View Single Post
  #4 (permalink)  
Old 2005-11-14
czech12 czech12 is offline
Member
 
Join Date: 2005-10-25
Location: North Brunswick, NJ
Posts: 38
Rep Power: 0
czech12 has an average reputation (10+)
Default Re: MS AD replication across firewall

I've actually seen a problem very similar to this before. I believe it was in Check Point NG w/ AI, R54, Check Point took away the "epmap" service from the TCP Services menu and broke them out to a different service grouping called "DCE-RPC". epmap is a very broad service that uses a different identifier over port 135, called the SSID or Interface UUID.

In the problem I experience, we could not get the traffic to work using the DCE-RPC object, and Check Point's resolution to us was to create an object for TCP 135 and leave the "Match For Any" option unchecked in the "Advanced" section of the service properties. Then you must create a rule that explicitly allows the TCP 135 traffic. So, that means if you have a rule that allows Any service, you still need to add another rule that allows TCP 135 by itself.

Give that a try and let me know how it works out.
__________________
====================
Aaron Vivo
CCSE Plus, CCMSE, NSA
====================
Reply With Quote