MikeIs_61713
Aug 03, 2011Nimbostratus
Active Directory AAA server failing when just specify the domain name
Hi,
I am trying to setup an Active Directory AAA server on a BIG-IP Edge gateway to use when connecting to a web application. In defining the AAA server, I would just like to give the domain name, and let the edge gateway query DNS for the domain controllers for that domain.
Environment: BIG-IP Edge Gateway running 10.2.2 (Build 852). The edge's internal interface goes into to firewall, and DNS, Kerberos, LDPA and HTTP are allowed through the firewall to the dns sever/domain controller/web server.
When I configure the AAA server with just the domain name, and attempt to login, an error is returned that the edge gateway was unable to find a KDC for the domain (apologies, I do not have the exact message).
If I configure the AAA server with the IP address of one of the domain controllers, the login works fine.
Can anyone suggest why the edge is failing to connect to a KDC when I give just the domain name to the AAA server? Are there other ports I need to allow through the firewall??
Thanks in advance,
MikeI