<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Secure LDAP Policy Rule Setup in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/secure-ldap-policy-rule-setup/m-p/10867#M8012</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That worked.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 11 Mar 2015 14:33:18 GMT</pubDate>
    <dc:creator>dannon</dc:creator>
    <dc:date>2015-03-11T14:33:18Z</dc:date>
    <item>
      <title>Secure LDAP Policy Rule Setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-ldap-policy-rule-setup/m-p/10865#M8010</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to setup an application policy rule to allow secure LDAP from our hosting company back to our internal domain controller running MS AD.&amp;nbsp; I have the appropriate NAT statement setup.&lt;IMG alt="ldaps2.jpg" class="image-0 jive-image" height="255" src="https://live.paloaltonetworks.com/legacyfs/online/18345_ldaps2.jpg" style="height: 255px; width: 1362.93px;" width="1363" /&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you look in the log screenshot above, you'll see that the first entry is being denied.&amp;nbsp; For my list of allowed applications in that rule, I have added LDAP and SSL.&amp;nbsp; My services tab is set at Application-default.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;For testing, I also tried just using regular LDAP with with just LDAP for application allowed, and services as Application-default.&amp;nbsp; That worked fine, as you can see in log entry 2-8.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Do I need to change the services to TCP-636 to get LDAPS to work?&amp;nbsp; I looked at the LDAP application object, and it lists 389, 636 as the ports it uses.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks.&lt;/P&gt;&lt;P&gt;Dannon&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Feb 2015 17:48:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-ldap-policy-rule-setup/m-p/10865#M8010</guid>
      <dc:creator>dannon</dc:creator>
      <dc:date>2015-02-19T17:48:26Z</dc:date>
    </item>
    <item>
      <title>Re: Secure LDAP Policy Rule Setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-ldap-policy-rule-setup/m-p/10866#M8011</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi &lt;A href="https://live.paloaltonetworks.com/u1/28936"&gt;dannon&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;You will have to allow SSL on service TCP-636 to make this work.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Firewall will not be able to identify it as LDAP unless you enable decryption.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 19 Feb 2015 20:24:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-ldap-policy-rule-setup/m-p/10866#M8011</guid>
      <dc:creator>bat</dc:creator>
      <dc:date>2015-02-19T20:24:39Z</dc:date>
    </item>
    <item>
      <title>Re: Secure LDAP Policy Rule Setup</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/secure-ldap-policy-rule-setup/m-p/10867#M8012</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;That worked.&amp;nbsp; Thanks.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 11 Mar 2015 14:33:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/secure-ldap-policy-rule-setup/m-p/10867#M8012</guid>
      <dc:creator>dannon</dc:creator>
      <dc:date>2015-03-11T14:33:18Z</dc:date>
    </item>
  </channel>
</rss>

