<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic IDC logs always &amp;quot;failed log in&amp;quot; or always &amp;quot;log in&amp;quot; in Firewall and Security Management</title>
    <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-logs-always-quot-failed-log-in-quot-or-always-quot-log-in/m-p/207454#M39241</link>
    <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;on a lab environment the logs are always and only "&lt;STRONG&gt;Log in&lt;/STRONG&gt;" so no "&lt;STRONG&gt;log out&lt;/STRONG&gt;" or "&lt;STRONG&gt;failed log in&lt;/STRONG&gt;" logs:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="collector7.JPG" style="width: 829px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24679iA20AA9299FDCB8D8/image-size/large?v=v2&amp;amp;px=999" role="button" title="collector7.JPG" alt="collector7.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Wireshark between the AD and the machine where IDC is installed shows this when trying wrong password, log in and log out:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="a1.JPG" style="width: 853px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24680i8FCF5EA003C310BC/image-size/large?v=v2&amp;amp;px=999" role="button" title="a1.JPG" alt="a1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="a2.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24681i49971203535D9A21/image-size/large?v=v2&amp;amp;px=999" role="button" title="a2.JPG" alt="a2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="a3.JPG" style="width: 876px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24682iDB263D2C82B7A816/image-size/large?v=v2&amp;amp;px=999" role="button" title="a3.JPG" alt="a3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In production environment the logs are "failed log in" or "log out" and no "log in" logs:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="a5.JPG" style="width: 290px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24683i8CEBF9F3C26D6B13/image-size/large?v=v2&amp;amp;px=999" role="button" title="a5.JPG" alt="a5.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;running wireshark between AD and the machine where IDC is installed shows no LDAP or kerberos packets between these machines, it shows only DCERPC packets!&lt;/P&gt;&lt;P&gt;the machine where IDC is installed is 10.32.0.166, same machine i run wireshark:&lt;/P&gt;&lt;P&gt;ip.addr == 10.8.0.12 and ldap shows nothing&lt;/P&gt;&lt;P&gt;ip.addr == 10.8.0.12 and kerberos shows nothing&lt;/P&gt;&lt;P&gt;only&amp;nbsp;ip.addr == 10.8.0.12 and dcerpc shows this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="a6.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24684iC226218E5568DDC8/image-size/large?v=v2&amp;amp;px=999" role="button" title="a6.JPG" alt="a6.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The question is why on lab environment I get only "log in" logs and why on production I get only "failed log in" or "log out"&amp;nbsp;&amp;nbsp;By the way the "failed log in" logs are not accurate because my environment is running with no problem.&lt;/P&gt;</description>
    <pubDate>Thu, 29 Feb 2024 09:32:11 GMT</pubDate>
    <dc:creator>Moudar</dc:creator>
    <dc:date>2024-02-29T09:32:11Z</dc:date>
    <item>
      <title>IDC logs always "failed log in" or always "log in"</title>
      <link>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-logs-always-quot-failed-log-in-quot-or-always-quot-log-in/m-p/207454#M39241</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;&lt;P&gt;on a lab environment the logs are always and only "&lt;STRONG&gt;Log in&lt;/STRONG&gt;" so no "&lt;STRONG&gt;log out&lt;/STRONG&gt;" or "&lt;STRONG&gt;failed log in&lt;/STRONG&gt;" logs:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="collector7.JPG" style="width: 829px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24679iA20AA9299FDCB8D8/image-size/large?v=v2&amp;amp;px=999" role="button" title="collector7.JPG" alt="collector7.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Wireshark between the AD and the machine where IDC is installed shows this when trying wrong password, log in and log out:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="a1.JPG" style="width: 853px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24680i8FCF5EA003C310BC/image-size/large?v=v2&amp;amp;px=999" role="button" title="a1.JPG" alt="a1.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="a2.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24681i49971203535D9A21/image-size/large?v=v2&amp;amp;px=999" role="button" title="a2.JPG" alt="a2.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="a3.JPG" style="width: 876px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24682iDB263D2C82B7A816/image-size/large?v=v2&amp;amp;px=999" role="button" title="a3.JPG" alt="a3.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In production environment the logs are "failed log in" or "log out" and no "log in" logs:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="a5.JPG" style="width: 290px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24683i8CEBF9F3C26D6B13/image-size/large?v=v2&amp;amp;px=999" role="button" title="a5.JPG" alt="a5.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;running wireshark between AD and the machine where IDC is installed shows no LDAP or kerberos packets between these machines, it shows only DCERPC packets!&lt;/P&gt;&lt;P&gt;the machine where IDC is installed is 10.32.0.166, same machine i run wireshark:&lt;/P&gt;&lt;P&gt;ip.addr == 10.8.0.12 and ldap shows nothing&lt;/P&gt;&lt;P&gt;ip.addr == 10.8.0.12 and kerberos shows nothing&lt;/P&gt;&lt;P&gt;only&amp;nbsp;ip.addr == 10.8.0.12 and dcerpc shows this:&lt;/P&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="a6.JPG" style="width: 999px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/24684iC226218E5568DDC8/image-size/large?v=v2&amp;amp;px=999" role="button" title="a6.JPG" alt="a6.JPG" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The question is why on lab environment I get only "log in" logs and why on production I get only "failed log in" or "log out"&amp;nbsp;&amp;nbsp;By the way the "failed log in" logs are not accurate because my environment is running with no problem.&lt;/P&gt;</description>
      <pubDate>Thu, 29 Feb 2024 09:32:11 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Firewall-and-Security-Management/IDC-logs-always-quot-failed-log-in-quot-or-always-quot-log-in/m-p/207454#M39241</guid>
      <dc:creator>Moudar</dc:creator>
      <dc:date>2024-02-29T09:32:11Z</dc:date>
    </item>
  </channel>
</rss>

