- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
12-04-2020 09:45 AM
Hello,
I need to create a source service route for LDAP on one of our PANs due to MGT interface IP being unable to access the LDAP servers (I am unable to change this). I have gone into Device, Setup, Services, Service Route Configuration, selected customize and then changed LDAP to use ethernet1/1 and the source of that address. I then committed the changes. However, I still see no changes to the LDAP requests... logs show that the PAN is still trying to access LDAP server over the MGT interface and after further research it seems I should see source service routes using this command : "debug dataplane internal vif route 250" but when I do that, it shows up as blank.
Is there some step I am missing?
Thanks.
12-07-2020 07:11 AM
I was able to get this work but only by doing an override on the local PAN. The settings are exactly the same as I used in Panorama but they only worked once I overrode the service route config.
Thanks.
12-04-2020 10:23 AM
That would be everything that you actually need to do to get this to work and that debug command should deffinately be showing something if properly configured. First thing I would do is go and make absolutely sure that you actually committed the configuration and that it didn't error out.
If you go into configure mode and run 'show deviceconfig system route service' it will list out all of your service routes. Verify that ldap is showing up properly.
12-04-2020 11:22 AM
Commit shows no error. When I go to the actual PAN device and look at the service route, I can see it's set to customize, and LDP has a source interface of ethernet1/1 and the source address of that interface.
'show deviceconfig system route service' returns 'service;'
Should this not be configured from Panorama (the interface is not showing as being overridden so I can see that the template pushed successfully but now I'm curious.)?
Thanks.
12-07-2020 07:11 AM
I was able to get this work but only by doing an override on the local PAN. The settings are exactly the same as I used in Panorama but they only worked once I overrode the service route config.
Thanks.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!