<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Which traffic does LDAP use.? in Spark Firewall (SMB)</title>
    <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Which-traffic-does-LDAP-use/m-p/14314#M354</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That should be possible by checking the LDAP server IP and the VPN community settings. All traffic to the remote site on SMBs goes thru the VPN tunnel, in WebGUI we only can exclude admin access traffic to the gateway by the &lt;EM&gt;Advanced Setting &amp;gt; VPN Site to Site global settings - Override 'Route all traffic to remote VPN site' configuration&amp;nbsp;for admin access to the device&lt;/EM&gt;. Or, you can use a special configuration file, see &lt;A href="https://community.checkpoint.com/docs/DOC-2834"&gt;Locally managed SMBs vpn_table.def file&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Strange is that you are using this 1470 like a 770 - using central management would make it easy to exclude services from VPN, also enable the second processor core and even give you logs with names &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt;...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 12 Apr 2018 08:38:10 GMT</pubDate>
    <dc:creator>G_W_Albrecht</dc:creator>
    <dc:date>2018-04-12T08:38:10Z</dc:date>
    <item>
      <title>Which traffic does LDAP use.?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Which-traffic-does-LDAP-use/m-p/14309#M349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Checkmates,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I would like to ask about the status for this 1470 firewall.&lt;/P&gt;&lt;P&gt;Regarding the LDAP traffic which is about 40MB.&lt;/P&gt;&lt;P&gt;Does it mean it is using the site to site traffic or some internet connection got ldap protocol?&lt;/P&gt;&lt;P&gt;&lt;IMG alt="" class="image-1 jive-image j-img-original" src="https://community.checkpoint.com/legacyfs/online/checkpoint/64521_LDAP.jpeg" style="width: 620px; height: 240px;" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2018 04:56:27 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Which-traffic-does-LDAP-use/m-p/14309#M349</guid>
      <dc:creator>Aznaz_Reflectio</dc:creator>
      <dc:date>2018-04-11T04:56:27Z</dc:date>
    </item>
    <item>
      <title>Re: Which traffic does LDAP use.?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Which-traffic-does-LDAP-use/m-p/14310#M350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Aznaz,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;see&amp;nbsp;&lt;A href="https://community.checkpoint.com/docs/DOC-2740"&gt;Ports Used for Communication by Various Check Point Modules (new version)&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Heiko&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2018 05:27:31 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Which-traffic-does-LDAP-use/m-p/14310#M350</guid>
      <dc:creator>HeikoAnkenbrand</dc:creator>
      <dc:date>2018-04-11T05:27:31Z</dc:date>
    </item>
    <item>
      <title>Re: Which traffic does LDAP use.?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Which-traffic-does-LDAP-use/m-p/14311#M351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Aznaz,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I believe this graphic shows statistics for all the traffic, not only from the internet, so this&amp;nbsp;could be ldap from the site-to-site traffic.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Apr 2018 14:27:23 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Which-traffic-does-LDAP-use/m-p/14311#M351</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-04-11T14:27:23Z</dc:date>
    </item>
    <item>
      <title>Re: Which traffic does LDAP use.?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Which-traffic-does-LDAP-use/m-p/14312#M352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the information sharing..&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 02:43:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Which-traffic-does-LDAP-use/m-p/14312#M352</guid>
      <dc:creator>Aznaz_Reflectio</dc:creator>
      <dc:date>2018-04-12T02:43:26Z</dc:date>
    </item>
    <item>
      <title>Re: Which traffic does LDAP use.?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Which-traffic-does-LDAP-use/m-p/14313#M353</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;is there any way for me to verify this.?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 02:44:16 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Which-traffic-does-LDAP-use/m-p/14313#M353</guid>
      <dc:creator>Aznaz_Reflectio</dc:creator>
      <dc:date>2018-04-12T02:44:16Z</dc:date>
    </item>
    <item>
      <title>Re: Which traffic does LDAP use.?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Which-traffic-does-LDAP-use/m-p/14314#M354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That should be possible by checking the LDAP server IP and the VPN community settings. All traffic to the remote site on SMBs goes thru the VPN tunnel, in WebGUI we only can exclude admin access traffic to the gateway by the &lt;EM&gt;Advanced Setting &amp;gt; VPN Site to Site global settings - Override 'Route all traffic to remote VPN site' configuration&amp;nbsp;for admin access to the device&lt;/EM&gt;. Or, you can use a special configuration file, see &lt;A href="https://community.checkpoint.com/docs/DOC-2834"&gt;Locally managed SMBs vpn_table.def file&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Strange is that you are using this 1470 like a 770 - using central management would make it easy to exclude services from VPN, also enable the second processor core and even give you logs with names &lt;IMG src="https://community.checkpoint.com/legacyfs/online/checkpoint/emoticons/wink.png" /&gt;...&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 08:38:10 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Which-traffic-does-LDAP-use/m-p/14314#M354</guid>
      <dc:creator>G_W_Albrecht</dc:creator>
      <dc:date>2018-04-12T08:38:10Z</dc:date>
    </item>
    <item>
      <title>Re: Which traffic does LDAP use.?</title>
      <link>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Which-traffic-does-LDAP-use/m-p/14315#M355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Do you have accept logs enabled? Hosts using LDAP service usually make connections&amp;nbsp;every few minutes. So checking the logs with the filter "service:ldap" should show you where the traffic is going.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you see ldap traffic going both to the internet and to VPN sites, then you will not be able to check how much of the 40MB went to each destination. This would only be possible on a central management with SmartEvent.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 12 Apr 2018 13:43:26 GMT</pubDate>
      <guid>https://community.checkpoint.com/t5/Spark-Firewall-SMB/Which-traffic-does-LDAP-use/m-p/14315#M355</guid>
      <dc:creator>Pedro_Espindola</dc:creator>
      <dc:date>2018-04-12T13:43:26Z</dc:date>
    </item>
  </channel>
</rss>

