> Source: [sk139652](https://support.checkpoint.com/results/sk/sk139652)

# sk139652 - ClusterXL failover leads to Firewall Service Account being locked out by AD environment

| Property | Value |
|----------|-------|
| Solution ID | sk139652 |
| Date Created | 2018-11-13 |
| Last Modified | 2021-04-04 |
| Technical Level | Advanced |
| Products | Security Gateway |
| Versions | R82.10, R82, R81.20 |

## Symptoms

- * When a ClusterXL failover occurs, the newly active gateway has the Identity Awareness service account locked out by the AD environment.

* Running wmi/test_ad_connectivity (according to [sk100406](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk100406)) output:  


  :status (BAD_USER_OR_PASS)  

  :err_msg ("ADLOG_ERROR_BAD_CREDS;LDAP_PROTOCOL_ERROR")  

  :ldap_status (LDAP_PROTOCOL_ERROR)  

  :wmi_status (ADLOG_ERROR_BAD_CREDS)

* Output from running adlog debug (according to [sk113747](https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&solutionid=sk113747)):  

  `
  [ ADLOG_DCOM (TD::Important)] ADLOG::DcomWmiBasicProtocol::DataReceived: received data from query engine:
  $$START$$ error: ntstatus = 0xc0000022 $$END$$`  
  `
  [ADLOG_DCOM (TD::All)] ADLOG::DcomWmiLogicLayer::handleError: error code indicates: bad credentials`

* Testing when using only port 389, the traffic captures show that both cluster members are using the same CN and password in the authentication process.

## Cause

The NTLM version being used during the authentication process differ between the ClusterXL members. One cluster member is using the same NTLM version as the involved Domain Controllers and the other cluster member is not.

## Solution

This solution requires authentication. Please log in to view the full solution.

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
