Service route for ldap

cancel
Showing results for 
Search instead for 
Did you mean: 

Service route for ldap

Not applicable

Hi,

I have implemented a Palo Alto without Management interface, only an Inside interface/zone and Outside interface/zone. I configured the service route configuration to use Inside IP address for updates, dns... (all service routes). Also I have configured the network routing (all the networks that has to be accessed from Inside IP address.

The problem is on ldap connection. When I configure the group mapping, I get an error because PaloAlto can not connect to ldap server.

My tests:

If I do a ping to ldap host, I get: From <management IP> icmp seq=X Destination host unrecheable. But If I do a ping with source Iniside IP address to ldap host I get response.

admin@PA-500> show user group-mapping state all

Group Mapping(vsys1, type: e-directory): LDAP_userauth        Bind DN    : cn=admin,o=esteve        Base       : ou=info,ou=intranet,o=esteve        Group Filter: (None)        User Filter: (None)        Servers    : configured 1 servers                172.20.0.181(636)                        Last Action Time: 50 secs ago(took 3 secs)                        Next Action Time: In 10 secs                        Last LDAP error: Can't contact LDAP server        Number of Groups: 0

Could be that ldap connection is being started on management interface and the service routing for this service is not working?

Regards,

1 ACCEPTED SOLUTION

Accepted Solutions

Unfortunately only a single IP Address can be specificed. There is no need to put /32 mask, just the IP address. For example: 172.24.7.50

Attached is sample screenshot.

View solution in original post

3 REPLIES 3

L4 Transporter

Hi David,

You need to specify a service route based on destination for ldap connections.

This can be done Device -> Setup -> Services -> Service Route Configuration -> set Destination(ldap server) and source Inside IP address

- Stefan

I have configured a destination to the ldap network with the Internal Source addres. Shuld I add a destination to host (maks 32) instead a destination to the network?

Unfortunately only a single IP Address can be specificed. There is no need to put /32 mask, just the IP address. For example: 172.24.7.50

Attached is sample screenshot.

View solution in original post

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!