<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: domain-udp Decrypted in community RemoteAccess in SASE and Remote Access</title>
    <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/domain-udp-Decrypted-in-community-RemoteAccess/m-p/182630#M4898</link>
    <description>&lt;P&gt;Maybe try newest VPN client to see if it makes any difference. Only other reason I can think of would be maybe some 3rd party software possibly causing this. Other than that, maybe engage TAC, but not real sure how much they can do either, considering its definitely not the FW issue.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
    <pubDate>Wed, 31 May 2023 01:21:37 GMT</pubDate>
    <dc:creator>the_rock</dc:creator>
    <dc:date>2023-05-31T01:21:37Z</dc:date>
    <item>
      <title>domain-udp Decrypted in community RemoteAccess</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/domain-udp-Decrypted-in-community-RemoteAccess/m-p/182580#M4895</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;we have about 100 VPN users. Some use CP mobile, some SecureRemote.&lt;/P&gt;&lt;P&gt;Only one user have some problem. On his site, he doesn't have any problems. But in log file, there is record every 20-40sec. Copy is down below.&lt;/P&gt;&lt;P&gt;I did try to fresh install client and also tries his credentials on new PC, but problem remains.&lt;/P&gt;&lt;P&gt;Why is his computer try to connect to DC every few seconds? He only use VPN for RDP, but even if he only establishes VPN without RDP connection, logs are full with same message as copy of log bellow.&lt;/P&gt;&lt;P&gt;Did try with win10 and win11. All other users doesn't create logs like one bellow&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Interface Direction: inbound&lt;/P&gt;&lt;P&gt;Id Generated By Indexer: false&lt;BR /&gt;First: true&lt;BR /&gt;Sequencenum: 1&lt;BR /&gt;Source Zone: External&lt;BR /&gt;Destination Zone: Internal&lt;BR /&gt;Service ID: domain-udp&lt;BR /&gt;Source: 10.18.252.27&lt;BR /&gt;Source Port: 58782&lt;BR /&gt;Destination: 10.18.205.35&lt;BR /&gt;Destination Port: 53&lt;BR /&gt;IP Protocol: 17&lt;BR /&gt;Scheme: IKE&lt;BR /&gt;Methods: ESP: 3DES + SHA1&lt;BR /&gt;VPN Peer Gateway: 10.18.252.27&lt;BR /&gt;Community: RemoteAccess&lt;BR /&gt;VPN Feature: VPN&lt;BR /&gt;Action: Decrypt&lt;BR /&gt;Type: Connection&lt;BR /&gt;Blade: VPN&lt;BR /&gt;Service: UDP/53&lt;BR /&gt;Product Family: Access&lt;BR /&gt;Logid: 0&lt;BR /&gt;Access Rule Name: VPN Support&lt;BR /&gt;Description: Decrypted in community RemoteAccess&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 17:39:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/domain-udp-Decrypted-in-community-RemoteAccess/m-p/182580#M4895</guid>
      <dc:creator>WhOPP</dc:creator>
      <dc:date>2023-05-30T17:39:16Z</dc:date>
    </item>
    <item>
      <title>Re: domain-udp Decrypted in community RemoteAccess</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/domain-udp-Decrypted-in-community-RemoteAccess/m-p/182586#M4896</link>
      <description>&lt;P&gt;If I were you, since you say its just 1 single user, I would maybe have them delete/re-create VPN site, if that fails, have them reinstall the vpn client (maybe try latest one, E87.30)&lt;/P&gt;
&lt;P&gt;Cheers,&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 17:47:47 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/domain-udp-Decrypted-in-community-RemoteAccess/m-p/182586#M4896</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-30T17:47:47Z</dc:date>
    </item>
    <item>
      <title>Re: domain-udp Decrypted in community RemoteAccess</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/domain-udp-Decrypted-in-community-RemoteAccess/m-p/182598#M4897</link>
      <description>&lt;P&gt;Hi, thanks for replay&lt;/P&gt;&lt;P&gt;I did delete user and create new one with new certificate. Also reinstalled client on his PC and also try with new clean VM but results are same.&lt;/P&gt;&lt;P&gt;All users use same client&lt;/P&gt;&lt;P&gt;&lt;A href="https://supportcenter.checkpoint.com/supportcenter/portal/user/anon/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=118725" target="_blank"&gt;https://supportcenter.checkpoint.com/supportcenter/portal/user/anon/page/default.psml/media-type/html?action=portlets.DCFileAction&amp;amp;eventSubmit_doGetdcdetails=&amp;amp;fileid=118725&lt;/A&gt;&lt;/P&gt;&lt;P&gt;FW is R81.10&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 30 May 2023 18:09:24 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/domain-udp-Decrypted-in-community-RemoteAccess/m-p/182598#M4897</guid>
      <dc:creator>WhOPP</dc:creator>
      <dc:date>2023-05-30T18:09:24Z</dc:date>
    </item>
    <item>
      <title>Re: domain-udp Decrypted in community RemoteAccess</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/domain-udp-Decrypted-in-community-RemoteAccess/m-p/182630#M4898</link>
      <description>&lt;P&gt;Maybe try newest VPN client to see if it makes any difference. Only other reason I can think of would be maybe some 3rd party software possibly causing this. Other than that, maybe engage TAC, but not real sure how much they can do either, considering its definitely not the FW issue.&lt;/P&gt;
&lt;P&gt;Andy&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 01:21:37 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/domain-udp-Decrypted-in-community-RemoteAccess/m-p/182630#M4898</guid>
      <dc:creator>the_rock</dc:creator>
      <dc:date>2023-05-31T01:21:37Z</dc:date>
    </item>
    <item>
      <title>Re: domain-udp Decrypted in community RemoteAccess</title>
      <link>https://community.checkpoint.com/t5/SASE-and-Remote-Access/domain-udp-Decrypted-in-community-RemoteAccess/m-p/182648#M4899</link>
      <description>&lt;P&gt;The client is dowing DNS requests. I guess it is perfectly normal.&lt;/P&gt;</description>
      <pubDate>Wed, 31 May 2023 08:21:45 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/SASE-and-Remote-Access/domain-udp-Decrypted-in-community-RemoteAccess/m-p/182648#M4899</guid>
      <dc:creator>_Val_</dc:creator>
      <dc:date>2023-05-31T08:21:45Z</dc:date>
    </item>
  </channel>
</rss>

