<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic LDAP not work if management interface IP address cannot reach Windows AD in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-not-work-if-management-interface-ip-address-cannot-reach/m-p/221867#M63840</link>
    <description>&lt;P&gt;Configuration as below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Mangement interface with IP 192.168.1.2 (non-PA device as gateway)&lt;/P&gt;&lt;P&gt;2. Windows AD with IP 172.16.1.2 (PA device layer3 interface as gateway)&lt;/P&gt;&lt;P&gt;3. Subnet 192.168.1.0/24 and 172.16.1.0/24 cannot reach each other&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With correct LDAP config (LDAP IP, Port, Base DN, etc.). Go to "Device &amp;gt; User Identification &amp;gt; Group Mapping Settings &amp;gt; Group Include List". When expand the AD Users and Computers list always show failed to connect to the AD server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After I change the management interface IP to the same subnet of Windows AD or set route to allow communication between the 2 subnet. The problem gone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this the product restriction or did I miss something?&lt;/P&gt;</description>
    <pubDate>Thu, 12 Jul 2018 03:10:59 GMT</pubDate>
    <dc:creator>jeremylo</dc:creator>
    <dc:date>2018-07-12T03:10:59Z</dc:date>
    <item>
      <title>LDAP not work if management interface IP address cannot reach Windows AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-not-work-if-management-interface-ip-address-cannot-reach/m-p/221867#M63840</link>
      <description>&lt;P&gt;Configuration as below&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;1. Mangement interface with IP 192.168.1.2 (non-PA device as gateway)&lt;/P&gt;&lt;P&gt;2. Windows AD with IP 172.16.1.2 (PA device layer3 interface as gateway)&lt;/P&gt;&lt;P&gt;3. Subnet 192.168.1.0/24 and 172.16.1.0/24 cannot reach each other&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;With correct LDAP config (LDAP IP, Port, Base DN, etc.). Go to "Device &amp;gt; User Identification &amp;gt; Group Mapping Settings &amp;gt; Group Include List". When expand the AD Users and Computers list always show failed to connect to the AD server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;After I change the management interface IP to the same subnet of Windows AD or set route to allow communication between the 2 subnet. The problem gone.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this the product restriction or did I miss something?&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 03:10:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-not-work-if-management-interface-ip-address-cannot-reach/m-p/221867#M63840</guid>
      <dc:creator>jeremylo</dc:creator>
      <dc:date>2018-07-12T03:10:59Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP not work if management interface IP address cannot reach Windows AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-not-work-if-management-interface-ip-address-cannot-reach/m-p/221882#M63844</link>
      <description>&lt;P&gt;By default ldap service is on management interface. Go to device, setup, services and change the default to an interface that can route to your AD network.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 06:19:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-not-work-if-management-interface-ip-address-cannot-reach/m-p/221882#M63844</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2018-07-12T06:19:04Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP not work if management interface IP address cannot reach Windows AD</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-not-work-if-management-interface-ip-address-cannot-reach/m-p/221883#M63845</link>
      <description>&lt;P&gt;Thanks MickBall. Customize service route configuration solve the probem.&lt;/P&gt;</description>
      <pubDate>Thu, 12 Jul 2018 06:36:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-not-work-if-management-interface-ip-address-cannot-reach/m-p/221883#M63845</guid>
      <dc:creator>jeremylo</dc:creator>
      <dc:date>2018-07-12T06:36:44Z</dc:date>
    </item>
  </channel>
</rss>

