<?xml version="1.0"?>
<rss version="2.0">
<channel>
<title>Thycotic Community - Secret Server - Heartbeat query question - Messages</title>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=298</link>
<description>Thycotic Community - Secret Server - Heartbeat query question - Messages</description>
<language>en-us</language>
<docs>http://blogs.law.harvard.edu/tech/rss</docs>
<generator>Jitbit AspNetForum</generator>
<pubDate>Tue, 16 Nov 2010 08:30:56 GMT</pubDate>
<lastBuildDate>Tue, 16 Nov 2010 08:30:56 GMT</lastBuildDate>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=298</link>
<title>Message from Scott</title>
<description><![CDATA[Peter,<br/><br/>Agent initiates the connection. It is most useful for environments where admins have control over opening ports on their own networks, but do not have control over the ports in the external networks. Thus, agent would call back to the Secret Server through ports the admin would enable.<br/><br/>It looks as though this would not be helpful to you. You would be better off opening the ports discussed earlier on the DMZ servers.<br/><br/><br/>Thank you for your questions,<br/>Scott<br/>Thycotic Support]]></description>
<pubDate>Tue, 16 Nov 2010 08:30:56 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=298</link>
<title>Message from Peter C</title>
<description><![CDATA[Hello Jacob,<br/>thank you for the quick answer.<br/><br/>Now the next question:<br/>Are the connections initiated by SecretServer initiate the the Agent? I suppose Secret Server initiates the connection - correct?<br/><br/>Because the Agent would not be allowed to access ports in the inner Network, only from the inside out is allowed by our firewall policy.<br/><br/>Thank you!<br/><br/>Kind regards,<br/>Peter Cermak<br/><br/>]]></description>
<pubDate>Mon, 15 Nov 2010 06:03:25 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=298</link>
<title>Message from Jacob S</title>
<description><![CDATA[Hello,<br/><br/>The following two ports are needed for Windows RPC and Heartbeat depending on the operating system and how the computers are set-up.  <br/><br/>Windows Kerberos (441)<br/>Windows NTLM (2640)<br/><br/>However we would recommend installing a Secret Server Agent on a DMZ Server, which would allow you to choose the port that the Agent communicates with Secret Server through the firewall, and you would not have to open either of the ports above.]]></description>
<pubDate>Fri, 12 Nov 2010 09:00:53 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=298</link>
<title>Message from Peter C</title>
<description><![CDATA[How is the mechanism for Windows Local accounts? What ports do we need for our DMZ Servers?<br/>]]></description>
<pubDate>Fri, 12 Nov 2010 02:15:21 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=298</link>
<title>Message from David</title>
<description><![CDATA[When a heartbeat is performed on an Active Directory secret, it uses an LDAP query to authenticate that account. If the authentication fails, then it will no longer try to run the heartbeat until it is changed in Secret Server (or the run heartbeat button is pressed) to prevent locking out the account. The heartbeats are run serially instead of concurrently, so your Active Directory won't be pelted with thousands of LDAP queries at the same time.]]></description>
<pubDate>Fri, 10 Sep 2010 09:48:07 GMT</pubDate>
</item>
<item>
<link>http://www.thycotic.com/forums/messages.aspx?TopicID=298</link>
<title>Message from Nick D</title>
<description><![CDATA[What exactly is the heartbeat process doing when heartbeating an account in Active Directory. There is some concern over if we have heartbeating set on short durations, on thousands of secrets, how will this impact Active Directory.]]></description>
<pubDate>Fri, 10 Sep 2010 06:09:18 GMT</pubDate>
</item>
</channel>
</rss>
