- Products
- Learn
- Local User Groups
- Partners
- More
Check Point Jump-Start Online Training
Now Available on CheckMates for Beginners!
Welcome to Maestro Masters!
Talk to Masters, Engage with Masters, Be a Maestro Master!
ZTNA Buyer’s Guide
Zero Trust essentials for your most valuable assets
The SMB Cyber Master
Boost your knowledge on Quantum Spark SMB gateways!
Check Point's Cyber Park is Now Open
Let the Games Begin!
As YOU DESERVE THE BEST SECURITY
Upgrade to our latest GA Jumbo
CheckFlix!
All Videos In One Space
Hello,
I have an issue regarding AD Queries for Identity Awareness.
Environment: Check Point R81 + Take 56 (active/passive cluster)
The monitor shows a warning related to Identity Awareness: Error: At least one DC is currently disconnected; the AD Query Status shows Bad Credentials.
I double-checked credentials (they didn't expire); I also changed the password, test LDAPs (636 port) with ldp.exe tool and it is working.
Any advice ? Is there any specific log I can check to better understand the issue ?
Thank you.
I suspect that MS KB500442 was installed on the domain controllers. I would check that first.
I suspect that MS KB500442 was installed on the domain controllers. I would check that first.
Hello,
yes, you are completely right.
It seems a June 2022 enables hardening changes on DCOM.
There is this Check Point article Check Point response to CVE-2021-26414 - "Windows DCOM Server Security Feature B...
The best way to solve it, instead of disabling the behavior introduced by KB via registry key, is to install latest Check Point R81 take (Take 60 solves the issue).
Thank you,
Luca
Regards,
Luca
Yes indeed the latest HF resolved it 🙂
About CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY