<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Security Gateway to encrypt LDAP communication for Identity Awareness, port 389 vs 636 in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-to-encrypt-LDAP-communication-for-Identity/m-p/162201#M28810</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Make a packet capture while running on encrypted on port 389. You will see everything. This makes it vulnerable for men in the middle attacks. Attackers could steal or change data in the AD. I would strongly recommend to use 636 with fingerprint Check Point. The only downside for 636 in combination with Check Point is the random fingerprint changes. Please refer to this SK to get better understanding:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42905" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42905&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/td-p/100671" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/td-p/100671&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Wed, 16 Nov 2022 09:32:57 GMT</pubDate>
    <dc:creator>Lesley</dc:creator>
    <dc:date>2022-11-16T09:32:57Z</dc:date>
    <item>
      <title>Security Gateway to encrypt LDAP communication for Identity Awareness, port 389 vs 636</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-to-encrypt-LDAP-communication-for-Identity/m-p/162131#M28789</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Hello Gents,&lt;/P&gt;&lt;P&gt;Just seeking an opinion on how risky it would be to stick with port 389 over 636 for communication with domain controller.&lt;/P&gt;&lt;P&gt;Cheers,&lt;/P&gt;&lt;P&gt;CPter&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Nov 2022 13:17:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-to-encrypt-LDAP-communication-for-Identity/m-p/162131#M28789</guid>
      <dc:creator>checkpointer</dc:creator>
      <dc:date>2022-11-15T13:17:13Z</dc:date>
    </item>
    <item>
      <title>Re: Security Gateway to encrypt LDAP communication for Identity Awareness, port 389 vs 636</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-to-encrypt-LDAP-communication-for-Identity/m-p/162187#M28803</link>
      <description>&lt;P&gt;Suggest researching the relevant Microsoft recommendations and what they're enforcing, for example:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://support.microsoft.com/en-us/topic/2020-ldap-channel-binding-and-ldap-signing-requirements-for-windows-kb4520412-ef185fb8-00f7-167d-744c-f299a66fc00a" target="_blank"&gt;https://support.microsoft.com/en-us/topic/2020-ldap-channel-binding-and-ldap-signing-requirements-for-windows-kb4520412-ef185fb8-00f7-167d-744c-f299a66fc00a&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 01:53:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-to-encrypt-LDAP-communication-for-Identity/m-p/162187#M28803</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2022-11-16T01:53:22Z</dc:date>
    </item>
    <item>
      <title>Re: Security Gateway to encrypt LDAP communication for Identity Awareness, port 389 vs 636</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-to-encrypt-LDAP-communication-for-Identity/m-p/162201#M28810</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;Make a packet capture while running on encrypted on port 389. You will see everything. This makes it vulnerable for men in the middle attacks. Attackers could steal or change data in the AD. I would strongly recommend to use 636 with fingerprint Check Point. The only downside for 636 in combination with Check Point is the random fingerprint changes. Please refer to this SK to get better understanding:&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42905" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk42905&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;A href="https://community.checkpoint.com/t5/Security-Gateways/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/td-p/100671" target="_blank"&gt;https://community.checkpoint.com/t5/Security-Gateways/Check-Point-LDAPS-connection-breaks-everytime-AD-certificate-is/td-p/100671&amp;nbsp;&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 16 Nov 2022 09:32:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Security-Gateway-to-encrypt-LDAP-communication-for-Identity/m-p/162201#M28810</guid>
      <dc:creator>Lesley</dc:creator>
      <dc:date>2022-11-16T09:32:57Z</dc:date>
    </item>
  </channel>
</rss>

