Forum Discussion
smp_86112
Cirrostratus
Aug 18, 2009Slow AD Auth LTM MGMT GUI
I have the management interfaces of a GTM and an LTM configured to use Active Directory authentication. Based on the admin GUI settings, both units are configured exactly the same. When I authenticate...
smp_86112
Cirrostratus
Sep 03, 2009We suddenly had difficulties again logging in to our F5 equipment yesterday. This time it happened on all our F5 equipment located in our DMZs. It turns out, for some unknown reason, that the /etc/resolv.conf file on all our F5 equipment had the following directive:
search localhost.com
We did not add this intentionally, so I don't know how/when this was added. But localhost.com is a valid internet domain and apparently whoever hosts this domain is having trouble with their DNS servers - nslookup on localhost.com varies between timeouts, a valid address, and an address in the 10.x.x.x/8 private address space. By performing network traces, I could see that the F5 equipment was appending localhost.com to its attempts to resolve our Active Directory domain name in DNS. But since the localhost.com DNS server was having trouble, our login attempts were timing out.
By commenting out the search directive in /etc/resolv.conf and restarting httpd, our logins recovered. Our internal F5 units were not affected because they can not resolve Internet names.
Wow, we were lucky to figure this one out. This is another good thing to check if you are having AD auth problems.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects