<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: PA-500 LDAP Checkin Timing in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/pa-500-ldap-checkin-timing/m-p/20561#M15016</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Regarding your OWA question... does your clients have dns servers set who are available on untrust (who are blocked)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because your description fits that a client tries to resolve something with dns1, fails after 2 seconds, tries dns2, fails after 2 seconds and so on until some more time have passed and the browser/sshclient/whatever just figures out "ehh, this doesnt work" and then continue with whatever it was trying to access.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 28 Mar 2012 18:33:43 GMT</pubDate>
    <dc:creator>mikand</dc:creator>
    <dc:date>2012-03-28T18:33:43Z</dc:date>
    <item>
      <title>PA-500 LDAP Checkin Timing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-500-ldap-checkin-timing/m-p/20560#M15015</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Does anyone know how often a PA-500 checks in with LDAP to determine group members?&amp;nbsp; I was adding users to a group that should be blocked from outside access, however, even after 10 minutes and several restarts the user can still get right out to the internet.&amp;nbsp; How long does it take for the Palo Alto to check back for group members?&lt;/P&gt;&lt;P&gt;On that same note.&amp;nbsp; I have a policy that blocks certain users from getting out to the internet. However, when I apply this policy to the users, it takes up to 10 seconds for them to get to our internal OWA server.&amp;nbsp; When I remove the policy, it is instantaneous.&amp;nbsp; Why would blocking "any" traffic from my Internal Network to the Untrust Zone, cause users to stall out when trying to get to an internal OWA server?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2012 15:53:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-500-ldap-checkin-timing/m-p/20560#M15015</guid>
      <dc:creator>kaysun</dc:creator>
      <dc:date>2012-03-28T15:53:30Z</dc:date>
    </item>
    <item>
      <title>Re: PA-500 LDAP Checkin Timing</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/pa-500-ldap-checkin-timing/m-p/20561#M15016</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Regarding your OWA question... does your clients have dns servers set who are available on untrust (who are blocked)?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Because your description fits that a client tries to resolve something with dns1, fails after 2 seconds, tries dns2, fails after 2 seconds and so on until some more time have passed and the browser/sshclient/whatever just figures out "ehh, this doesnt work" and then continue with whatever it was trying to access.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 28 Mar 2012 18:33:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/pa-500-ldap-checkin-timing/m-p/20561#M15016</guid>
      <dc:creator>mikand</dc:creator>
      <dc:date>2012-03-28T18:33:43Z</dc:date>
    </item>
  </channel>
</rss>

