Enhanced Security Measures in Place:   To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.

Service Route Help

cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 
Announcements

Service Route Help

L2 Linker

Hello,

 

 I need to create a source service route for LDAP on one of our PANs due to MGT interface IP being unable to access the LDAP servers (I am unable to change this).    I have gone into Device, Setup, Services, Service Route Configuration, selected customize and then changed LDAP to use ethernet1/1 and the source of that address.  I then committed the changes.  However, I still see no changes to the LDAP requests... logs show that the PAN is still trying to access LDAP server over the MGT interface and after further research it seems I should see source service routes using this command : "debug dataplane internal vif route 250" but when I do that, it shows up as blank.  

 

 Is there some step I am missing?

 

 Thanks. 

1 accepted solution

Accepted Solutions

I was able to get this work but only by doing an override on the local PAN.  The settings are exactly the same as I used in Panorama but they only worked once I overrode the service route config.

 

Thanks. 

View solution in original post

3 REPLIES 3

Cyber Elite
Cyber Elite

@COlson,

That would be everything that you actually need to do to get this to work and that debug command should deffinately be showing something if properly configured. First thing I would do is go and make absolutely sure that you actually committed the configuration and that it didn't error out. 

If you go into configure mode and run 'show deviceconfig system route service' it will list out all of your service routes. Verify that ldap is showing up properly. 

Commit shows no error.  When I go to the actual PAN device and look at the service route, I can see it's set to customize, and LDP has a source interface of ethernet1/1 and the source address of that interface. 

 

'show deviceconfig system route service' returns 'service;'

 

Should this not be configured from Panorama (the interface is not showing as being overridden so I can see that the template pushed successfully but now I'm curious.)?

 

Thanks.

 

 

I was able to get this work but only by doing an override on the local PAN.  The settings are exactly the same as I used in Panorama but they only worked once I overrode the service route config.

 

Thanks. 

  • 1 accepted solution
  • 3051 Views
  • 3 replies
  • 0 Likes
Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!