> Source: [sk135872](https://support.checkpoint.com/results/sk/sk135872)

# sk135872 - "No matches found" error when configuring an AD Authentication Server on Embedded Gaia appliance

| Property | Value |
|----------|-------|
| Solution ID | sk135872 |
| Date Created | 2018-09-06 |
| Last Modified | 2020-04-22 |
| Technical Level | General |
| Products | Spark Firewall (Locally Managed) |
| Versions | R82.00.X, R81.10.X |
| Platform | 910 |

## Symptoms

- * "No matches found" validation error for the Domain Name when clicking "Discover".
* Error message "An error has occurred while reading groups from the Active Directory".

## Cause

The AD Server netBiosName (pre win-2000) contains '\&' character in its name:e.g.: check-point is check\&point.

## Solution

1. Click 'Users \& Objects \> Authentication Servers \> New'.  

2. Fill in the Domain, IPv4 address, User name and Password field.  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1536158778591/useawareness1809050821.png)  
   Important Notes:  
   The user needs to be assigned to the "Domain Admin" and "Schema Admin" groups in AD.   
   If domain name DOES NOT MATCH the NetBIOS name, you will need to use NetBIOSname\\username in "User name" field.  
   For example: Domain name is CheckPoint with suffix .local  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1536158778591/AD1809050828.png)  

   Righ-click the domain and click Properties to find the NetBIOS name, CHECK\&POINT.  

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/NEW_SK_NOID1536158778591/AD21809050829.png)  

   The user name will be CHECK\&POINT\\adadmin  

   The firewall automatically appends the domain name to user name when authenticating. If NetBIOS name doesn't match domain name, the bind will fail.

3. Click on Discover and if the information is correct, User DN will populate.

4. Query the AD, VPN \> Remote Access Users \> Add \> Active Directory Group

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk135872/test11809050857.PNG)

You should now see your AD groups:

![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk135872/test21809050858.PNG)

**Related Solutions:**

* [sk105977 - There is no option to add specific Active Directory users and organization units inside policy rules, when using Identity Awareness blade on SMB appliances](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk105977)
* [sk116338 - How to configure User Awareness to see Specific Active Directory Organization Unit on SMB appliance](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk116338)
* [sk121442 - Failed to see all Active Directory groups in locally managed SMB appliance](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk121442)
* [sk123614 - Cannot add an Active Directory Group to Remote Access VPN on SMB Appliances](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk123614)

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
