CPUG

The Check Point User Group

A Resource For The Check Point Community.  Fast.  Useful.  Independent.

1. CCSA/CCSE One-Week Dual-Certification Training Course with CPUG in San Francisco!
    Courses Starting 10/6, 11/3, 12/8, (2009) 1/19, 2/9, 3/9, 4/6, 5/4, 6/8, 7/6, 8/3, 9/7.
2. Corrent S3500 SecureXL Turbocards For Sale - Last Six Remaining - Get Your Spares!
3. Join Us On LinkedIn - We now have a CPUG group.


Go Back   CPUG: The Check Point User Group > Internal Security > Endpoint Security (Formerly Integrity)
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

Reply
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old 2007-01-15
prdehoop prdehoop is offline
Junior Member
 
Join Date: 2006-12-14
Posts: 17
Rep Power: 0
prdehoop has an average reputation (10+)
Default LDAP MAX 1000 query problem

Hello,

We wan't to connect the new integrity server in our windows 2000 AD, and import the users on specified times. but we have the problem dat there are moren then 14000 User accounts, and the integrity qeury doesn't support that ??

Is there a way to resolve this import and NOT do anything with ntdsutils on the server AD side ?


Thanxs

Patrick
Reply With Quote
  #2 (permalink)  
Old 2007-01-15
betski betski is offline
Member
 
Join Date: 2006-07-05
Location: Yorkshire, UK
Posts: 42
Rep Power: 0
betski has an average reputation (10+)
Default Re: Ldap MAX 1000 qeury problem

Hi Patrick

The 1000 user limit is imposed by the AD Domain Controller, it isn't an Integrity setting. You have to use ntdsutil.exe or apply a script using 'ldifde' to the local DC on which the query results must be increased.
Reply With Quote
  #3 (permalink)  
Old 2007-01-16
prdehoop prdehoop is offline
Junior Member
 
Join Date: 2006-12-14
Posts: 17
Rep Power: 0
prdehoop has an average reputation (10+)
Default Re: Ldap MAX 1000 qeury problem

Quote:
Originally Posted by betski View Post
Hi Patrick

The 1000 user limit is imposed by the AD Domain Controller, it isn't an Integrity setting. You have to use ntdsutil.exe or apply a script using 'ldifde' to the local DC on which the query results must be increased.

the problem is that a change on the AD is not something we wan't, so thats why the question is there a way to let Integrity do a split in the query to do more queries and resume with 1001 with the next ?
Reply With Quote
  #4 (permalink)  
Old 2007-06-26
CSING CSING is offline
Member
 
Join Date: 2007-06-22
Posts: 98
Rep Power: 2
CSING has an average reputation (10+)
Default Re: LDAP MAX 1000 query problem

Use foxfire not iexplore for AD imports.
Reply With Quote
  #5 (permalink)  
Old 2007-08-01
CSING CSING is offline
Member
 
Join Date: 2007-06-22
Posts: 98
Rep Power: 2
CSING has an average reputation (10+)
Default Re: LDAP MAX 1000 query problem

Internet Explorer (6.x) limits to 3000 the number of groups you can import into an NTDomain, LDAP, or RADIUS catalog on Integrity Advanced Server. To import more than 3000 groups, use another of the supported browsers. Mozilla Firefox is the only compatible browser that accommodates imports of more than 10,000 groups. Note that, for very large imports, the import page may take up to ten minutes to display all imported groups. When importing groups with a browser other than Internet Explorer, users may get a warning asking whether to abort the long-running javascript routine. Users should close the dialog box or choose to continue running javascript. For Firefox, you can suppress this message by typing about:config in the address bar, finding the entry for dom.max_script_run_time, and setting the number to 60 (on new computers) or 120 (on older computers).
Reply With Quote
  #6 (permalink)  
Old 2008-02-14
baccord35 baccord35 is offline
Junior Member
 
Join Date: 2007-07-11
Posts: 5
Rep Power: 0
baccord35 has an average reputation (10+)
Default Re: LDAP MAX 1000 query problem

How was this resolved?
It looks the same as our max 1500 LDAP group membership (the >1000 default in Win2000 is increased to >1500 in Win2003).
CP doesn't read multiple pages so either the attribute is dramatically increased or group membership has to be redesigned to keep numbers below 1500.
Reply With Quote
  #7 (permalink)  
Old 2008-09-01
prdehoop prdehoop is offline
Junior Member
 
Join Date: 2006-12-14
Posts: 17
Rep Power: 0
prdehoop has an average reputation (10+)
Default Re: LDAP MAX 1000 query problem

We solved this by installing Firefox on the machine.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -7. The time now is 16:32.


Powered by vBulletin® Version 3.7.2
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
LinkBacks Enabled by vBSEO 3.0.0