<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How to decrypt LDAPs packets captured with tcpdump or fwmonitor in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-decrypt-LDAPs-packets-captured-with-tcpdump-or-fwmonitor/m-p/154650#M26243</link>
    <description>&lt;P&gt;Maybe you can start from other way around. You can check what is LDAP query which firewall is sending. You can then be 100% sure if that answer from LDAP is correct or not. You will need to enable VPN debugs on the firewall and examine vpnd.elg file.&lt;/P&gt;
&lt;P&gt;Another option to confirm where is the problem is to use "ldapsearch" command to query needed user groups and see the answer from LDAP.&lt;/P&gt;
&lt;P&gt;Sometimes it is better to open vendor case and get official answer from the vendor in order to convince the other end that the issue is/ is not on their end &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
    <pubDate>Sat, 06 Aug 2022 05:21:06 GMT</pubDate>
    <dc:creator>JozkoMrkvicka</dc:creator>
    <dc:date>2022-08-06T05:21:06Z</dc:date>
    <item>
      <title>How to decrypt LDAPs packets captured with tcpdump or fwmonitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-decrypt-LDAPs-packets-captured-with-tcpdump-or-fwmonitor/m-p/154636#M26237</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we have configured an LDAP account unit with two server using port tcp 636. We need understand if the LDAP servers answer to our query with the correct user_group. We did a tcpdump (or fwmonitor) but all packets collected are encrypted.&lt;/P&gt;&lt;P&gt;Is it possibile decrypt them?&lt;/P&gt;&lt;P&gt;Let me know&lt;/P&gt;&lt;P&gt;Massimiliano&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 11:48:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-decrypt-LDAPs-packets-captured-with-tcpdump-or-fwmonitor/m-p/154636#M26237</guid>
      <dc:creator>Massimiliano</dc:creator>
      <dc:date>2022-08-05T11:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: How to decrypt LDAPs packets captured with tcpdump or fwmonitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-decrypt-LDAPs-packets-captured-with-tcpdump-or-fwmonitor/m-p/154637#M26238</link>
      <description>&lt;P&gt;Use WireShark:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://ask.wireshark.org/question/2553/can-wireshark-decode-a-ldaps-conversation/" target="_blank" rel="noopener"&gt;https://ask.wireshark.org/question/2553/can-wireshark-decode-a-ldaps-conversation/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.golinuxcloud.com/analyze-ldap-traffic-with-wireshark/#Decrypting_LDAP_traffic" target="_blank" rel="noopener"&gt;https://www.golinuxcloud.com/analyze-ldap-traffic-with-wireshark/#Decrypting_LDAP_traffic&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 13:09:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-decrypt-LDAPs-packets-captured-with-tcpdump-or-fwmonitor/m-p/154637#M26238</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2022-08-05T13:09:16Z</dc:date>
    </item>
    <item>
      <title>Re: How to decrypt LDAPs packets captured with tcpdump or fwmonitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-decrypt-LDAPs-packets-captured-with-tcpdump-or-fwmonitor/m-p/154640#M26240</link>
      <description>&lt;P&gt;Sorry, but how I can recover the &lt;STRONG&gt;keylog&lt;/STRONG&gt; of the Security gateway? The LDAP connection is not between my pc and the LDAP server, but between FW and LDAP server.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 12:48:32 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-decrypt-LDAPs-packets-captured-with-tcpdump-or-fwmonitor/m-p/154640#M26240</guid>
      <dc:creator>Massimiliano</dc:creator>
      <dc:date>2022-08-05T12:48:32Z</dc:date>
    </item>
    <item>
      <title>Re: How to decrypt LDAPs packets captured with tcpdump or fwmonitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-decrypt-LDAPs-packets-captured-with-tcpdump-or-fwmonitor/m-p/154641#M26241</link>
      <description>&lt;P&gt;I think it would be much easier just to see LDAP logs&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 13:16:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-decrypt-LDAPs-packets-captured-with-tcpdump-or-fwmonitor/m-p/154641#M26241</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2022-08-05T13:16:20Z</dc:date>
    </item>
    <item>
      <title>Re: How to decrypt LDAPs packets captured with tcpdump or fwmonitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-decrypt-LDAPs-packets-captured-with-tcpdump-or-fwmonitor/m-p/154642#M26242</link>
      <description>&lt;P&gt;Yea, but from the log I saw the user_group "all_users"; so it seems that the LDAP server didn't send the correct user group. I need the packet capture, because the Microsoft guy (ower of the LDAP server) didn't saw any problem from his side. I need understand where is the issue and the logs is not enough.&lt;/P&gt;</description>
      <pubDate>Fri, 05 Aug 2022 13:21:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-decrypt-LDAPs-packets-captured-with-tcpdump-or-fwmonitor/m-p/154642#M26242</guid>
      <dc:creator>Massimiliano</dc:creator>
      <dc:date>2022-08-05T13:21:59Z</dc:date>
    </item>
    <item>
      <title>Re: How to decrypt LDAPs packets captured with tcpdump or fwmonitor</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-decrypt-LDAPs-packets-captured-with-tcpdump-or-fwmonitor/m-p/154650#M26243</link>
      <description>&lt;P&gt;Maybe you can start from other way around. You can check what is LDAP query which firewall is sending. You can then be 100% sure if that answer from LDAP is correct or not. You will need to enable VPN debugs on the firewall and examine vpnd.elg file.&lt;/P&gt;
&lt;P&gt;Another option to confirm where is the problem is to use "ldapsearch" command to query needed user groups and see the answer from LDAP.&lt;/P&gt;
&lt;P&gt;Sometimes it is better to open vendor case and get official answer from the vendor in order to convince the other end that the issue is/ is not on their end &lt;span class="lia-unicode-emoji" title=":winking_face:"&gt;😉&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Aug 2022 05:21:06 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/How-to-decrypt-LDAPs-packets-captured-with-tcpdump-or-fwmonitor/m-p/154650#M26243</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2022-08-06T05:21:06Z</dc:date>
    </item>
  </channel>
</rss>

