<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: AD Authentication Problem with Secondary Firewall in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46737#M34356</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope the AD server is connected through the management interface. Hence, you need to capture packet on the management interface. It is not necessary to bring the firewall in &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Active state&lt;/SPAN&gt;, in order to capture &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;packet&lt;/SPAN&gt;, you can capture in Passive FW as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reference DOC: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-4595"&gt;tcpdump&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 30 Jul 2014 09:15:30 GMT</pubDate>
    <dc:creator>HULK</dc:creator>
    <dc:date>2014-07-30T09:15:30Z</dc:date>
    <item>
      <title>AD Authentication Problem with Secondary Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46724#M34343</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN lang="EN-IN" style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;HI friends..&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-IN" style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-IN" style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;I am having two Palo Alto Network (&lt;/SPAN&gt; PAN-PA-3020&lt;SPAN lang="EN-IN" style="font-size: 10pt; font-family: Arial, sans-serif;"&gt; ) firewall installed in HA&amp;nbsp; mode (Active-Passive) .&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp; &lt;SPAN lang="EN-IN" style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;My problem is when ever my Primary FW goes down or change to passive and Secondary become Active, My Active directory authentication&amp;nbsp; becomes fails, however all other things works fine. Please suggest.Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-IN" style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-IN" style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;Regards&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-IN" style="font-size: 10pt; font-family: Arial, sans-serif;"&gt;Satish&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN lang="EN-IN" style="font-size: 12pt; font-family: 'Times New Roman', serif;"&gt; &lt;BR /&gt; &lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2014 15:56:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46724#M34343</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-07-28T15:56:34Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication Problem with Secondary Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46725#M34344</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After the HA failover, did you check the reachability to the AD server from PAN firewall.? Also, verify &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;authd&lt;/SPAN&gt; logs for more detail information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2014 16:03:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46725#M34344</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-28T16:03:56Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication Problem with Secondary Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46726#M34345</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Make sure both the devices have similar authentication configuration, because authentication configuration is not synced via failover.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2014 16:03:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46726#M34345</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-07-28T16:03:58Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication Problem with Secondary Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46727#M34346</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Reference DOC for more details info--- HA-Sync :&lt;A href="https://live.paloaltonetworks.com/docs/DOC-4175"&gt;Information Synchronized in an HA Pair&lt;/A&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2014 16:07:19 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46727#M34346</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-28T16:07:19Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication Problem with Secondary Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46728#M34347</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hardik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let me check if i got any problem i will coordinate with you.apart from this any other configuration i need to consider??&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Satish &lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2014 16:12:14 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46728#M34347</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-07-28T16:12:14Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication Problem with Secondary Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46729#M34348</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hulk bro.,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for sharing such kind of use full document.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2014 16:14:32 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46729#M34348</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-07-28T16:14:32Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication Problem with Secondary Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46730#M34349</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Most likely its happening due to configuration differences on both the boxes, verify the same.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 28 Jul 2014 16:16:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46730#M34349</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-07-28T16:16:34Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication Problem with Secondary Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46731#M34350</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Friends&lt;/P&gt;&lt;P&gt;I am facing such king of issue can you help me plz &lt;/P&gt;&lt;P&gt;&lt;IMG alt="AttendeeViewerImage004 - Copy.gif" class="image-0 jive-image" src="https://live.paloaltonetworks.com/legacyfs/online/14719_AttendeeViewerImage004 - Copy.gif" style="max-width: 620px; height: auto;" /&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jul 2014 06:47:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46731#M34350</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-07-29T06:47:51Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication Problem with Secondary Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46732#M34351</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could you please re-configure the LDAP server credentials on this PAN firewall and let us know the result. It looks like your LDAP credentials were not configured correctly.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jul 2014 07:03:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46732#M34351</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-29T07:03:50Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication Problem with Secondary Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46733#M34352</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hulk Bro..,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;same configuration have primary firewall its working fine. but secondary firewall have only issue plz suggest.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jul 2014 08:58:38 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46733#M34352</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-07-29T08:58:38Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication Problem with Secondary Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46734#M34353</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;It's not about the configuration, but LDAP credentials. Could you please try to re-enter credentials one more time on the passive node.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jul 2014 13:58:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46734#M34353</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-29T13:58:29Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication Problem with Secondary Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46735#M34354</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Also try to capture traffic between AD server and Firewall, even capture can tell you whats going wrong. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;As HULK said if its a authentication issue, you will be able to view in captures.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Capture is greatest friend for security engineers.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Hardik Shah&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 29 Jul 2014 14:20:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46735#M34354</guid>
      <dc:creator>hshah</dc:creator>
      <dc:date>2014-07-29T14:20:26Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication Problem with Secondary Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46736#M34355</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hardik,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Is this required to Passive device active for the traffic capture or AD authentication verification.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If i am wrong plz correct me. buz customer are asking its not required to passive device to active for the same.&amp;nbsp; &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jul 2014 09:06:16 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46736#M34355</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-07-30T09:06:16Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication Problem with Secondary Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46737#M34356</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Satish,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I hope the AD server is connected through the management interface. Hence, you need to capture packet on the management interface. It is not necessary to bring the firewall in &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;Active state&lt;/SPAN&gt;, in order to capture &lt;SPAN class="GINGER_SOFTWARE_mark"&gt;packet&lt;/SPAN&gt;, you can capture in Passive FW as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Reference DOC: &lt;A href="https://live.paloaltonetworks.com/docs/DOC-4595"&gt;tcpdump&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Hope this helps.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jul 2014 09:15:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46737#M34356</guid>
      <dc:creator>HULK</dc:creator>
      <dc:date>2014-07-30T09:15:30Z</dc:date>
    </item>
    <item>
      <title>Re: AD Authentication Problem with Secondary Firewall</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46738#M34357</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Hulk Bro.,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have &lt;SPAN style="color: #3b3b3b; font-family: 'Helvetica Neue', Helvetica, Arial, 'Lucida Grande', sans-serif;"&gt;re-enter credentials on the passive node. but i am facing same issue. &lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Satish&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 30 Jul 2014 09:37:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ad-authentication-problem-with-secondary-firewall/m-p/46738#M34357</guid>
      <dc:creator>Satish</dc:creator>
      <dc:date>2014-07-30T09:37:44Z</dc:date>
    </item>
  </channel>
</rss>

