<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GP Issue with LDAP timeouts in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/gp-issue-with-ldap-timeouts/m-p/341893#M85742</link>
    <description>&lt;P&gt;Bind timeout - Time spent trying to connect to a server before marking it 'down'.&amp;nbsp; Will try next in list&lt;/P&gt;&lt;P&gt;Search timeout&amp;nbsp; - Time spent on a successful server attempting a search.&amp;nbsp; Does not mark it down, just incomplete&lt;/P&gt;&lt;P&gt;Retry - Time to 'wait' before reconnecting to a 'down' server (from bind)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the auth is failing, is it returning an 'auth failed' to the user, or just timing out?&amp;nbsp; If auth failed, they need to enter their username/pw correctly (in format the DC likes)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would suggest (since you have two servers) lowing BIND to 10 seconds, leave search as is. For the retry interval - lower is good for a network 'blip'.&amp;nbsp; Higher is better if you feel the outage will be &amp;gt; 60 second (reboot of server).&lt;/P&gt;</description>
    <pubDate>Mon, 03 Aug 2020 19:59:15 GMT</pubDate>
    <dc:creator>Chris_Johnston</dc:creator>
    <dc:date>2020-08-03T19:59:15Z</dc:date>
    <item>
      <title>GP Issue with LDAP timeouts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-issue-with-ldap-timeouts/m-p/340797#M85504</link>
      <description>&lt;P&gt;Hello Folks ,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We are having an issue with LDAP auth . We have two servers in LDAP profile&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;10.1.1.4&lt;/P&gt;&lt;P&gt;10.1.1.26&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The timeout settings are&lt;/P&gt;&lt;P&gt;Bind timeout 30 seconds&lt;/P&gt;&lt;P&gt;Search timeout 30 seconds&lt;/P&gt;&lt;P&gt;Retry 60 seconds&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The GP timeout is 80 seconds&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The behaviour is quite random . Most of the time the auth fails to 10.1.1.4 but it never goes to next server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;but some times when elapsed timeout is around 35-40 seconds , it goes to second server&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;What is the meaning of Search timeout ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do i have to decrease the bind and search timeouts ?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;-Tom&lt;/P&gt;</description>
      <pubDate>Mon, 27 Jul 2020 08:34:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-issue-with-ldap-timeouts/m-p/340797#M85504</guid>
      <dc:creator>FWPalolearner</dc:creator>
      <dc:date>2020-07-27T08:34:36Z</dc:date>
    </item>
    <item>
      <title>Re: GP Issue with LDAP timeouts</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/gp-issue-with-ldap-timeouts/m-p/341893#M85742</link>
      <description>&lt;P&gt;Bind timeout - Time spent trying to connect to a server before marking it 'down'.&amp;nbsp; Will try next in list&lt;/P&gt;&lt;P&gt;Search timeout&amp;nbsp; - Time spent on a successful server attempting a search.&amp;nbsp; Does not mark it down, just incomplete&lt;/P&gt;&lt;P&gt;Retry - Time to 'wait' before reconnecting to a 'down' server (from bind)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;When the auth is failing, is it returning an 'auth failed' to the user, or just timing out?&amp;nbsp; If auth failed, they need to enter their username/pw correctly (in format the DC likes)&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Would suggest (since you have two servers) lowing BIND to 10 seconds, leave search as is. For the retry interval - lower is good for a network 'blip'.&amp;nbsp; Higher is better if you feel the outage will be &amp;gt; 60 second (reboot of server).&lt;/P&gt;</description>
      <pubDate>Mon, 03 Aug 2020 19:59:15 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/gp-issue-with-ldap-timeouts/m-p/341893#M85742</guid>
      <dc:creator>Chris_Johnston</dc:creator>
      <dc:date>2020-08-03T19:59:15Z</dc:date>
    </item>
  </channel>
</rss>

