Forum Discussion
lkchen
Nimbostratus
Jul 07, 2008HA Domain Controllers
I've been asked to create a BigIP pool containing two Domain Controllers. Looking for HA, so Active/Standby is okay if load-balance isn't possible.
First question would be is this even possible?
Next being how to implement....
5 Replies
Sort By
- Mark_Curole
Nimbostratus
What is your goal here? Active Directory is HA by default if you are doing standard things like logins or any application that uses native APIs. If you have something like apache doing LDAP authentication then you can just setup a load balancing pool for LDAP against the domain controllers. - lkchen
Nimbostratus
With something to ask, the answer was LDAP. So, now the only problem is that the DC's have a default route, which is not the BigIP...and the BigIP is just tagged into the same VLAN as the DC's. - hoolio
Cirrostratus
If the client makes a request to the VIP but gets a response back directly from the DC, the client should drop the response as it's not coming from the IP it made the request from. You should be able to enable SNAT automap on the VIP to ensure the response goes back to the BIG-IP and the response to the client comes from the VIP address. - lkchen
Nimbostratus
Ya, it seemed to my fuzzy recollection and reasoning that SNATs would be needed and just turning on SNAT automap for the VIP was all that I would need to change. But, nobody here has ever used SNATS before, so I wasn't positive. - lkchen
Nimbostratus
Well, I turned on SNAT, and at least I could telnet into the port.
Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects