Support Center > Search Results > SecureKnowledge Details
AD Query and Identity Logging do not work with Domain Controller on Windows Server 2022 Technical Level
Symptoms
  • The traffic is not matched to Identity Awareness Access Roles as expected.

  • SmartConsole logs from the Identity Awareness Gateway do not show User / Machine identities.

  • Output of the "adlog a dc" command on the Identity Awareness Gateway shows:

    [Expert@IDA_GW:0]# adlog a dc
    Domain controllers:
    Domain Name              IP Address                Events (last hour)   Connection state
    ===========================================================================================================
    <Name of Domain>        <IP Address>               0                    connection had internal error [ntstatus = 0x80010111]
    
    Ignored domain controllers on this gateway:
    No ignored domain controllers found.
    [Expert@IDA_GW:0]#
    
  • Output of the "adlog l dc" command on the Management Server shows:

    [Expert@MGMT:0]# adlog l dc
    Domain controllers:
    Domain Name              IP Address                Events (last hour)   Connection state
    ===========================================================================================================
    <Name of Domain>        <IP Address>               0                    bad credentials or firewall blocks DCOM traffic [ntstatus = 0xc0000022]
    
    Ignored domain controllers on this gateway:
    No ignored domain controllers found.
    [Expert@MGMT:0]#
    
  • When configuring the Identity Awareness Software Blade for the first time and selecting AD Query in the Identity Awareness Configuration wizard, the connectivity test might fail with this error:

    User is not a domain administrator, as such AD Query will not work.
    Click back and chose another authentication method.
    
Cause

Issue in Microsoft Windows Server 2022.


Solution

Check Point is working with Microsoft to resolve this issue.

These workarounds are available:

This solution has been verified for the specific scenario, described by the combination of Product, Version and Symptoms. It may not work in other scenarios.

Give us Feedback
Please rate this document
[1=Worst,5=Best]
Comment