxx]: failed to execute command. error= at com.checkpoint.management.cloud.connection.GetAllCloudElementsCodeQueryHandler.performRemoteQUery(GetAllCloudElementsCodeQueryHandler.java:48)

 

If the only issue was a buggy browsing experience, I wouldn't be too bothered, but none of my security policies created using Azure AD groups are working.

 

How would I go about troubleshooting this issue? Are there other log files which may give me some more insight?

0 Kudos
3 Replies
PhoneBoy
Admin
Admin

You can create local groups of the form EXT_ID_xxx (where xxx is the name of the group (with same capitalization as) in Azure AD.
See: https://support.checkpoint.com/results/sk/sk177267 

0 Kudos
the_rock
Legend
Legend

I will look for great document someone on community sent me couple of years ago and if I find it, will attach.

Best,

Andy

0 Kudos
the_rock
Legend
Legend

K, got the doc, attached. Hope it helps.

Best,

Andy

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events