<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: LDAP authentication failover in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-failover/m-p/259407#M73561</link>
    <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the information.&lt;/P&gt;&lt;P&gt;I have tested different scenarios in my LAB and found the following,&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;with plaintext ldap, failover is happening with configured timeout.&lt;/LI&gt;&lt;LI&gt;With LDAPS (over port 636), failover is working fine - here PA will by default try with SSL&lt;/LI&gt;&lt;LI&gt;With SSL/TLS over any other port, firewall is trying with TLS by default and wait for timeout then try with SSL - which may be the cause the higher timeout.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In a nutshell, plantect and ssl connection is having the timeout configured, but if PA start with TLS, it causes higher timeout and GP auth fails.&lt;/P&gt;&lt;P&gt;Not sure why TLS connectivity does wait for the default timeout.&lt;/P&gt;</description>
    <pubDate>Wed, 01 May 2019 14:28:48 GMT</pubDate>
    <dc:creator>Abdul_Razaq</dc:creator>
    <dc:date>2019-05-01T14:28:48Z</dc:date>
    <item>
      <title>LDAP authentication failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-failover/m-p/258974#M73456</link>
      <description>Hi Community,&lt;BR /&gt;&lt;BR /&gt;I have 2 Domain controllers serving user information. I have configured these 2 under same LDAP server profile. I am using this profile in authentication profile for GP.&lt;BR /&gt;I configured 4s each for search and bind timeout under LDAP server profile.&lt;BR /&gt;I need the user should be authenticated with second server when first one is down(it is the default behavior)&lt;BR /&gt;It works fine when the LDAP connection is via plain text(didn't check SSL/TLS box under LDAP server profile). But when SSL/TLS is enabled, it takes toomuch time for authentication timeout to first server, by that time GP authentication timeout, and users are not able to authenticate. I don't prefer increasing timeout for GP authentication.&lt;BR /&gt;&lt;BR /&gt;Please advice if there is a way to enable TLS/SSL along with smaller timeout , so that users will he authenticated with second server.</description>
      <pubDate>Sun, 28 Apr 2019 19:38:29 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-failover/m-p/258974#M73456</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-04-28T19:38:29Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-failover/m-p/259050#M73468</link>
      <description>&lt;P&gt;i'm not sure if you understand the failover correctly.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;the authentication process will not try all servers in you ldap\server profile.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;if device 1 does not respond it will not try that server again for the time you have set in "retry interval"&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;on your second attempt (if within the "retry interval") it will try server 2.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it will then continue to auth all users on server 2 until the "retry interval" expires.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;you may be better off using an authentication sequence.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;configure 2 server profiles, one&amp;nbsp;for each server, configure 2 authentication profiles with one server profile in each.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;configure an authentication sequence with both server profiles included and select this in your portal auth page.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;also... where can you increase GP authentication timeout, i have not seen this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 12:22:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-failover/m-p/259050#M73468</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-04-29T12:22:51Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-failover/m-p/259068#M73470</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the response,&lt;/P&gt;&lt;P&gt;i was following the below kb, which says about the failover. i was having the similar problem and timer values were default in mine also. i configured retry inteval high just to avoid retying to the same server frequently.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXnCA" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClXnCA&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;In my case i am able to failover successfully when i disable ssl in LDAP server profile ( using gp application or by test authentication command in cli), i am able to see that PA tries to authenticate the user with second server after configured bind interval. But the moment i enable 'ssl/tls required' option in LDAP server profile, the timeout is increased, and it tooks around 30s to failover to next ldap server and authentication succeed in cli. but definitly it will cause auth timeout for GP users.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i am checking for a solution with enabling ssl/tls connectivity to ldap along with lesser failover time as normal plaintext connection. not even sure if it is a protocol limitation.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;regarding gp timeout, i have seen below PA document&lt;/P&gt;&lt;P&gt;-------------&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN class="ph uicontrol"&gt;Portal Connection Timeout (sec)&lt;/SPAN&gt;—The number of seconds (between 1 and 600) before a connection request to the portal times out due to no response from the portal. When your firewall is running Applications and Threats content versions earlier than 777-4484, the default is 30. Starting with content version 777-4484, the default is 5&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;-------------&lt;/P&gt;&lt;P&gt;i even doesnt check if it is configurable, i even dont prefer to change it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 14:53:40 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-failover/m-p/259068#M73470</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-04-29T14:53:40Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-failover/m-p/259105#M73472</link>
      <description>&lt;P&gt;&lt;SPAN class="ph uicontrol"&gt;Portal Connection Timeout (sec)&lt;/SPAN&gt;—The number of seconds (between 1 and 600) before a connection request to the portal times out due to no response from the portal.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;i think this is not related to authentication but the ssl handshake to the portal itself, when this time expires the GP client attempts to find a cached version of the portal/gateway config.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I have tested failover using ssl/tls and it works if you use authentication sequence, have you tried this.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 29 Apr 2019 16:07:57 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-failover/m-p/259105#M73472</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-04-29T16:07:57Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-failover/m-p/259244#M73514</link>
      <description>&lt;P&gt;Hmmm... i have now reverted back to the auth profile that was timing out GlobalProtect.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;it now works... i have no idea why, i must have jolted something...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;ldap server profile hs 2 servers with ssl/tls-636&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;first server is not listening on 636, second server is.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;timers are 4,4,30.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;tries first server 2 times and then auths to second, all within 5-6 seconds, i have no idea what caused this to work as expected.&lt;/P&gt;</description>
      <pubDate>Tue, 30 Apr 2019 08:25:09 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-failover/m-p/259244#M73514</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-04-30T08:25:09Z</dc:date>
    </item>
    <item>
      <title>Re: LDAP authentication failover</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-failover/m-p/259407#M73561</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks for the information.&lt;/P&gt;&lt;P&gt;I have tested different scenarios in my LAB and found the following,&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;with plaintext ldap, failover is happening with configured timeout.&lt;/LI&gt;&lt;LI&gt;With LDAPS (over port 636), failover is working fine - here PA will by default try with SSL&lt;/LI&gt;&lt;LI&gt;With SSL/TLS over any other port, firewall is trying with TLS by default and wait for timeout then try with SSL - which may be the cause the higher timeout.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;In a nutshell, plantect and ssl connection is having the timeout configured, but if PA start with TLS, it causes higher timeout and GP auth fails.&lt;/P&gt;&lt;P&gt;Not sure why TLS connectivity does wait for the default timeout.&lt;/P&gt;</description>
      <pubDate>Wed, 01 May 2019 14:28:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/ldap-authentication-failover/m-p/259407#M73561</guid>
      <dc:creator>Abdul_Razaq</dc:creator>
      <dc:date>2019-05-01T14:28:48Z</dc:date>
    </item>
  </channel>
</rss>

