Jump to content

Kerberos klist delays but only for some accounts (on Cisco AnyConnect VPN)


Recommended Posts

Posted

Hi All,While connected to a Cisco AnyConnect VPN session on my laptop from home to the workplace, I note the following behaviour for some accounts.ADDS related TCP/UDP ports are open/listening 135 RPC, 389 LDAP, 88 Kerberos, 123 NTP, LDAPS 636, GC 3268,3269, SMB 445 etcFirewall is on no dropped packets.Example 1:If an active directory account has a DitinguishedName attribute like: CN=TestAccount klist immediately shows me tickets I can browse / access windows server shares setspn -L TestAccount Registered ServicePrincipalNames for CN=TestAccount ,CN=Users,DC=domain,DC=com:Example 2: However, I

 

Continue reading...

  • Replies 0
  • Created
  • Last Reply

Popular Days

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.


×
×
  • Create New...