<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic RPC traffic on port 135 getting blocked on Checkpoint firewall intermittently. in General Topics</title>
    <link>https://community.checkpoint.com/t5/General-Topics/RPC-traffic-on-port-135-getting-blocked-on-Checkpoint-firewall/m-p/87428#M17596</link>
    <description>&lt;P&gt;&lt;FONT face="Calibri" size="3"&gt;RPC traffic on port 135 getting blocked on Checkpoint firewall intermittently. Getting error “Blocked MS-RPC non compliant version”.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri" size="3"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="M3.jpg" style="width: 754px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6364i3E91201FD15A0166/image-size/large?v=v2&amp;amp;px=999" role="button" title="M3.jpg" alt="M3.jpg" /&gt;&lt;/span&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
    <pubDate>Fri, 05 Jun 2020 13:08:55 GMT</pubDate>
    <dc:creator>Prime</dc:creator>
    <dc:date>2020-06-05T13:08:55Z</dc:date>
    <item>
      <title>RPC traffic on port 135 getting blocked on Checkpoint firewall intermittently.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/RPC-traffic-on-port-135-getting-blocked-on-Checkpoint-firewall/m-p/87428#M17596</link>
      <description>&lt;P&gt;&lt;FONT face="Calibri" size="3"&gt;RPC traffic on port 135 getting blocked on Checkpoint firewall intermittently. Getting error “Blocked MS-RPC non compliant version”.&lt;/FONT&gt;&lt;/P&gt;&lt;P&gt;&lt;FONT face="Calibri" size="3"&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="M3.jpg" style="width: 754px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6364i3E91201FD15A0166/image-size/large?v=v2&amp;amp;px=999" role="button" title="M3.jpg" alt="M3.jpg" /&gt;&lt;/span&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 13:08:55 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/RPC-traffic-on-port-135-getting-blocked-on-Checkpoint-firewall/m-p/87428#M17596</guid>
      <dc:creator>Prime</dc:creator>
      <dc:date>2020-06-05T13:08:55Z</dc:date>
    </item>
    <item>
      <title>Re: RPC traffic on port 135 getting blocked on Checkpoint firewall intermittently.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/RPC-traffic-on-port-135-getting-blocked-on-Checkpoint-firewall/m-p/87454#M17601</link>
      <description>&lt;P&gt;&lt;SPAN&gt;We noticed this issue today. Server is unable to connect to the domain controller from last 3 days.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;After changing the inspection configuration for Non compliant MS RPC to accept, we now see one packet allowed and one packet denied with same error.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;R80.10&lt;/SPAN&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="sccm error.PNG" style="width: 666px;"&gt;&lt;img src="https://community.checkpoint.com/t5/image/serverpage/image-id/6365i9A95D20C4A9AAA8D/image-size/large?v=v2&amp;amp;px=999" role="button" title="sccm error.PNG" alt="sccm error.PNG" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 19:06:01 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/RPC-traffic-on-port-135-getting-blocked-on-Checkpoint-firewall/m-p/87454#M17601</guid>
      <dc:creator>Prime</dc:creator>
      <dc:date>2020-06-05T19:06:01Z</dc:date>
    </item>
    <item>
      <title>Re: RPC traffic on port 135 getting blocked on Checkpoint firewall intermittently.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/RPC-traffic-on-port-135-getting-blocked-on-Checkpoint-firewall/m-p/87455#M17602</link>
      <description>&lt;P&gt;&lt;a href="https://community.checkpoint.com/t5/user/viewprofilepage/user-id/43914"&gt;@Prime&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;did you create recently the new service „TCP_135“ and used them in your policy?&lt;/P&gt;
&lt;P&gt;It‘s better to use the default „ALL_DCE_RPC“-service for Microsoft connections on port tcp/135.&lt;/P&gt;
&lt;P&gt;Follow&amp;nbsp;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?action=portlets.SearchResultMainAction&amp;amp;eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk65676" target="_blank" rel="noopener"&gt;DCE-RPC traffic is dropped on High Ports&lt;/A&gt;&amp;nbsp;, I think this should help.&lt;/P&gt;
&lt;P&gt;Wolfgang&lt;/P&gt;</description>
      <pubDate>Fri, 05 Jun 2020 19:52:51 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/RPC-traffic-on-port-135-getting-blocked-on-Checkpoint-firewall/m-p/87455#M17602</guid>
      <dc:creator>Wolfgang</dc:creator>
      <dc:date>2020-06-05T19:52:51Z</dc:date>
    </item>
    <item>
      <title>Re: RPC traffic on port 135 getting blocked on Checkpoint firewall intermittently.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/RPC-traffic-on-port-135-getting-blocked-on-Checkpoint-firewall/m-p/87461#M17604</link>
      <description>Will the use of a DCE/RPC service will stop SecureXL's ?</description>
      <pubDate>Fri, 05 Jun 2020 22:54:22 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/RPC-traffic-on-port-135-getting-blocked-on-Checkpoint-firewall/m-p/87461#M17604</guid>
      <dc:creator>Prime</dc:creator>
      <dc:date>2020-06-05T22:54:22Z</dc:date>
    </item>
    <item>
      <title>Re: RPC traffic on port 135 getting blocked on Checkpoint firewall intermittently.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/RPC-traffic-on-port-135-getting-blocked-on-Checkpoint-firewall/m-p/87467#M17607</link>
      <description>&lt;P&gt;Consider the rule placement per&amp;nbsp;&lt;SPAN&gt;sk32578&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jun 2020 02:12:09 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/RPC-traffic-on-port-135-getting-blocked-on-Checkpoint-firewall/m-p/87467#M17607</guid>
      <dc:creator>Chris_Atkinson</dc:creator>
      <dc:date>2020-06-06T02:12:09Z</dc:date>
    </item>
    <item>
      <title>Re: RPC traffic on port 135 getting blocked on Checkpoint firewall intermittently.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/RPC-traffic-on-port-135-getting-blocked-on-Checkpoint-firewall/m-p/87468#M17608</link>
      <description>&lt;P&gt;Use of a DCE/RPC service in a rule will stop SecureXL Accept templating but not affect whether or how the traffic can be accelerated.&amp;nbsp; So try to place the rule permitting DCE/RPC as far down as possible in your rule base.&lt;/P&gt;</description>
      <pubDate>Sat, 06 Jun 2020 02:17:21 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/RPC-traffic-on-port-135-getting-blocked-on-Checkpoint-firewall/m-p/87468#M17608</guid>
      <dc:creator>Timothy_Hall</dc:creator>
      <dc:date>2020-06-06T02:17:21Z</dc:date>
    </item>
    <item>
      <title>Re: RPC traffic on port 135 getting blocked on Checkpoint firewall intermittently.</title>
      <link>https://community.checkpoint.com/t5/General-Topics/RPC-traffic-on-port-135-getting-blocked-on-Checkpoint-firewall/m-p/87577#M17635</link>
      <description>Error:-Blocked MS-RPC non compliant version&lt;BR /&gt;we followed SK66605 file in order to resolve the issue.&lt;BR /&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk66605&amp;amp;partition=Advanced&amp;amp;product=Security" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal?eventSubmit_doGoviewsolutiondetails=&amp;amp;solutionid=sk66605&amp;amp;partition=Advanced&amp;amp;product=Security&lt;/A&gt;&lt;BR /&gt;&lt;BR /&gt;Edited the $FWDIR/lib/table.def file&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;fw_dcerpc_map_ports = { &amp;lt;135&amp;gt; };&lt;BR /&gt;to&lt;BR /&gt;fw_dcerpc_map_ports = { };&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt;We disabled the extra rule which was used for per-defined service DCERPC.&lt;BR /&gt;&lt;BR /&gt;&amp;gt;&amp;gt;&amp;gt;Post that pushed the policy, Traffic started to work and able to join the domain.</description>
      <pubDate>Mon, 08 Jun 2020 08:09:54 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/General-Topics/RPC-traffic-on-port-135-getting-blocked-on-Checkpoint-firewall/m-p/87577#M17635</guid>
      <dc:creator>Prime</dc:creator>
      <dc:date>2020-06-08T08:09:54Z</dc:date>
    </item>
  </channel>
</rss>

