Hi,
We’ve recently implemented LDAP authentication for our Clariion arrays.
We’ve set our 2 AD servers in the domain for the LDAP authentication on each array.
My question is: In case 2 AD servers are set for authentication,
Does the array perform the authentication against the first server only
Or maybe the authentication is performed randomly between the 2 AD servers?
Couldn’t find an answer in the manuals.
We’d like to understand that in order know if we should expect high utilization on 1 of our DCs in case the authentication is performed on the first AD server only.
Thanks.
Solved! Go to Solution.
Hi wade3,
as far as i know and remember the arrays would query the first AD server as log as it is reachable and responsive. If there is an issue with your first server the second one would queried.
Hope this will help a litte.
regards
Was your question answered correctly? If so, please remember to mark your question Answered when you get the correct answer and award points to the person providing the answer. This helps others searching for a similar issue.
glen
Hi Sheron,
Thank you for you answer.
Unfortunately this video doesn't refer to cases which i have 2 AD Domain controllers assigned for LDAP authentication.
Any other suggestions?
Sorry Wade for the delayed response, I am trying to see if i there is anything more I could provide to answer this.
I will try to see if I can get access to try this and see how it works and will make an attempt to see if there are any ways to answer this.
In the mean time you can try opening a case with the clariion support , and if you find the answer kindly share as this would help in in future.
Regards,
Sheron
Hi wade3,
as far as i know and remember the arrays would query the first AD server as log as it is reachable and responsive. If there is an issue with your first server the second one would queried.
Hope this will help a litte.
regards
Sorry Wade,
No luck from my end. Can you open a case with clariion support and let me know how to do it too?
Regards,
Sheron
Thank you guys for your tries.
i will open an SR and update you with the results.
I appreciate your answers
Hi,
i checked it with EMC support, and got similar answer to what Sheron have mentioned:
It is found that the LDAP user is always authenticated by the primary AD server which is configured initially when the LDAP account for that user is created.
Only if the primary AD server fails then it will try authenticate from the secondary AD server.
It will not randomly validate from both the AD servers.