<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Priority value of the LDAP-Server is changing randomly in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201761#M37962</link>
    <description>&lt;P&gt;Good morning all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are facing a strange issue with the priority value of the configured LDAP-Server on the "User Directory" pane.&lt;/P&gt;&lt;P&gt;On the onsite gateways the priority is configured to prefer local LDAP-Server (On the gateway in the UK, UK-LDAP-Server does have Prio 1 and all other are on Prio 1001, on the Gateway in Peru the local Peru-LDAP-Server does have Prio 1 and all other are on Prio 1001.....and so on).&lt;/P&gt;&lt;P&gt;Double checking the priorities we can see that sometime the priority value is randomly changing on one Gateway.&lt;/P&gt;&lt;P&gt;In November the Priority on the Gateway in Ecuador was set to Prio 1 for the local LDAP-server and today it's set to Prio 1 for the LDAP-Server loacted in Spain.&lt;/P&gt;&lt;P&gt;All other priorities on all other gateways remain unaffected.&lt;/P&gt;&lt;P&gt;All Gateways are running R81.10 Take 96&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have no clue what is changing the priority values nor do I have any idea in which file I can find information about what is actually happening.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone here who knows this problem or knows where I can find the information for troubleshooting?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Much appreciate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Michael Menen&lt;/P&gt;</description>
    <pubDate>Fri, 29 Dec 2023 08:02:36 GMT</pubDate>
    <dc:creator>Michael_Menen</dc:creator>
    <dc:date>2023-12-29T08:02:36Z</dc:date>
    <item>
      <title>Priority value of the LDAP-Server is changing randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201761#M37962</link>
      <description>&lt;P&gt;Good morning all,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;we are facing a strange issue with the priority value of the configured LDAP-Server on the "User Directory" pane.&lt;/P&gt;&lt;P&gt;On the onsite gateways the priority is configured to prefer local LDAP-Server (On the gateway in the UK, UK-LDAP-Server does have Prio 1 and all other are on Prio 1001, on the Gateway in Peru the local Peru-LDAP-Server does have Prio 1 and all other are on Prio 1001.....and so on).&lt;/P&gt;&lt;P&gt;Double checking the priorities we can see that sometime the priority value is randomly changing on one Gateway.&lt;/P&gt;&lt;P&gt;In November the Priority on the Gateway in Ecuador was set to Prio 1 for the local LDAP-server and today it's set to Prio 1 for the LDAP-Server loacted in Spain.&lt;/P&gt;&lt;P&gt;All other priorities on all other gateways remain unaffected.&lt;/P&gt;&lt;P&gt;All Gateways are running R81.10 Take 96&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have no clue what is changing the priority values nor do I have any idea in which file I can find information about what is actually happening.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Anyone here who knows this problem or knows where I can find the information for troubleshooting?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Much appreciate&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Best regards&lt;/P&gt;&lt;P&gt;Michael Menen&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2023 08:02:36 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201761#M37962</guid>
      <dc:creator>Michael_Menen</dc:creator>
      <dc:date>2023-12-29T08:02:36Z</dc:date>
    </item>
    <item>
      <title>Re: Priority value of the LDAP-Server is changing randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201764#M37963</link>
      <description>&lt;P&gt;I would review&amp;nbsp;&lt;SPAN&gt;sk107378 for relevance and follow-up with TAC as appropriate.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Per sk44261 we plan to introduce a proximity based solution in future.&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2023 08:31:59 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201764#M37963</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2023-12-29T08:31:59Z</dc:date>
    </item>
    <item>
      <title>Re: Priority value of the LDAP-Server is changing randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201767#M37964</link>
      <description>&lt;P&gt;Make sure the fingerprint for Ecuador LDAP is the same as on LDAP itself. Within the main LDAP Account Unit, open Ecuador LDAP object and click on "fetch fingerprint". If you see change in the fingerprint, it is the cause why Ecuador LDAP was skipped, since fingerprint didnt match.&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2023 10:24:20 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201767#M37964</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2023-12-29T10:24:20Z</dc:date>
    </item>
    <item>
      <title>Re: Priority value of the LDAP-Server is changing randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201791#M37965</link>
      <description>&lt;P&gt;sk107378 has already been checked.&lt;/P&gt;&lt;P&gt;sk107378 is poiting the the issue, that priority value of an LDAP server changes automatically in all Security Gateways if priority was changed in one of these Security Gateways - but in my case nothing was changed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2023 13:14:17 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201791#M37965</guid>
      <dc:creator>Michael_Menen</dc:creator>
      <dc:date>2023-12-29T13:14:17Z</dc:date>
    </item>
    <item>
      <title>Re: Priority value of the LDAP-Server is changing randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201792#M37966</link>
      <description>&lt;P&gt;Not using fingerprints for LDAP-communication.&lt;/P&gt;&lt;P&gt;The issue with using fingerprints for LDAPS is, that a fingerprint might change if something is changing on the Windows LDAP-Server&lt;/P&gt;&lt;P&gt;sk42905 -&amp;gt; Workaround 2&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2023 13:18:57 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201792#M37966</guid>
      <dc:creator>Michael_Menen</dc:creator>
      <dc:date>2023-12-29T13:18:57Z</dc:date>
    </item>
    <item>
      <title>Re: Priority value of the LDAP-Server is changing randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201803#M37967</link>
      <description>&lt;P&gt;I searched for anything related to this in Guidbedit, but cant really find much.&lt;/P&gt;
&lt;P&gt;Might be worth opening TAC case to check further.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2023 15:55:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201803#M37967</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-29T15:55:55Z</dc:date>
    </item>
    <item>
      <title>Re: Priority value of the LDAP-Server is changing randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201813#M37968</link>
      <description>&lt;P&gt;How did you notice that the priority was changed by itself? Over SmartConsole ? Over CLI checking which LDAP is using port 389/636 (netstat -anop | grep 636 ) ?&lt;/P&gt;
&lt;P&gt;Did you try to use priority of 2, 3 for non-local LDAPs ? Why using 1001 if it should be used as a backup ?&lt;/P&gt;
&lt;P&gt;I can imagine that &lt;A href="https://support.checkpoint.com/results/sk/sk174664" target="_blank" rel="noopener"&gt;priority of 1001&lt;/A&gt; can be in some cases interpreted as 1 (as first digit is 1).&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2023 19:26:13 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201813#M37968</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2023-12-29T19:26:13Z</dc:date>
    </item>
    <item>
      <title>Re: Priority value of the LDAP-Server is changing randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201814#M37969</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/13874"&gt;@Michael_Menen&lt;/a&gt;&amp;nbsp;I see what&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1702"&gt;@JozkoMrkvicka&lt;/a&gt;&amp;nbsp;is saying...why use priority 1001 is they are supposed to be backup? Just use 2 or 3 or something close to 1, as 1 is always highest priority.&lt;/P&gt;
&lt;P&gt;Best,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Fri, 29 Dec 2023 19:27:08 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201814#M37969</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-12-29T19:27:08Z</dc:date>
    </item>
    <item>
      <title>Re: Priority value of the LDAP-Server is changing randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201843#M37978</link>
      <description>&lt;P&gt;in addition to that, if local prior 1 LDAP is for some reason down and not responding, all other non-local LDAPs shouldnt be used at all, since priority 1001 means they are skipped and not used at all. If the only usable LDAP (local, prior 1) is not working, the outage of VPN is very likely. This is logic problem and redundancy should be ensured (and tested) in such a case.&lt;/P&gt;</description>
      <pubDate>Sat, 30 Dec 2023 07:48:33 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201843#M37978</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2023-12-30T07:48:33Z</dc:date>
    </item>
    <item>
      <title>Re: Priority value of the LDAP-Server is changing randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201844#M37979</link>
      <description>&lt;P&gt;Did you check audit logs if someone else didnt change the LDAP priorities within gateway in Ecuador ? I had dozens of cases where someone from the firewall team did change something but didnt inform anyone about the change &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 30 Dec 2023 07:53:50 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/201844#M37979</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2023-12-30T07:53:50Z</dc:date>
    </item>
    <item>
      <title>Re: Priority value of the LDAP-Server is changing randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/202037#M38014</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;happy new year!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1) Using priority 1001 works fine most of the time, but it might be worth trying to change it to 8 or 9.&lt;/P&gt;&lt;P&gt;2) Priority is not only changing in Ecuador but randomly across the whole enviroment.&lt;/P&gt;&lt;P&gt;3) Double checking changes - no correlation.&lt;/P&gt;&lt;P&gt;4) A scheduled task is in place to check the priority every month. Last check the priority on the gateway in Ecuador has been canched. The check before nothing changed.&lt;/P&gt;&lt;P&gt;5) Nothing shown in the logs.&lt;/P&gt;&lt;P&gt;6) Because of nothing shown in the logs and the issue only occurs every 1 or 2 months we could not provide any logs and the TAC-case was closed.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 10:11:35 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/202037#M38014</guid>
      <dc:creator>Michael_Menen</dc:creator>
      <dc:date>2024-01-03T10:11:35Z</dc:date>
    </item>
    <item>
      <title>Re: Priority value of the LDAP-Server is changing randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/202140#M38033</link>
      <description>&lt;P&gt;all the best in 2024 ! &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;My suggestion is to schedule task to check current priority for 12 hours. You will have plenty of hours left once all logs (.elg files) are overwritten and possibly perform cpinfo/snapshot/backup on management and gateway to found the reason. At the same time re-open the case and provide needed debug files. On the other hand, there should be some debug plan available (from TAC/R&amp;amp;D) in case the issue happened again in the future.&lt;/P&gt;
&lt;P&gt;You may be even able to see if there is some pattern when exactly is the priority changed, if you check the current status more often (on daily/hours basis).&lt;/P&gt;</description>
      <pubDate>Wed, 03 Jan 2024 22:12:53 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/202140#M38033</guid>
      <dc:creator>JozkoMrkvicka</dc:creator>
      <dc:date>2024-01-03T22:12:53Z</dc:date>
    </item>
    <item>
      <title>Re: Priority value of the LDAP-Server is changing randomly</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/202662#M38134</link>
      <description>&lt;P&gt;Hi all,&lt;/P&gt;&lt;P&gt;totally agree that re-open the case will be the best we can do.&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;&lt;P&gt;Best regards.&lt;BR /&gt;Michael&lt;/P&gt;</description>
      <pubDate>Wed, 10 Jan 2024 08:00:00 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/Priority-value-of-the-LDAP-Server-is-changing-randomly/m-p/202662#M38134</guid>
      <dc:creator>Michael_Menen</dc:creator>
      <dc:date>2024-01-10T08:00:00Z</dc:date>
    </item>
  </channel>
</rss>

