<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD Query server connection in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/57019#M12583</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;It looks like you are in the right direction with the DCE-RPC ports, I will explain why:&lt;/P&gt;
&lt;P&gt;LDAP connectivity is not related to the WMI connection which should be open between GW to AD.&lt;/P&gt;
&lt;P&gt;You can also see in the log:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;:status (SUCCESS_LDAP_WMI_NO_CONNECTIVITY)&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;:err_msg ("ADLOG_ERROR_NETWORK_PROBLEM;LDAP_SUCCESS")&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:ldap_status (LDAP_SUCCESS)&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;:wmi_status (ADLOG_ERROR_NETWORK_PROBLEM)&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;:timestamp ("Thu Jun 27 16:55:30 2019")&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Royi.&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Sun, 30 Jun 2019 07:01:52 GMT</pubDate>
    <dc:creator>Royi_Priov</dc:creator>
    <dc:date>2019-06-30T07:01:52Z</dc:date>
    <item>
      <title>AD Query server connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/56885#M12576</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Wondering if anyone has ideas on this issue, I have 2 clusters (same policy). On one cluster it can successfully connect and receive login events from two domain controllers, on the other cluster I get the message "no connectivity, connection refused by remote host [ntstatus = 0xc0000236]"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Both clusters use the same login credentials,&amp;nbsp; both clusters can telnet to the server IP's on port 389 and 636. I have also connected to the server and checked event viewer. I don't see any errors it all says success.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I use the test_ad_connectivity tool I get the following:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;:status (SUCCESS_LDAP_WMI_NO_CONNECTIVITY)&lt;BR /&gt;:err_msg ("ADLOG_ERROR_NETWORK_PROBLEM;LDAP_SUCCESS")&lt;BR /&gt;:ldap_status (LDAP_SUCCESS)&lt;BR /&gt;:wmi_status (ADLOG_ERROR_NETWORK_PROBLEM)&lt;BR /&gt;:timestamp ("Thu Jun 27 16:55:30 2019")&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any ideas what this could be?&lt;/P&gt;&lt;P&gt;thanks&lt;/P&gt;</description>
      <pubDate>Thu, 27 Jun 2019 22:16:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/56885#M12576</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2019-06-27T22:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query server connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/56899#M12577</link>
      <description>Can you check with ldapsearch instead?&lt;BR /&gt;See: &lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk55040" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk55040&lt;/A&gt;</description>
      <pubDate>Thu, 27 Jun 2019 23:21:03 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/56899#M12577</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-27T23:21:03Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query server connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/56904#M12578</link>
      <description>&lt;P&gt;Hi good idea,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried that and can confirm it has successfully queried and returns correct information from ldap.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 02:03:48 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/56904#M12578</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2019-06-28T02:03:48Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query server connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/56918#M12579</link>
      <description>&lt;P&gt;Unless&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/8232"&gt;@Royi_Priov&lt;/a&gt;&amp;nbsp;or someone from R&amp;amp;D has an idea, I suggest opening a TAC case.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 03:31:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/56918#M12579</guid>
      <dc:creator>PhoneBoy</dc:creator>
      <dc:date>2019-06-28T03:31:46Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query server connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/56919#M12580</link>
      <description>&lt;P&gt;I might have found the issue, if there is another f/w between the gateway and the domain controller it appears you need to open:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tcp/389 or tcp/636&lt;/P&gt;&lt;P&gt;tcp/135&lt;/P&gt;&lt;P&gt;tcp/1025-65535&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;For full connectivity. Will update once we have opened ports and confirmed.&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 04:13:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/56919#M12580</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2019-06-28T04:13:08Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query server connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/56922#M12581</link>
      <description>&lt;P&gt;Hi Ryan,&lt;/P&gt;&lt;P&gt;You do need RPC communication for AD Query to work, but you don't need all "tcp-high-ports".&lt;/P&gt;&lt;P&gt;49152-65535 is the Microsoft specified range required, and it's what we use for our AD Query setups.&lt;/P&gt;&lt;P&gt;(In addtition to tcp/636 and tcp/135)&lt;/P&gt;&lt;P&gt;/Sigbjorn&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 05:38:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/56922#M12581</guid>
      <dc:creator>Sigbjorn</dc:creator>
      <dc:date>2019-06-28T05:38:01Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query server connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/56941#M12582</link>
      <description>&lt;P&gt;Hi Ryan,&lt;/P&gt;
&lt;P&gt;I am sure that firewall in between is the issue. You need to open required ports on that firewall&lt;/P&gt;</description>
      <pubDate>Fri, 28 Jun 2019 09:54:02 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/56941#M12582</guid>
      <dc:creator>Gaurav_Pandya</dc:creator>
      <dc:date>2019-06-28T09:54:02Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query server connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/57019#M12583</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;It looks like you are in the right direction with the DCE-RPC ports, I will explain why:&lt;/P&gt;
&lt;P&gt;LDAP connectivity is not related to the WMI connection which should be open between GW to AD.&lt;/P&gt;
&lt;P&gt;You can also see in the log:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;:status (SUCCESS_LDAP_WMI_NO_CONNECTIVITY)&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;:err_msg ("ADLOG_ERROR_NETWORK_PROBLEM;LDAP_SUCCESS")&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;:ldap_status (LDAP_SUCCESS)&lt;/SPAN&gt;&lt;BR /&gt;&lt;STRONG&gt;:wmi_status (ADLOG_ERROR_NETWORK_PROBLEM)&lt;/STRONG&gt;&lt;BR /&gt;&lt;SPAN&gt;:timestamp ("Thu Jun 27 16:55:30 2019")&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Thanks,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Royi.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 30 Jun 2019 07:01:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/57019#M12583</guid>
      <dc:creator>Royi_Priov</dc:creator>
      <dc:date>2019-06-30T07:01:52Z</dc:date>
    </item>
    <item>
      <title>Re: AD Query server connection</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/57413#M12584</link>
      <description>&lt;P&gt;confirmed it was the f/w ports needing to be opened. working now!&lt;/P&gt;</description>
      <pubDate>Thu, 04 Jul 2019 03:38:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/AD-Query-server-connection/m-p/57413#M12584</guid>
      <dc:creator>Ryan_Ryan</dc:creator>
      <dc:date>2019-07-04T03:38:09Z</dc:date>
    </item>
  </channel>
</rss>

