<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Multiple LDAP servers in a single profile - behavior in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-ldap-servers-in-a-single-profile-behavior/m-p/171668#M54256</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;l think this option is purely for redundancy. My guess is that AD servers are sharing the same user database:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Using-More-than-Four-LDAP-Servers-in-a-Palo-Alto-Networks/ta-p/55125" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Using-More-than-Four-LDAP-Servers-in-a-Palo-Alto-Networks/ta-p/55125&lt;/A&gt;&lt;/P&gt;</description>
    <pubDate>Tue, 15 Aug 2017 15:21:47 GMT</pubDate>
    <dc:creator>TranceforLife</dc:creator>
    <dc:date>2017-08-15T15:21:47Z</dc:date>
    <item>
      <title>Multiple LDAP servers in a single profile - behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-ldap-servers-in-a-single-profile-behavior/m-p/171662#M54255</link>
      <description>&lt;P&gt;Dear comm,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;when I have several LDAP servers in a &lt;A href="https://ip1.i.lithium.com/1af81518201cfbff5431e31401c28af6e883c390/68747470733a2f2f74777a767137393632342e692e6c69746869756d2e636f6d2f74352f696d6167652f736572766572706167652f696d6167652d69642f3534313369393046423532453935413132333042322f696d6167652d73697a652f6c617267653f763d312e302670783d383030" target="_self"&gt;profile&lt;/A&gt; for user authentication. How is this list utilized? Is only the first entry used? Are authentication requests distributed over all configured servers? How does it work?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Rene&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 14:56:55 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-ldap-servers-in-a-single-profile-behavior/m-p/171662#M54255</guid>
      <dc:creator>Rboehme</dc:creator>
      <dc:date>2017-08-15T14:56:55Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple LDAP servers in a single profile - behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-ldap-servers-in-a-single-profile-behavior/m-p/171668#M54256</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;l think this option is purely for redundancy. My guess is that AD servers are sharing the same user database:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://live.paloaltonetworks.com/t5/Management-Articles/Using-More-than-Four-LDAP-Servers-in-a-Palo-Alto-Networks/ta-p/55125" target="_blank"&gt;https://live.paloaltonetworks.com/t5/Management-Articles/Using-More-than-Four-LDAP-Servers-in-a-Palo-Alto-Networks/ta-p/55125&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 15:21:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-ldap-servers-in-a-single-profile-behavior/m-p/171668#M54256</guid>
      <dc:creator>TranceforLife</dc:creator>
      <dc:date>2017-08-15T15:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple LDAP servers in a single profile - behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-ldap-servers-in-a-single-profile-behavior/m-p/171673#M54258</link>
      <description>&lt;P&gt;Dear Trancefor,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;thank you for your answer. I am confused by this:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Usually four LDAP servers are more than enough to authenticate all the users in the domain, and to provide redundancy in case a LDAP server goes down.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;This sounds like:"Hey, I will use one LDAP forever, if it goes down, I just will pick the next in the list".&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Sometimes, larger companies have more than four LDAP servers with distributed environments in which users connect to dedicated LDAP servers. Users may contact LDAP servers that are not one of the four servers, and will try to authenticate to them.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;So this sounds to me like (if the first statement above is true):"Hey I will use the first LDAP server of the first entry of the authentication sequence. If this authentication fails, I will contact the first LDAP server of the second entry of the authentication profile."&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Bascially if you have two groups of LDAP servers:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Group1: 1,2,3,4&lt;/P&gt;&lt;P&gt;Group2:5,6,7,8&lt;/P&gt;&lt;P&gt;Authentication Sequence: Group1,Group2&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Assuming no LDAP server goes down ever: LDAP1 will be contacted and LDAP5 might be contacted, the rest of the server will never be contacted. Am I right here?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Kind regards,&lt;/P&gt;&lt;P&gt;&lt;BR /&gt;Rene&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 15:56:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-ldap-servers-in-a-single-profile-behavior/m-p/171673#M54258</guid>
      <dc:creator>Rboehme</dc:creator>
      <dc:date>2017-08-15T15:56:44Z</dc:date>
    </item>
    <item>
      <title>Re: Multiple LDAP servers in a single profile - behavior</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/multiple-ldap-servers-in-a-single-profile-behavior/m-p/171679#M54259</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/14291"&gt;@Rboehme&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;The servers in Group1 will be polled and contact will stop once a user is matched authenticated. If the entire Group1 does not find a match it will continue to Group2. If The first polling server in Group1 never goes down then I believe your assumption is correct that the others will never be consulted.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 15 Aug 2017 16:30:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/multiple-ldap-servers-in-a-single-profile-behavior/m-p/171679#M54259</guid>
      <dc:creator>BPry</dc:creator>
      <dc:date>2017-08-15T16:30:18Z</dc:date>
    </item>
  </channel>
</rss>

