<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Service route for ldap in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/service-route-for-ldap/m-p/47238#M34720</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have implemented a Palo Alto without Management interface, only an Inside interface/zone and Outside interface/zone. I configured the service route configuration to use Inside IP address for updates, dns... (all service routes). Also I have configured the network routing (all the networks that has to be accessed from Inside IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is on ldap connection. When I configure the group mapping, I get an error because PaloAlto can not connect to ldap server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My tests:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I do a ping to ldap host, I get: From &amp;lt;management IP&amp;gt; icmp seq=X Destination host unrecheable. But If I do a ping with source Iniside IP address to ldap host I get response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@PA-500&amp;gt; show user group-mapping state all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group Mapping(vsys1, type: e-directory): LDAP_userauth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bind DN&amp;nbsp;&amp;nbsp;&amp;nbsp; : cn=admin,o=esteve&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Base&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : ou=info,ou=intranet,o=esteve&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Group Filter: (None)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User Filter: (None)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Servers&amp;nbsp;&amp;nbsp;&amp;nbsp; : configured 1 servers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.20.0.181(636)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last Action Time: 50 secs ago(took 3 secs)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Next Action Time: In 10 secs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last LDAP error: Can't contact LDAP server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Number of Groups: 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could be that ldap connection is being started on management interface and the service routing for this service is not working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 12 Jun 2012 09:44:35 GMT</pubDate>
    <dc:creator>david_rivas1</dc:creator>
    <dc:date>2012-06-12T09:44:35Z</dc:date>
    <item>
      <title>Service route for ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/service-route-for-ldap/m-p/47238#M34720</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I have implemented a Palo Alto without Management interface, only an Inside interface/zone and Outside interface/zone. I configured the service route configuration to use Inside IP address for updates, dns... (all service routes). Also I have configured the network routing (all the networks that has to be accessed from Inside IP address.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The problem is on ldap connection. When I configure the group mapping, I get an error because PaloAlto can not connect to ldap server.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;My tests:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If I do a ping to ldap host, I get: From &amp;lt;management IP&amp;gt; icmp seq=X Destination host unrecheable. But If I do a ping with source Iniside IP address to ldap host I get response.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;admin@PA-500&amp;gt; show user group-mapping state all&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Group Mapping(vsys1, type: e-directory): LDAP_userauth&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bind DN&amp;nbsp;&amp;nbsp;&amp;nbsp; : cn=admin,o=esteve&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Base&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : ou=info,ou=intranet,o=esteve&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Group Filter: (None)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User Filter: (None)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Servers&amp;nbsp;&amp;nbsp;&amp;nbsp; : configured 1 servers&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 172.20.0.181(636)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last Action Time: 50 secs ago(took 3 secs)&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Next Action Time: In 10 secs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last LDAP error: Can't contact LDAP server&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Number of Groups: 0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Could be that ldap connection is being started on management interface and the service routing for this service is not working?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2012 09:44:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/service-route-for-ldap/m-p/47238#M34720</guid>
      <dc:creator>david_rivas1</dc:creator>
      <dc:date>2012-06-12T09:44:35Z</dc:date>
    </item>
    <item>
      <title>Re: Service route for ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/service-route-for-ldap/m-p/47239#M34721</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi David,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You need to specify a service route based on destination for ldap connections.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This can be done Device -&amp;gt; Setup -&amp;gt; Services -&amp;gt; Service Route Configuration -&amp;gt; set Destination(ldap server) and source Inside IP address&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;- Stefan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 12 Jun 2012 18:09:20 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/service-route-for-ldap/m-p/47239#M34721</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2012-06-12T18:09:20Z</dc:date>
    </item>
    <item>
      <title>Re: Service route for ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/service-route-for-ldap/m-p/47240#M34722</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I have configured a destination to the ldap network with the Internal Source addres. Shuld I add a destination to host (maks 32) instead a destination to the network?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 08:15:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/service-route-for-ldap/m-p/47240#M34722</guid>
      <dc:creator>david_rivas1</dc:creator>
      <dc:date>2012-06-13T08:15:12Z</dc:date>
    </item>
    <item>
      <title>Re: Service route for ldap</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/service-route-for-ldap/m-p/47241#M34723</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Unfortunately only a single IP Address can be specificed. There is no need to put /32 mask, just the IP address. For example: 172.24.7.50&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Attached is sample screenshot.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 13 Jun 2012 16:32:43 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/service-route-for-ldap/m-p/47241#M34723</guid>
      <dc:creator>sspringer</dc:creator>
      <dc:date>2012-06-13T16:32:43Z</dc:date>
    </item>
  </channel>
</rss>

