<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP - failed to create page control in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-failed-to-create-page-control/m-p/28319#M20695</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Out of curiosity, is the output via your syslog? Are you actually able to utilize the LDAP server for authentication?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 16 Mar 2011 18:28:51 GMT</pubDate>
    <dc:creator>gswcowboy</dc:creator>
    <dc:date>2011-03-16T18:28:51Z</dc:date>
    <item>
      <title>LDAP - failed to create page control</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-failed-to-create-page-control/m-p/28318#M20694</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi All,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Seen this in the ldapd.log file.&lt;/P&gt;&lt;P&gt;Has anyone come across this before ?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;PRE __default_attr="plain" __jive_macro_name="code" class="jive_text_macro jive_macro_code"&gt;&lt;P&gt; Mar 16 10:10:03 connected to ldap server ldap://172.17.23.132&lt;BR /&gt; Mar 16 10:10:03 ldap cfg LDAP Server connected to 172.17.23.132:389(index 0)&lt;BR /&gt; Mar 16 10:10:09 Warning: pan_ldap_search(pan_ldap.c:521): failed to create page control&lt;BR /&gt; Mar 16 10:10:09 Warning: pan_ldap_search(pan_ldap.c:521): failed to create page control&lt;BR /&gt; Mar 16 10:10:09 Warning: pan_ldap_search(pan_ldap.c:521): failed to create page control&lt;BR /&gt; Mar 16 10:10:09 Warning: pan_ldap_search(pan_ldap.c:521): failed to create page control&lt;BR /&gt; Mar 16 10:10:09 Warning: pan_ldap_search(pan_ldap.c:521): failed to create page control&lt;BR /&gt; Mar 16 10:10:09 Warning: pan_ldap_search(pan_ldap.c:521): failed to create page control&lt;BR /&gt; Mar 16 10:10:09 Warning: pan_ldap_search(pan_ldap.c:521): failed to create page control&lt;BR /&gt; Mar 16 10:10:09 Warning: pan_ldap_search(pan_ldap.c:521): failed to create page control&lt;/P&gt;&lt;/PRE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;the "failed to create page control" pages for quite a bit.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Mar 2011 13:04:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-failed-to-create-page-control/m-p/28318#M20694</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-03-16T13:04:48Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP - failed to create page control</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-failed-to-create-page-control/m-p/28319#M20695</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Out of curiosity, is the output via your syslog? Are you actually able to utilize the LDAP server for authentication?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Mar 2011 18:28:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-failed-to-create-page-control/m-p/28319#M20695</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2011-03-16T18:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP - failed to create page control</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-failed-to-create-page-control/m-p/28320#M20696</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In eDir, a request is made by the PAN for group information (1000 at a time) and from this all users (1000 at a time), thus the need for page control. This way, the PAN will not be inundated by a possilbe 'dump' of data. Having said that, if you're running AD, page control is not a supported feature and you'll eventually receive these log messages. However, if you're running eDir version 8.7, you'll need to upgrade to version 8.8 to alleviate these alerts. Hope this answers your question.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 16 Mar 2011 21:15:22 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-failed-to-create-page-control/m-p/28320#M20696</guid>
      <dc:creator>gswcowboy</dc:creator>
      <dc:date>2011-03-16T21:15:22Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP - failed to create page control</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-failed-to-create-page-control/m-p/28321#M20697</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;We are currently using a Donino (v6.5.x I think) for captive portal authentication, which seems to be working with the tests we have performed.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;These logs are from the ldapd.log on the PA its self not via syslog.&lt;/P&gt;&lt;P&gt;using "show user ldap-server server all" the PA contact the LDAP server and returns all the groups and users in under 20 seconds, when viewing the ldapd.log imiedatly after the PA connects we recieve the "failed to create page control" warning in the log.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Im just concerened that this may have an impact on the users authenticating when we start migrating more users across.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 06:42:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-failed-to-create-page-control/m-p/28321#M20697</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-03-17T06:42:39Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP - failed to create page control</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-failed-to-create-page-control/m-p/28322#M20698</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marc,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This may impact results later on.&lt;/P&gt;&lt;P&gt;The LDAP quesry is looking to get all the user/group mappings - so the paging error probably means you're getting the 1st 1,000 results only.&amp;nbsp; This means - a valid user will likely get authenticated.&amp;nbsp; However, they may not end up in the correct group for security policies - you'll be able to see this on the device CLI - all user/group mappings.&amp;nbsp; Although it could be a big list to go through.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The question is whether your 1,000+ results are all users or something different - e.g. groups.&lt;/P&gt;&lt;P&gt;Filters on groups will help if there are a lot of groups being returned that you'll not use in security policy.&lt;/P&gt;&lt;P&gt;Filter on users, if you can, to get only the &amp;lt;1,000 that you need - assuming you have less than 1,000 that will authenticate in this way.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Of course, the above needs validating with checks on the CLI to see what you see.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 08:10:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-failed-to-create-page-control/m-p/28322#M20698</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-03-17T08:10:44Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP - failed to create page control</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-failed-to-create-page-control/m-p/28323#M20699</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi James,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;With ldap page control I asume you are refering to RFC 2696 - LDAP Control Extension for Simple Paged Results Manipulation?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If so then I belive from the research I have done Lotus Domino versions 5,6 and 7 do not support this RFC.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So it looks like the customer is going to have to do some regrouping by Region to bring the returned numbers down... however if the total number of users in all groups exceeds 1,000+ would I still have the same issue??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Marc&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 13:00:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-failed-to-create-page-control/m-p/28323#M20699</guid>
      <dc:creator>migration</dc:creator>
      <dc:date>2011-03-17T13:00:30Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP - failed to create page control</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-failed-to-create-page-control/m-p/28324#M20700</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Marc,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I cannot comment on the RFC - perhaps someone can check this.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;However, yes - if more than 1,000 lines are returned the problem will remain.&amp;nbsp; The company may not need to change their structure.&amp;nbsp; It is possible for example to filter user on their loction - assuming this information has been entered into the LDAP server.&amp;nbsp; Here are some examples of filters:&lt;/P&gt;&lt;P style="line-height: 85%; margin-top: 14.4pt; margin-bottom: 1.44pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Arial; "&gt;Use only users based in Dallas or Houston:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="line-height: 85%; margin-top: 14.4pt; margin-bottom: 1.44pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Arial; "&gt;(|(l=Dallas)(l=Austin))&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="line-height: 85%; margin-top: 14.4pt; margin-bottom: 1.44pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"&gt;&lt;SPAN style="color: black; font-size: 12pt; font-family: Arial; "&gt;Only users named John in the same cities:&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="line-height: 85%; margin-top: 14.4pt; margin-bottom: 1.44pt; text-align: center; direction: ltr; unicode-bidi: embed; vertical-align: baseline;"&gt;&lt;SPAN style="font-size: 12pt;"&gt;&lt;SPAN style="font-family: Arial; color: black;"&gt;(&amp;amp;(&lt;/SPAN&gt;&lt;SPAN style="font-family: Arial; color: black;"&gt;givenName&lt;/SPAN&gt;&lt;SPAN style="font-family: Arial; color: black;"&gt;=John)(|(l=Dallas)(l=Austin))) &lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 17 Mar 2011 22:53:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-failed-to-create-page-control/m-p/28324#M20700</guid>
      <dc:creator>James</dc:creator>
      <dc:date>2011-03-17T22:53:14Z</dc:date>
    </item>
  </channel>
</rss>

