APM VPN LDAP POOL can't contact ldap server.

Hi,

I have a question regarding APM VPN and LDAP authentication.
When I configure the LDAP server using the direct LDAP Server IP, the authentication works fine.
However, when I use a Pool with the same LDAP Server IP, it shows the error message:

“Can’t contact LDAP server.”

From the packet capture, it seems that no traffic is being sent out at all.
Is there any specific configuration I need to adjust for LDAP Pool settings?

Thank you.

It shouldn’t be any different you’re just using a pool instead of directly accessing the ldap.
Only thing I can advise is maybe check that the pool and the member you’re using are actually available.
Go to pools search for your ldap  pool and make sure it is green and available.

What seeting does your LDAP pool has.

Maybe you have define specific port there? For example LDAP but in LDAP auth you choose ldaps?

Usually, at least in ad auth, where you can create a pool directly through ad auth config, the pool actually be created with wildcard port

Hi ShawnC,

If you use the “direct” option, communication will be through management.

If you use the “pool” option, it will be through TMM and self IPs will be used.

If self IP is not defined for the VLAN where the LDAP servers are located, and there is no TMM route, you can route the traffic from a different self IP.

I have confirmed that all POOL members are greenlit.

The setup uses LDAP on port 389 for everything. It works when configured as a ‘direct’ connection, but it fails when switching to the ‘pool’ configuration.

I am not sure that direct option uses mgmt
Unless of course there is no TMM route

Have you done a tcpdump to check if the traffic is leaving f5 correctly?

I configured a route domain, and I am unsure if that is affecting the issue. The VLAN responsible for authentication has a self-IP configured, but it does not have a floating IP.

you cannot use another route domain exept 0 for AD/LDAP auth if I am not wrong

If the pool is available you should run a tcpdump to see where the traffic is coming from,
plus look at ltm logs /var/log/ltm once you get the error, might be more information there.

Using tcpdump, I discovered that when using a pool, port 389 always sends out through other floating IPs.

The problem was that the interface I needed to route to didn’t have a floating IP configured, only its own IP. After configuring it, the connection worked.

I’m using two machines in HA mode. I found that using Direct routes sends the MGMT, while using Pool routes it sends the floating IP. I tried directly pointing the router to the VLAN, but without a floating IP, the data wasn’t sent out at all.

The conclusion is that a floating IP must be configured. Thank you for your help.

The problem was that the interface I was trying to access didn’t have a floating IP configured, only a self IP. After configuring the floating IP, it worked.

Finally, using Route domain 1 with a floating IP configured successfully verified the connection.

Thank you for your help.

Using tcpdump, I discovered that when using a pool, port 389 always sends out through other floating IPs.

The problem was that the interface I needed to route to didn’t have a floating IP configured, only its own IP. After configuring it, the connection worked.

I’m using two machines in HA mode. I found that using Direct routes sends the MGMT, while using Pool routes it sends the floating IP. I tried directly pointing the router to the VLAN, but without a floating IP, the data wasn’t sent out at all.

The conclusion is that a floating IP must be configured. Thank you for your help.

Hello @ShawnC

Thank you for posting to our community. I wanted to encourage you to update your post and mark as solved if it has been, or update if you are needing additional assistance and we can see what we can do to get you a solution.

-Melissa