Page: https://docs.netwrix.com/docs/privilegesecure/26_03/requirements/ports
Issue or question:
The Application Server Firewall Rules table lists Kerberos as 88/UDP only, but it should be 88/TCP and UDP — Windows retries the Kerberos exchange over TCP whenever the KDC reply exceeds MaxPacketSize (1465 bytes by default), which is routine for administrative accounts with many group memberships, and with TCP 88 closed the authentication fails with NO_LOGON_SERVERS and Privilege Secure reports it as "Invalid Username or Password".
Page: https://docs.netwrix.com/docs/privilegesecure/26_03/requirements/ports
Issue or question:
The Application Server Firewall Rules table lists Kerberos as 88/UDP only, but it should be 88/TCP and UDP — Windows retries the Kerberos exchange over TCP whenever the KDC reply exceeds MaxPacketSize (1465 bytes by default), which is routine for administrative accounts with many group memberships, and with TCP 88 closed the authentication fails with NO_LOGON_SERVERS and Privilege Secure reports it as "Invalid Username or Password".