Forum Discussion
MikeIs_61713
Nimbostratus
Aug 03, 2011Active Directory AAA server failing when just specify the domain name
Hi,
I am trying to setup an Active Directory AAA server on a BIG-IP Edge gateway to use when connecting to a web application. In defining the AAA server, I would just like to give the doma...
MikeIs_61713
Nimbostratus
Aug 09, 2011Solution: The following seemed to fix the problems
1. Allow LDAP UDP through firewall
2. Update /etc/krb5.conf on the BIG-IP to enable dns lookup for the realm and kdc
[libdefaults]
default_realm = EXAMPLE.COM
dns_lookup_realm = false
dns_lookup_kdc = false
ticket_lifetime = 24h
forwardable = yesThis then impacted AD Queries for authorisation, and we had to ensure that DNS could resolve both
_kerberos-master._udp
_kerberos._udpHelp guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects
