Forum Discussion

KEN_67036's avatar
KEN_67036
Icon for Nimbostratus rankNimbostratus
Apr 10, 2008

multiple hosts entries for AD authentication

Wondering if I can have multiple host entries for AD authentication incase of a AD server failure.?
  • Deb_Allen_18's avatar
    Deb_Allen_18
    Historic F5 Account
    Client auth, or admin auth?

     

     

    AFAIK, the only way to auth LTM with ACA (Advanced Client Authentication) module includes PAM (Pluggable Auth Module), and that is pretty flexible config-wise.

     

     

    For admin auth using AD, it looks like you can specify a hostname OR an IP for Host, and it is retained in the config file as a name instead of resolving to an IP. Since that's the case, you can use a hostname that resolves to multiple IP addresses.

     

     

    Better yet, you could use a service (like GTM) that hands out only one known good address with a short TTL, and minimize local visibility of failure.

     

     

    HTH

     

    /deb
  • Thanks Deb,

     

    I have entered multiple host IP's using the GUI putting spaces between the IP address entries and it seems to work. We will be looking at a GTM down the road but for now I just needed some redundancy for AD authentication when a server is taken down for maintenance or if there is a failure.

     

     

    Thanks again!

     

    Regards,

     

    Kim