- Products
- Learn
- Local User Groups
- Partners
- More
What's New in R82.10?
10 December @ 5pm CET / 11am ET
Improve Your Security Posture with
Threat Prevention and Policy Insights
Overlap in Security Validation
Help us to understand your needs better
CheckMates Go:
Maestro Madness
Hi all,
Wondering if anyone has ideas on this issue, I have 2 clusters (same policy). On one cluster it can successfully connect and receive login events from two domain controllers, on the other cluster I get the message "no connectivity, connection refused by remote host [ntstatus = 0xc0000236]"
Both clusters use the same login credentials, both clusters can telnet to the server IP's on port 389 and 636. I have also connected to the server and checked event viewer. I don't see any errors it all says success.
When I use the test_ad_connectivity tool I get the following:
:status (SUCCESS_LDAP_WMI_NO_CONNECTIVITY)
:err_msg ("ADLOG_ERROR_NETWORK_PROBLEM;LDAP_SUCCESS")
:ldap_status (LDAP_SUCCESS)
:wmi_status (ADLOG_ERROR_NETWORK_PROBLEM)
:timestamp ("Thu Jun 27 16:55:30 2019")
Any ideas what this could be?
thanks
Hi Ryan,
You do need RPC communication for AD Query to work, but you don't need all "tcp-high-ports".
49152-65535 is the Microsoft specified range required, and it's what we use for our AD Query setups.
(In addtition to tcp/636 and tcp/135)
/Sigbjorn
Hi good idea,
I tried that and can confirm it has successfully queried and returns correct information from ldap.
Unless @Royi_Priov or someone from R&D has an idea, I suggest opening a TAC case.
I might have found the issue, if there is another f/w between the gateway and the domain controller it appears you need to open:
tcp/389 or tcp/636
tcp/135
tcp/1025-65535
For full connectivity. Will update once we have opened ports and confirmed.
Hi Ryan,
You do need RPC communication for AD Query to work, but you don't need all "tcp-high-ports".
49152-65535 is the Microsoft specified range required, and it's what we use for our AD Query setups.
(In addtition to tcp/636 and tcp/135)
/Sigbjorn
Hi Ryan,
I am sure that firewall in between is the issue. You need to open required ports on that firewall
Hi,
It looks like you are in the right direction with the DCE-RPC ports, I will explain why:
LDAP connectivity is not related to the WMI connection which should be open between GW to AD.
You can also see in the log:
:status (SUCCESS_LDAP_WMI_NO_CONNECTIVITY)
:err_msg ("ADLOG_ERROR_NETWORK_PROBLEM;LDAP_SUCCESS")
:ldap_status (LDAP_SUCCESS)
:wmi_status (ADLOG_ERROR_NETWORK_PROBLEM)
:timestamp ("Thu Jun 27 16:55:30 2019")
Thanks,
Royi.
confirmed it was the f/w ports needing to be opened. working now!
Leaderboard
Epsum factorial non deposit quid pro quo hic escorol.
| User | Count |
|---|---|
| 26 | |
| 18 | |
| 11 | |
| 8 | |
| 7 | |
| 6 | |
| 6 | |
| 5 | |
| 4 | |
| 4 |
Wed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasWed 03 Dec 2025 @ 10:00 AM (COT)
Última Sesión del Año – CheckMates LATAM: ERM & TEM con ExpertosThu 04 Dec 2025 @ 12:30 PM (SGT)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - APACThu 04 Dec 2025 @ 03:00 PM (CET)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - EMEAThu 04 Dec 2025 @ 02:00 PM (EST)
End-of-Year Event: Securing AI Transformation in a Hyperconnected World - AmericasAbout CheckMates
Learn Check Point
Advanced Learning
YOU DESERVE THE BEST SECURITY