The information you are about to copy is INTERNAL!
DO NOT share it with anyone outside Check Point.
Identity Awareness Gateway may lose connection with Domain Controllers configured for the ADQuery
Technical Level
Solution ID
sk113216
Technical Level
Product
Identity Awareness
Version
R77.30 (EOL)
Platform / Model
All
Date Created
06-Sep-2016
Last Modified
27-Jul-2017
Symptoms
Identity Awareness Gateway may lose connection with Domain Controllers configured for the ADQuery.
"Connectivity Error" is displayed in SmartView Monitor for several Domain Controllers.
Output of "adlog a dc" command on Identity Awareness Gateway shows "no connection" status for these Domain Controllers.
Example: my.domain.com 192.168.0.2 4870 no connection
The "test_ad_connectivity" tool (sk100406) on Identity Awareness Gateway returns success for both LDAP and WMI.
Cause
More than 256 Domain Controllers are configured for the ADQuery.
Current limit of Domain Controllers for ADQuery is 256. If there are more than 256 DCs configured for the ADQuery, Identity Awareness Gateway may lose connection with random DC.