<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: get-ldap-data-failure - LDAP Failover doesn't work in Next-Generation Firewall Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/get-ldap-data-failure-ldap-failover-doesn-t-work/m-p/570227#M2279</link>
    <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/239962"&gt;@dramchandani&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to be honest I do not think that PA Firewall is built for this kind of health check. To address this use case, I would be looking into pointing Firewall to virtual IP address of load balancer and have load balancer to perform health LDAP check queries against LDAP servers. In this case load balancer could take out of service unhealthy server from the server pool.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 18 Dec 2023 12:19:37 GMT</pubDate>
    <dc:creator>PavelK</dc:creator>
    <dc:date>2023-12-18T12:19:37Z</dc:date>
    <item>
      <title>get-ldap-data-failure - LDAP Failover doesn't work</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/get-ldap-data-failure-ldap-failover-doesn-t-work/m-p/569814#M2267</link>
      <description>&lt;P&gt;-I had two LDAP servers configured with a firewall, the primary LDAP server had an issue with high CPU and memory due to which the firewall lost the group membership though the firewall has L3 reachability.&lt;/P&gt;
&lt;P&gt;During the log analysis found that&amp;nbsp;&amp;nbsp;get-ldap-data-failure from Primary LDAP.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We manually failed over the LDAP to a secondary one and this resolved the issue but the primary concern is how do we trigger a failover LDAP based on information being missing rather than just L3 reachability.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In this case, Firewall was not losing any pings to Primary LDAP, it was just not getting the data at the right time.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 14 Dec 2023 03:08:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/get-ldap-data-failure-ldap-failover-doesn-t-work/m-p/569814#M2267</guid>
      <dc:creator>dramchandani</dc:creator>
      <dc:date>2023-12-14T03:08:19Z</dc:date>
    </item>
    <item>
      <title>Re: get-ldap-data-failure - LDAP Failover doesn't work</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/get-ldap-data-failure-ldap-failover-doesn-t-work/m-p/570227#M2279</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/239962"&gt;@dramchandani&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;to be honest I do not think that PA Firewall is built for this kind of health check. To address this use case, I would be looking into pointing Firewall to virtual IP address of load balancer and have load balancer to perform health LDAP check queries against LDAP servers. In this case load balancer could take out of service unhealthy server from the server pool.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2023 12:19:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/get-ldap-data-failure-ldap-failover-doesn-t-work/m-p/570227#M2279</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-12-18T12:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: get-ldap-data-failure - LDAP Failover doesn't work</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/get-ldap-data-failure-ldap-failover-doesn-t-work/m-p/570271#M2280</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/192693"&gt;@PavelK&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks for responding, yes LB makes sense in this case.&lt;/P&gt;
&lt;P&gt;The other question I have is, why firewall will lose cached entry? The firewall has LDAP query timer configured as 60 minutes and after 60 min FW will fetch delta configuration from LDAP but in this case, the Firewall lost the complete group membership and there was not a single group entry, why would firewall lose all of the cached/learned entries?&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2023 20:08:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/get-ldap-data-failure-ldap-failover-doesn-t-work/m-p/570271#M2280</guid>
      <dc:creator>dramchandani</dc:creator>
      <dc:date>2023-12-18T20:08:23Z</dc:date>
    </item>
    <item>
      <title>Re: get-ldap-data-failure - LDAP Failover doesn't work</title>
      <link>https://live.paloaltonetworks.com/t5/next-generation-firewall/get-ldap-data-failure-ldap-failover-doesn-t-work/m-p/570280#M2281</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/239962"&gt;@dramchandani&lt;/a&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;thank you for reply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I see what you mean. Based on my past experience default LDAP query timer never failed me. I do not have answer for this. From your post it looks like you went pretty deep into troubleshooting, but just in case did you have a chance to review logs:&amp;nbsp;tail mp-log authd.log to see what exactly happened?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Kind Regards&lt;/P&gt;
&lt;P&gt;Pavel&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 18 Dec 2023 23:20:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/next-generation-firewall/get-ldap-data-failure-ldap-failover-doesn-t-work/m-p/570280#M2281</guid>
      <dc:creator>PavelK</dc:creator>
      <dc:date>2023-12-18T23:20:34Z</dc:date>
    </item>
  </channel>
</rss>

