<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: After Upgrading R81 LDAPS communiction stops working in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-Upgrading-R81-LDAPS-communiction-stops-working/m-p/120390#M17062</link>
    <description>&lt;P&gt;I know this is late, but as I recently ran across the issue after an upgrade I wanted to share what I found to fix my LDAPS issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After upgrading to R80.40 from R80.10 I was no longer able to fetch the fingerprints from the LDAPS servers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking in the logs, the connection attempt from the SMS to the remote LDAP servers was not being sent across the site-to-site VPN. Instead, it was being NAT'd out to the public IP address and attempting to reach the private IP address of the remote LDAP server.&lt;/P&gt;&lt;P&gt;It turns out, the LDAP service was hitting the implied rule for routing and never making it to the explicit rule to use the VPN connection. This is by design and can be changed using the SK and references below.&lt;/P&gt;&lt;P&gt;***** The change does not survive a major upgrade. *****&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk26059&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk26059&amp;amp;partition=Advanced&amp;amp;product=IPSec&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92281" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92281&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 04 Jun 2021 18:22:18 GMT</pubDate>
    <dc:creator>Gabe_Flynn</dc:creator>
    <dc:date>2021-06-04T18:22:18Z</dc:date>
    <item>
      <title>After Upgrading R81 LDAPS communiction stops working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-Upgrading-R81-LDAPS-communiction-stops-working/m-p/112235#M15564</link>
      <description>&lt;P&gt;Dear Team ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;WE have&amp;nbsp; MGMT at HO location (VM) which we have recently upgraded from R80.30 to R81&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;And some branch location Security Gateways also we have upgraded To r81 from R80.30&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;HUB and Spoke topology - Star VPN is working properly earlier and after R81 some time we are getting disconnection issue .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Also I want to create User based Policy and want add user group in Access role for which i am getting error .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I am enabling LDAPS and trying to fetch certificate but getting error&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;"Faild to connect to LDAP server connection failed&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Traffic we can see from MGMT to Server till Branch Gateway after we are not getting traffic and in log -VPN encryption showing decryption not showing&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please give us idea if anyone have same issue .&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Harmesh Yadav&lt;/P&gt;&lt;P&gt;9978440755&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Mar 2021 03:55:52 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-Upgrading-R81-LDAPS-communiction-stops-working/m-p/112235#M15564</guid>
      <dc:creator>Harmesh_Yadav</dc:creator>
      <dc:date>2021-03-06T03:55:52Z</dc:date>
    </item>
    <item>
      <title>Re: After Upgrading R81 LDAPS communiction stops working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-Upgrading-R81-LDAPS-communiction-stops-working/m-p/112437#M15605</link>
      <description>&lt;P&gt;Dear Team ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I am waiting for your reply it will be very helpful&lt;/P&gt;</description>
      <pubDate>Thu, 04 Mar 2021 05:10:46 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-Upgrading-R81-LDAPS-communiction-stops-working/m-p/112437#M15605</guid>
      <dc:creator>Harmesh_Yadav</dc:creator>
      <dc:date>2021-03-04T05:10:46Z</dc:date>
    </item>
    <item>
      <title>Re: After Upgrading R81 LDAPS communiction stops working</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-Upgrading-R81-LDAPS-communiction-stops-working/m-p/120390#M17062</link>
      <description>&lt;P&gt;I know this is late, but as I recently ran across the issue after an upgrade I wanted to share what I found to fix my LDAPS issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After upgrading to R80.40 from R80.10 I was no longer able to fetch the fingerprints from the LDAPS servers.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Looking in the logs, the connection attempt from the SMS to the remote LDAP servers was not being sent across the site-to-site VPN. Instead, it was being NAT'd out to the public IP address and attempting to reach the private IP address of the remote LDAP server.&lt;/P&gt;&lt;P&gt;It turns out, the LDAP service was hitting the implied rule for routing and never making it to the explicit rule to use the VPN connection. This is by design and can be changed using the SK and references below.&lt;/P&gt;&lt;P&gt;***** The change does not survive a major upgrade. *****&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk26059&amp;amp;partition=Advanced&amp;amp;product=IPSec" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk26059&amp;amp;partition=Advanced&amp;amp;product=IPSec&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92281" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk92281&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 04 Jun 2021 18:22:18 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/After-Upgrading-R81-LDAPS-communiction-stops-working/m-p/120390#M17062</guid>
      <dc:creator>Gabe_Flynn</dc:creator>
      <dc:date>2021-06-04T18:22:18Z</dc:date>
    </item>
  </channel>
</rss>

