ACS 4.1 LDAP server NOT reachable.

Answered Question
Jun 1st, 2010

Hi,


We have ACS 4.1 running. Everything seems to be (and has been) working fine. But when I want to add a LDAP group mapping I get an error message saying "LDAP Server NOT reachable. Please check the configuration". The ldap authentications are working fine, I just can't add a groupmapping. Where do I start troubleshooting this one?


Regards Marco

Correct Answer by Jatin Katyal about 6 years 8 months ago

Marco,


1. Do we have large number of groups in LDAP or AD structure?
2. Also, does your Admin DN has right to query database?


ACS Authentication Process with a Generic LDAP User Database


http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/UsrDb.html#wp354562


Configuring a Generic LDAP External User Database


http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/UsrDb.html#wp354805


Also, please download the LDAP browser softerra to fetch the correct information and configure it accordingle.


http://www.ldapbrowser.com/download.htm


HTH

JK


Do rate helpful posts-



  • 1
  • 2
  • 3
  • 4
  • 5
Overall Rating: 5 (3 ratings)
Loading.
Correct Answer
Jatin Katyal Tue, 06/01/2010 - 05:22

Marco,


1. Do we have large number of groups in LDAP or AD structure?
2. Also, does your Admin DN has right to query database?


ACS Authentication Process with a Generic LDAP User Database


http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/UsrDb.html#wp354562


Configuring a Generic LDAP External User Database


http://www.cisco.com/en/US/docs/net_mgmt/cisco_secure_access_control_server_for_windows/4.2/user/guide/UsrDb.html#wp354805


Also, please download the LDAP browser softerra to fetch the correct information and configure it accordingle.


http://www.ldapbrowser.com/download.htm


HTH

JK


Do rate helpful posts-



kerklaanm Tue, 06/01/2010 - 07:21

Yes, we have approx 1200 groups in the OU. If I change the OU to one with less groupw it works fine. I moved the group I needed to another OU and then made the groupmapping. After that, changed the settings back as they were. And it works. Is this a known issue with many groups?

Jatin Katyal Tue, 06/01/2010 - 18:31

Marco,


Yes, this is a known issue.


CSCsg85495    ACS LDAP connectivity vs MS Active-Directory fails due to LDAP referrals


Active-Directory may return LDAP referrals which are not supported by ACS LDAP interface. As a result connectivity fails - "LDAP server not reachable" error message is displayed.


Work-Around:
Limit search scope to a lower sub-tree which doesn't contain referral to avoid the problem.


Regds

JK


Do rate helpful posts-

Jatin Katyal Fri, 06/04/2010 - 07:26

Marco,


Could you please mark this thread "RESOLVED" so that others can take benefits out of it.

Actions

This Discussion

Related Content