<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAPS inexplicably working on 2 DCs, not on 3rd in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldaps-inexplicably-working-on-2-dcs-not-on-3rd/m-p/176644#M55209</link>
    <description>&lt;P&gt;If they are actuall working on LDAPS,&amp;nbsp; I don't want to step down the security if I don't have to!&lt;/P&gt;</description>
    <pubDate>Fri, 15 Sep 2017 00:12:06 GMT</pubDate>
    <dc:creator>gwilson78</dc:creator>
    <dc:date>2017-09-15T00:12:06Z</dc:date>
    <item>
      <title>LDAPS inexplicably working on 2 DCs, not on 3rd</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldaps-inexplicably-working-on-2-dcs-not-on-3rd/m-p/176637#M55208</link>
      <description>&lt;P&gt;Please suggest a better title, this issue has sent me through the ringer.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We have a site with an MPLS connection down.&amp;nbsp; The PAs use the domain controller in our datacenter for authentication for both admin, and GP users, which is over the MPLS.&amp;nbsp; LDAP requests of coures.. fail.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We also have a DC in Azure, which the PA has an IPSEC tunnel attached through the backup broadband connection at the office.&amp;nbsp; Users logging into computers onsite, eventually have their login sent to Azure, and they authenticate properly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;External users trying to connect to the local VPN, can't authenticate.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I created a new LDAP server profile, and a new authentication protocol.&amp;nbsp; The only way it will work, is to set the port to 389, and to uncheck the SSL button.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;However, the two other LDAP server that are configured , which are setup from the panorama, AND are the same on all 15 of my PAs,&amp;nbsp; use port 636, with the SSL box checked.&amp;nbsp; On other PAs, there are no issues with Authentication.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When I use ldp.exe to connect to the ldap servers, oddly enough, they all work with 389 no SSL.&amp;nbsp; They also all FAIL when trying to connect with 636 and SSL.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there some kind of magic allowing the other servers to work?&amp;nbsp; I of course inherited the network, but I know we don't have a Cert Authority.&amp;nbsp; So it would seem I haven't met the requirements for using LDAPS.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;What I'm after, is trying to figure out how the main 2 servers are working on port 636, and if legitimate, I'd like to make those changes to the AZURE server.&amp;nbsp; This way I can add the AZURE server to the list on the LDAP server profile, so i'm covered in the future.&amp;nbsp; The only certificates configure on the PA, are a Root, Intermediate , and Wildcard certificate ( full chain)&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please let me know if you have any questions.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2017 00:08:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldaps-inexplicably-working-on-2-dcs-not-on-3rd/m-p/176637#M55208</guid>
      <dc:creator>gwilson78</dc:creator>
      <dc:date>2017-09-15T00:08:50Z</dc:date>
    </item>
    <item>
      <title>Re: LDAPS inexplicably working on 2 DCs, not on 3rd</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldaps-inexplicably-working-on-2-dcs-not-on-3rd/m-p/176644#M55209</link>
      <description>&lt;P&gt;If they are actuall working on LDAPS,&amp;nbsp; I don't want to step down the security if I don't have to!&lt;/P&gt;</description>
      <pubDate>Fri, 15 Sep 2017 00:12:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldaps-inexplicably-working-on-2-dcs-not-on-3rd/m-p/176644#M55209</guid>
      <dc:creator>gwilson78</dc:creator>
      <dc:date>2017-09-15T00:12:06Z</dc:date>
    </item>
  </channel>
</rss>

