×

Warning message

  • Cisco Support Forums is in Read Only mode while the site is being migrated.
  • Cisco Support Forums is in Read Only mode while the site is being migrated.

ACS 4.1 LDAP server NOT reachable.

Answered Question
Jun 1st, 2010
User Badges:

Hi,


We have ACS 4.1 running. Everything seems to be (and has been) working fine. But when I want to add a LDAP group mapping I get an error message saying "LDAP Server NOT reachable. Please check the configuration". The ldap authentications are working fine, I just can't add a groupmapping. Where do I start troubleshooting this one?


Regards Marco

Correct Answer by Jatin Katyal about 7 years 2 months ago

Marco,


1. Do we have large number of groups in LDAP or AD structure?
2. Also, does your Admin DN has right to query database?


ACS Authentication Process with a Generic LDAP User Database


http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/UsrDb.html#wp354562


Configuring a Generic LDAP External User Database


http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/UsrDb.html#wp354805


Also, please download the LDAP browser softerra to fetch the correct information and configure it accordingle.


http://www.ldapbrowser.com/download.htm


HTH

JK


Do rate helpful posts-



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (3 ratings)
Loading.
Correct Answer
Jatin Katyal Tue, 06/01/2010 - 05:22
User Badges:
  • Cisco Employee,

Marco,


1. Do we have large number of groups in LDAP or AD structure?
2. Also, does your Admin DN has right to query database?


ACS Authentication Process with a Generic LDAP User Database


http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/UsrDb.html#wp354562


Configuring a Generic LDAP External User Database


http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/UsrDb.html#wp354805


Also, please download the LDAP browser softerra to fetch the correct information and configure it accordingle.


http://www.ldapbrowser.com/download.htm


HTH

JK


Do rate helpful posts-



kerklaanm Tue, 06/01/2010 - 07:21
User Badges:

Yes, we have approx 1200 groups in the OU. If I change the OU to one with less groupw it works fine. I moved the group I needed to another OU and then made the groupmapping. After that, changed the settings back as they were. And it works. Is this a known issue with many groups?

Jatin Katyal Tue, 06/01/2010 - 18:31
User Badges:
  • Cisco Employee,

Marco,


Yes, this is a known issue.


CSCsg85495    ACS LDAP connectivity vs MS Active-Directory fails due to LDAP referrals


Active-Directory may return LDAP referrals which are not supported by ACS LDAP interface. As a result connectivity fails - "LDAP server not reachable" error message is displayed.


Work-Around:
Limit search scope to a lower sub-tree which doesn't contain referral to avoid the problem.


Regds

JK


Do rate helpful posts-

Jatin Katyal Fri, 06/04/2010 - 07:26
User Badges:
  • Cisco Employee,

Marco,


Could you please mark this thread "RESOLVED" so that others can take benefits out of it.

Actions

This Discussion

Related Content