- Products
- Learn
- Local User Groups
- Partners
- More
Policy Insights and Policy Auditor in Action
19 November @ 5pm CET / 11am ET
Access Control and Threat Prevention Best Practices
Watch HereOverlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi CheckMates
Is anyone having issue with Identity Collectors when CrowdStrike is running on the domain controllers?
I'm running Identity Collectors on two dedicated servers (so not directly on the domain controllers) but since CrowdStrike has been installed on the domain controllers the id collectors stop receiving events from the DCs at least once per day. The Status Description for each DC remains 'connected' but the events stop incrementing. Restarting the Id Collector service on the Collectors kick-starts the process and they start receiving AD events again.
CrowdStrike technical support have reported that this is a known issue because it interrupts the Identity Collector's connection to AD and no RST packet is sent by the domain controller to reset the tcp session.
One suggested workaround is to configure Task Scheduler on the Collectors to periodically restart the service (say, every 6 hours) but this is not ideal.
Is Check Point R&D aware of the problem (hi, Royi Priov) and is there a better solution to keep the Id Collectors running?
Thanks,
Steve
Hi,
Thanks for tagging me.
Yes, there is a known issue, where crowdstrike is closing IDC connection to DC.
It was addressed in bug ID IDA-5232 from our side.
It will be added to the next GA of IDC, but as for now please use the fix from IDA-5232.
I had someone tell me they had CP case open for this, but no resolution was given. I can ask them what happened with it and report back.
Hi,
Thanks for tagging me.
Yes, there is a known issue, where crowdstrike is closing IDC connection to DC.
It was addressed in bug ID IDA-5232 from our side.
It will be added to the next GA of IDC, but as for now please use the fix from IDA-5232.
Hi Royi,
Thanks for the update, I will try the bug fix.
Kind regards
Steve
Did that fix your issue? I was going to say we aren't having any problems with it, but CrowdStrike was not installed on the server I have Identity Collector running on. It is installed on the DC however. I also have one other server where both are installed and running fine.
Has this been fixed in Identity Collector version R81.040? Where do I get IDA-5232?
I can't seem to find that, if I end up running into issues after installing CS on another server.
Next release of IDC is not yet available, contact TAC in the interim.
Hi r1der,
My Identity Collectors run on two servers that are separate from my DCs. It's possible that you are not seeing the problem because your Identity Collectors are running on your DCs.
The workaround I used was to set up a task in Windows Task Scheduler on the Identity Collectors that restarts the CP Id Collector service every 6 hours regardless of whether or not it has failed. And the restart schedule is offset by 6 hours between the two Collectors so they do not both restart the service at the same time.
This workaround has been successful so far so I'll keep using it until the fix is rolled into the GA updates.
You might be able to use something similar if you have multiple ID Collectors for resilience.
Thanks for sharing that @Stephen_Ware 👍
Thanks for the update! Good to know the service and that you can just restart it to get it running again.
Hi Royi,
Was it ever determined what on Crowdstrike was closing the connection?
Thanks,
Maurice
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 27 | |
| 23 | |
| 15 | |
| 14 | |
| 12 | |
| 10 | |
| 6 | |
| 6 | |
| 5 | |
| 4 |
Wed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchWed 19 Nov 2025 @ 11:00 AM (EST)
TechTalk: Improve Your Security Posture with Threat Prevention and Policy InsightsThu 20 Nov 2025 @ 05:00 PM (CET)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - AMERThu 20 Nov 2025 @ 10:00 AM (CST)
Hacking LLM Applications: latest research and insights from our LLM pen testing projects - EMEAThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAWed 26 Nov 2025 @ 12:00 PM (COT)
Panama City: Risk Management a la Parrilla: ERM, TEM & Meat LunchAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY