Forum Discussion

David_N_212709's avatar
David_N_212709
Icon for Nimbostratus rankNimbostratus
Jul 24, 2015

Load balancing / proxying AD itself?

I see iApp templates for ADFS but am having trouble figuring out if we can load balance / proxy AD itself.

 

A little background: We have a web-based application that authenticates users against AD, and its config screen requires you to specify a single AD server. If that AD server goes down then nobody can log in.

 

What we'd like to do is improve reliability by having a virtual server on our BIG-IP that points to a pool of AD servers instead.

 

1 Reply

  • Does the iApp also allow you to specify the domain name? Active Directory is pretty good at load balancing itself (and is recommended). If you can specify an AD domain instead of a DC server address, the system should perform a SRV DNS lookup to find the active/preferred DC.

     

    Otherwise, if you know the ports you'll be using to talk to the AD (ex. 389, 636, etc.), you could create a VIP on that port, create a pool of AD servers and use an appropriate monitor, and point your iApp at that VIP. That said, you're relying on the (external) monitor to tell you the health of a domain controller - something that is usually better left the AD itself.