<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: How can I test a ldap server that is healthy or not？ in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-test-a-ldap-server-that-is-healthy-or-not/m-p/1229793#M124355</link>
    <description>&lt;P&gt;In firewall add new LDAP profile.&lt;/P&gt;
&lt;P&gt;Enter server into "Server List"&lt;/P&gt;
&lt;P&gt;Add Bind DN and password.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If "Base DN" droppdown populates then connection to LDAP server is successful.&lt;/P&gt;</description>
    <pubDate>Thu, 22 May 2025 14:46:54 GMT</pubDate>
    <dc:creator>Raido_Rattameister</dc:creator>
    <dc:date>2025-05-22T14:46:54Z</dc:date>
    <item>
      <title>How can I test a ldap server that is healthy or not？</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-test-a-ldap-server-that-is-healthy-or-not/m-p/1229775#M124351</link>
      <description>&lt;P&gt;Dear all&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; We need to replace our old ldap server config to a new ldap server on PA firewall and panorama, I want to know if I add a new ldap server config on PA firewall and panorama, how can I test the healthy of the new ldap server? I try to use telnet command to connect the new ldap server's 636 or 389 port, but I found there is no telnet command on PA firewall and panorama...&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; On PA firewall maybe I can use the "group include list" function in "user identification", but it doesn't work on panorama, need you give me a favor~&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best wishes&lt;/P&gt;
&lt;P&gt;Cat&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 10:10:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-test-a-ldap-server-that-is-healthy-or-not/m-p/1229775#M124351</guid>
      <dc:creator>459768405</dc:creator>
      <dc:date>2025-05-22T10:10:24Z</dc:date>
    </item>
    <item>
      <title>Re: How can I test a ldap server that is healthy or not？</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-test-a-ldap-server-that-is-healthy-or-not/m-p/1229787#M124354</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/706468977"&gt;@459768405&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;Dear all&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; We need to replace our old ldap server config to a new ldap server on PA firewall and panorama, I want to know if I add a new ldap server config on PA firewall and panorama, how can I test the healthy of the new ldap server? I try to use telnet command to connect the new ldap server's 636 or 389 port, but I found there is no telnet command on PA firewall and panorama...&lt;/P&gt;
&lt;P&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; On PA firewall maybe I can use the "group include list" function in "user identification", but it doesn't work on panorama, need you give me a favor~&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Best wishes&lt;/P&gt;
&lt;P&gt;Cat&amp;nbsp;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;I don't have access to the PAN or FW UI right now, but is there a "test connection" button in the GUI?&amp;nbsp; I don't know of an easy way to test, but in the system logs the firewall's ability to connect/contact a LDAP server shows up.&amp;nbsp; So if a server goes offline there will be a log for that.&amp;nbsp; Also I don't believe Panorama will "connect" to the servers in your LDAP profile, that only happens from the firewalls themselves.&amp;nbsp; So if you're already executed the group include list command from the FW and it's working, that should be enough to tell you it is.&amp;nbsp; Especially if you're not seeing any system log error messages.&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 13:44:05 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-test-a-ldap-server-that-is-healthy-or-not/m-p/1229787#M124354</guid>
      <dc:creator>Brandon_Wertz</dc:creator>
      <dc:date>2025-05-22T13:44:05Z</dc:date>
    </item>
    <item>
      <title>Re: How can I test a ldap server that is healthy or not？</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-test-a-ldap-server-that-is-healthy-or-not/m-p/1229793#M124355</link>
      <description>&lt;P&gt;In firewall add new LDAP profile.&lt;/P&gt;
&lt;P&gt;Enter server into "Server List"&lt;/P&gt;
&lt;P&gt;Add Bind DN and password.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If "Base DN" droppdown populates then connection to LDAP server is successful.&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 14:46:54 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-test-a-ldap-server-that-is-healthy-or-not/m-p/1229793#M124355</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2025-05-22T14:46:54Z</dc:date>
    </item>
    <item>
      <title>Re: How can I test a ldap server that is healthy or not？</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-test-a-ldap-server-that-is-healthy-or-not/m-p/1229796#M124357</link>
      <description>&lt;P&gt;Hi &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/706468977"&gt;@459768405&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Not only can you test the initial LDAP connection as described by &lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/15603"&gt;@Raido_Rattameister&lt;/a&gt; above, but you can create a new authentication profile for the new LDAP server and test authentication to it via the CLI.&amp;nbsp; &lt;A href="https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-cli-quick-start/use-the-cli/test-the-configuration/test-the-authentication-configuration" target="_blank"&gt;https://docs.paloaltonetworks.com/pan-os/10-2/pan-os-cli-quick-start/use-the-cli/test-the-configuration/test-the-authentication-configuration&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Tom&lt;/P&gt;</description>
      <pubDate>Thu, 22 May 2025 15:52:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-test-a-ldap-server-that-is-healthy-or-not/m-p/1229796#M124357</guid>
      <dc:creator>TomYoung</dc:creator>
      <dc:date>2025-05-22T15:52:21Z</dc:date>
    </item>
    <item>
      <title>Re: How can I test a ldap server that is healthy or not？</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-test-a-ldap-server-that-is-healthy-or-not/m-p/1229868#M124363</link>
      <description>&lt;P&gt;Thank you for you help, I try it on firewall. it worked. But in panorama, there is not a&amp;nbsp;&lt;SPAN&gt;dropdown populates in Base DN, it's strange&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="459768405_0-1747965274094.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/67743i6DC4ADA2B687573A/image-size/medium?v=v2&amp;amp;px=400" role="button" title="459768405_0-1747965274094.png" alt="459768405_0-1747965274094.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 23 May 2025 01:54:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-test-a-ldap-server-that-is-healthy-or-not/m-p/1229868#M124363</guid>
      <dc:creator>459768405</dc:creator>
      <dc:date>2025-05-23T01:54:55Z</dc:date>
    </item>
    <item>
      <title>Re: How can I test a ldap server that is healthy or not？</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-test-a-ldap-server-that-is-healthy-or-not/m-p/1229930#M124369</link>
      <description>&lt;P&gt;Yes only firewall has droppdown. Panorama don't have it.&lt;/P&gt;
&lt;P&gt;You can just click on "Clone" button on LDAP profile pushed from Panorama and test droppdown. After test just delete cloned profile from firewall and adjust profile in Panorama as needed.&lt;/P&gt;</description>
      <pubDate>Fri, 23 May 2025 13:14:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-test-a-ldap-server-that-is-healthy-or-not/m-p/1229930#M124369</guid>
      <dc:creator>Raido_Rattameister</dc:creator>
      <dc:date>2025-05-23T13:14:51Z</dc:date>
    </item>
    <item>
      <title>Re: How can I test a ldap server that is healthy or not？</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-test-a-ldap-server-that-is-healthy-or-not/m-p/1230011#M124382</link>
      <description>&lt;P&gt;thank you! but I mean the ldap on panorama is used on panorama's own self, it will be using on authentication&lt;/P&gt;
&lt;P data-unlink="true"&gt;manager to login the webui or cli of panorama, but that's ok, I have tried the method that&amp;nbsp;&lt;SPAN class="UserName lia-user-name lia-user-rank-Cyber-Elite lia-component-message-view-widget-author-username"&gt;&lt;SPAN class="login-bold"&gt;TomYoung&lt;/SPAN&gt;&lt;/SPAN&gt; saied, it worked&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 26 May 2025 01:48:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/how-can-i-test-a-ldap-server-that-is-healthy-or-not/m-p/1230011#M124382</guid>
      <dc:creator>459768405</dc:creator>
      <dc:date>2025-05-26T01:48:33Z</dc:date>
    </item>
  </channel>
</rss>

