<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Dynamic ports block for AD Server in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/Dynamic-ports-block-for-AD-Server/m-p/59423#M12002</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;guys i need a help from you. one of our cutomer has AD servers between a IPSec vpn tunnel. from ADserver 49152-65535 dynamics ports are not open, .both tunnel source and destination all ports are allowed.but there's no logs that prevent those ports Is there any specific configuration should do to allow those traffic?&lt;/P&gt;</description>
    <pubDate>Thu, 01 Aug 2019 08:29:26 GMT</pubDate>
    <dc:creator>samtech4u</dc:creator>
    <dc:date>2019-08-01T08:29:26Z</dc:date>
    <item>
      <title>Dynamic ports block for AD Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dynamic-ports-block-for-AD-Server/m-p/59423#M12002</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;guys i need a help from you. one of our cutomer has AD servers between a IPSec vpn tunnel. from ADserver 49152-65535 dynamics ports are not open, .both tunnel source and destination all ports are allowed.but there's no logs that prevent those ports Is there any specific configuration should do to allow those traffic?&lt;/P&gt;</description>
      <pubDate>Thu, 01 Aug 2019 08:29:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dynamic-ports-block-for-AD-Server/m-p/59423#M12002</guid>
      <dc:creator>samtech4u</dc:creator>
      <dc:date>2019-08-01T08:29:26Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic ports block for AD Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dynamic-ports-block-for-AD-Server/m-p/59480#M12021</link>
      <description>&lt;P&gt;It should work out of the box with ANY-ANY-Accept on the VPN rule. Do you see any suspicious drops?&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 10:43:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dynamic-ports-block-for-AD-Server/m-p/59480#M12021</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-08-02T10:43:47Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic ports block for AD Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dynamic-ports-block-for-AD-Server/m-p/59482#M12023</link>
      <description>&lt;P&gt;For the dynamic communication via Microsoft protocols you can use the "ALL_DCE_RPC" service. With these service you allow the dynamicly used high ports, without defined them explicitly.&lt;/P&gt;&lt;P&gt;Follow&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk65676" target="_self"&gt;configuration of rules with service all_dce_rpc&lt;/A&gt;&lt;/P&gt;&lt;P&gt;regards&lt;/P&gt;&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 11:42:41 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dynamic-ports-block-for-AD-Server/m-p/59482#M12023</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2019-08-02T11:42:41Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic ports block for AD Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dynamic-ports-block-for-AD-Server/m-p/59483#M12024</link>
      <description>&lt;P&gt;Right,&amp;nbsp;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/1447"&gt;@Wolfgang&lt;/a&gt;, that would be my second question. Without that, however, one should see some "telling" drops.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 11:54:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dynamic-ports-block-for-AD-Server/m-p/59483#M12024</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2019-08-02T11:54:19Z</dc:date>
    </item>
    <item>
      <title>Re: Dynamic ports block for AD Server</title>
      <link>https://community.checkpoint.com/t5/General-Topics/Dynamic-ports-block-for-AD-Server/m-p/59514#M12027</link>
      <description>&lt;P&gt;What connection do you have between the two VPN peers? It might be a MTU related issue.&lt;/P&gt;&lt;P&gt;Lowering ext. IF MTU or enabling MSS clamping for VPN might help in such cases.&lt;/P&gt;&lt;P&gt;You may test by using ping with bigger packet sizes and setting DF bit.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Aug 2019 18:30:19 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/Dynamic-ports-block-for-AD-Server/m-p/59514#M12027</guid>
      <dc:creator>Norbert_Bohusch</dc:creator>
      <dc:date>2019-08-02T18:30:19Z</dc:date>
    </item>
  </channel>
</rss>

