<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Can't contact LDAP server/connect error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-contact-ldap-server-connect-error/m-p/109540#M45011</link>
    <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Issue is resolved by&amp;nbsp;&lt;SPAN&gt;unchecking the SSL box, committing, then checking the SSL box and committing again.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Farzana&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Wed, 31 Aug 2016 22:47:30 GMT</pubDate>
    <dc:creator>Farzana</dc:creator>
    <dc:date>2016-08-31T22:47:30Z</dc:date>
    <item>
      <title>Can't contact LDAP server/connect error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-contact-ldap-server-connect-error/m-p/105063#M44733</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;No changes on Firewall or LDAP server side. All of a sudden noticed&amp;nbsp;for some virtual systems, LDAP server connection failed.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;The &lt;SPAN class="lia-search-match-lithium"&gt;LDAP&lt;/SPAN&gt; is configured correctly and we have the read permissions for everything in AD user.&amp;nbsp;&lt;BR /&gt;&lt;SPAN&gt;Errors in usridd.log:&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2016-08-22 10:50:34.768 +1000 connecting to ldap://[192.168.12.16]:636 with StartTLS...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2016-08-22 10:50:34.772 +1000 Error:&amp;nbsp; pan_ldap_init_ex(pan_ldap.c:249): start_tls_s return(-1) : Can't contact LDAP server&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2016-08-22 10:50:34.772 +1000 connecting to ldaps://[192.168.12.16]:636 ...&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2016-08-22 10:50:34.778 +1000 Error:&amp;nbsp; pan_ldap_init_ex(pan_ldap.c:253): install_tls return(-11) : Connect error&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;2016-08-22 10:50:34.778 +1000 Error:&amp;nbsp; pan_user_get_ldap(pan_group_selection_n.c:74): pan_ldap_init(192.168.12.16, 636) failed: Connect error&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any idea what is it indicating?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards&lt;/P&gt;&lt;P&gt;Farzana&lt;/P&gt;</description>
      <pubDate>Mon, 22 Aug 2016 03:11:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-contact-ldap-server-connect-error/m-p/105063#M44733</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2016-08-22T03:11:44Z</dc:date>
    </item>
    <item>
      <title>Re: Can't contact LDAP server/connect error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-contact-ldap-server-connect-error/m-p/105189#M44739</link>
      <description>&lt;P&gt;have you tried disabling SSL on the ldap profile ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;try increasing the debug level:&lt;/P&gt;
&lt;PRE&gt;&amp;gt; debug user-id on debug
&amp;gt; debug user-id set ldap all&lt;/PRE&gt;
&lt;P&gt;this may provide you with more details&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;don't forget to unset debugging after you're done:&lt;/P&gt;
&lt;PRE&gt;&amp;gt; debug user-id unset all
&amp;gt; debug user-id on info&lt;/PRE&gt;</description>
      <pubDate>Mon, 22 Aug 2016 09:24:23 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-contact-ldap-server-connect-error/m-p/105189#M44739</guid>
      <dc:creator>reaper</dc:creator>
      <dc:date>2016-08-22T09:24:23Z</dc:date>
    </item>
    <item>
      <title>Re: Can't contact LDAP server/connect error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-contact-ldap-server-connect-error/m-p/109540#M45011</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Issue is resolved by&amp;nbsp;&lt;SPAN&gt;unchecking the SSL box, committing, then checking the SSL box and committing again.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Farzana&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Wed, 31 Aug 2016 22:47:30 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-contact-ldap-server-connect-error/m-p/109540#M45011</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2016-08-31T22:47:30Z</dc:date>
    </item>
    <item>
      <title>Re: Can't contact LDAP server/connect error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-contact-ldap-server-connect-error/m-p/116114#M45458</link>
      <description>&lt;P&gt;i have the same messages:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;2016-09-27 11:02:39.493 +0200 connecting to ldap://[XXXXXX.domain.com]:636 with StartTLS...&lt;BR /&gt;2016-09-27 11:02:39.496 +0200 Error: pan_ldap_init_ex(pan_ldap.c:249): start_tls_s return(-1) : Can't contact LDAP server&lt;BR /&gt;2016-09-27 11:02:39.496 +0200 connecting to ldaps://[XXXXXX.domain.com]:636 ...&lt;BR /&gt;2016-09-27 11:02:39.609 +0200 ldap cfg Pan_Grp connected to XXXXXX.domain.com:636(index 0)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;looks like, it tries to connect with normal LDAP:636 and then successfully with LDAPS:636.&amp;nbsp; LDAP:636 will not work...&lt;/P&gt;&lt;P&gt;Checkbox "SSL required" is checked and it still tries LDAP:636 first...&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2016 09:12:10 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-contact-ldap-server-connect-error/m-p/116114#M45458</guid>
      <dc:creator>Hithead</dc:creator>
      <dc:date>2016-09-27T09:12:10Z</dc:date>
    </item>
    <item>
      <title>Re: Can't contact LDAP server/connect error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/can-t-contact-ldap-server-connect-error/m-p/116252#M45475</link>
      <description>&lt;P&gt;Hi Hithead,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We opened a support case for this and now it is escalated to their engineering team. PAN support has suggested to upgrade to 7.0.10 and see if it addresses the issue.&lt;/P&gt;</description>
      <pubDate>Tue, 27 Sep 2016 22:44:12 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/can-t-contact-ldap-server-connect-error/m-p/116252#M45475</guid>
      <dc:creator>Farzana</dc:creator>
      <dc:date>2016-09-27T22:44:12Z</dc:date>
    </item>
  </channel>
</rss>

