- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
06-12-2012 02:44 AM
Hi,
I have implemented a Palo Alto without Management interface, only an Inside interface/zone and Outside interface/zone. I configured the service route configuration to use Inside IP address for updates, dns... (all service routes). Also I have configured the network routing (all the networks that has to be accessed from Inside IP address.
The problem is on ldap connection. When I configure the group mapping, I get an error because PaloAlto can not connect to ldap server.
My tests:
If I do a ping to ldap host, I get: From <management IP> icmp seq=X Destination host unrecheable. But If I do a ping with source Iniside IP address to ldap host I get response.
admin@PA-500> show user group-mapping state all
Group Mapping(vsys1, type: e-directory): LDAP_userauth Bind DN : cn=admin,o=esteve Base : ou=info,ou=intranet,o=esteve Group Filter: (None) User Filter: (None) Servers : configured 1 servers 172.20.0.181(636) Last Action Time: 50 secs ago(took 3 secs) Next Action Time: In 10 secs Last LDAP error: Can't contact LDAP server Number of Groups: 0
Could be that ldap connection is being started on management interface and the service routing for this service is not working?
Regards,
06-13-2012 09:32 AM
Unfortunately only a single IP Address can be specificed. There is no need to put /32 mask, just the IP address. For example: 172.24.7.50
Attached is sample screenshot.
06-12-2012 11:09 AM
Hi David,
You need to specify a service route based on destination for ldap connections.
This can be done Device -> Setup -> Services -> Service Route Configuration -> set Destination(ldap server) and source Inside IP address
- Stefan
06-13-2012 01:15 AM
I have configured a destination to the ldap network with the Internal Source addres. Shuld I add a destination to host (maks 32) instead a destination to the network?
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!