<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Getting LDAP Error in General Topics</title>
    <link>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/387793#M90424</link>
    <description>&lt;P&gt;Hi, I'm seeing the same error in the logs. What was the fix for this?&lt;/P&gt;</description>
    <pubDate>Thu, 25 Feb 2021 15:28:04 GMT</pubDate>
    <dc:creator>bwadmin</dc:creator>
    <dc:date>2021-02-25T15:28:04Z</dc:date>
    <item>
      <title>Getting LDAP Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300486#M78510</link>
      <description>&lt;DIV&gt;Our client is having issues with LDAP connectivity.&lt;/DIV&gt;&lt;DIV&gt;&lt;BR /&gt;We are trying to configure "Group Include List" in the Group Mapping Settings in User Identification but when we click on the Base DN to browse available groups, we get "Connect error".&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;Same thing showing on CLI:&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;PA-850-1(active)&amp;gt; show user group-mapping state all&lt;BR /&gt;&lt;BR /&gt;Group Mapping(vsys1, type: active-directory): ADMap&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Bind DN&amp;nbsp;&amp;nbsp;&amp;nbsp; : CN=svc_paloalto_auth,OU=Service Accounts,OU=Consult Cloud,OU=Hosted,DC=cloud,DC=local&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Base&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; : DC=cloud,DC=local&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Group Filter: (None)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; User Filter: (None)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Servers&amp;nbsp;&amp;nbsp;&amp;nbsp; : configured 2 servers&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.10.21(636)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last LDAP error: Connect error&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.0.25(636)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last Action Time: 19 secs ago(took 0 secs)&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Next Action Time: In 41 secs&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Last LDAP error: Connect error&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Number of Groups: 0&lt;/DIV&gt;&lt;DIV&gt;&amp;nbsp;&lt;/DIV&gt;&lt;DIV&gt;When doing tcpdump, we can see TCP connection established on port 636 (we're using SSL), but AD server resets the connection.&lt;/DIV&gt;&lt;DIV&gt;Any idea how to resolve this issue?&lt;/DIV&gt;</description>
      <pubDate>Mon, 25 Nov 2019 05:16:37 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300486#M78510</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-11-25T05:16:37Z</dc:date>
    </item>
    <item>
      <title>Re: Getting LDAP Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300493#M78511</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is this new setup or was it working before?&lt;/P&gt;&lt;P&gt;IS password configured &amp;nbsp;on the PA correct?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 05:25:33 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300493#M78511</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-11-25T05:25:33Z</dc:date>
    </item>
    <item>
      <title>Re: Getting LDAP Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300501#M78513</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;New setup but&amp;nbsp;&lt;SPAN&gt;configuration matched with working solution in different data centre.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;The service account for this setup resides in the same OU as the service account for the solution that does work.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Yes password is correct.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 05:27:53 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300501#M78513</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-11-25T05:27:53Z</dc:date>
    </item>
    <item>
      <title>Re: Getting LDAP Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300502#M78514</link>
      <description>&lt;P&gt;try this command please&lt;/P&gt;&lt;DIV&gt;&lt;DIV&gt;test authentication authentication-profile LDAP-Profile username User4-LDAP password&lt;/DIV&gt;&lt;/DIV&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 05:33:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300502#M78514</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-11-25T05:33:36Z</dc:date>
    </item>
    <item>
      <title>Re: Getting LDAP Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300504#M78516</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;test authentication authentication-profile LDAP-Profile username User4-LDAP password&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;can be used to verify username/password once LDAP connectivity has been established.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;You can’t use the command to verify the service-account, because it requires LDAP connectivity… which is failing to connect.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 05:50:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300504#M78516</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-11-25T05:50:56Z</dc:date>
    </item>
    <item>
      <title>Re: Getting LDAP Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300529#M78520</link>
      <description>&lt;P&gt;do you have the ability to flip ssl off, go back to port 389, then capture packets to see if this is a SSL issue with version mismatch&amp;nbsp; or cert expiry........&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;or issues with Bind itself.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 09:05:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300529#M78520</guid>
      <dc:creator>Mick_Ball</dc:creator>
      <dc:date>2019-11-25T09:05:01Z</dc:date>
    </item>
    <item>
      <title>Re: Getting LDAP Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300674#M78554</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/9981"&gt;@Mick_Ball&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;During some further troubleshooting yesterday, I found that the Palo Alto was actually denying the SSL connection to the LDAP server and sending RST to in both directions.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;All is good now.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Thanks for your help.&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 22:21:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300674#M78554</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-11-25T22:21:47Z</dc:date>
    </item>
    <item>
      <title>Re: Getting LDAP Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300675#M78555</link>
      <description>&lt;P&gt;was this connection via Management plane?&lt;/P&gt;</description>
      <pubDate>Mon, 25 Nov 2019 23:16:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300675#M78555</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-11-25T23:16:44Z</dc:date>
    </item>
    <item>
      <title>Re: Getting LDAP Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300875#M78593</link>
      <description>&lt;P&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/75039"&gt;@MP18&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Yes.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2019 22:59:03 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300875#M78593</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2019-11-26T22:59:03Z</dc:date>
    </item>
    <item>
      <title>Re: Getting LDAP Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300888#M78595</link>
      <description>&lt;P&gt;Thanks Farzana.&lt;/P&gt;</description>
      <pubDate>Tue, 26 Nov 2019 23:31:52 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/300888#M78595</guid>
      <dc:creator>MP18</dc:creator>
      <dc:date>2019-11-26T23:31:52Z</dc:date>
    </item>
    <item>
      <title>Re: Getting LDAP Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/387793#M90424</link>
      <description>&lt;P&gt;Hi, I'm seeing the same error in the logs. What was the fix for this?&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 15:28:04 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/387793#M90424</guid>
      <dc:creator>bwadmin</dc:creator>
      <dc:date>2021-02-25T15:28:04Z</dc:date>
    </item>
    <item>
      <title>Re: Getting LDAP Error</title>
      <link>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/387935#M90446</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/49687"&gt;@bwadmin&lt;/a&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Please check the Traffic logs if the security policy is denying the traffic to LDAP server.&lt;/P&gt;</description>
      <pubDate>Thu, 25 Feb 2021 22:46:34 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/general-topics/getting-ldap-error/m-p/387935#M90446</guid>
      <dc:creator>FarzanaMustafa</dc:creator>
      <dc:date>2021-02-25T22:46:34Z</dc:date>
    </item>
  </channel>
</rss>

