<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Been having a strange LDAP issue lately in ONTAP Discussions</title>
    <link>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/149716#M33307</link>
    <description>&lt;P&gt;Hi Sycraft,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does your verver have a route to the domain controller\global catalgue server? I had a quick search for you in NetApp Support. I can't be sure if this is related given the limited details but check the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A title="https://kb.netapp.com/app/answers/answer_view/a_id/1080502" href="https://kb.netapp.com/app/answers/answer_view/a_id/1080502" target="_blank" rel="noopener"&gt;https://kb.netapp.com/app/answers/answer_view/a_id/1080502&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are there any additional logs you can post? Also is your vserver in any type of secured network zone with firewall restrictions that could be blocking access to the domain controller\global catalogue? I check the following ports are allowed between your vserver and DC&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;UL&gt;
&lt;LI&gt;port 389 (UDP and TCP) – LDAP&lt;/LI&gt;
&lt;LI&gt;port 464 (TCP) - Kerberos Kpasswd&lt;/LI&gt;
&lt;LI&gt;port 88 (UDP and TCP)&amp;nbsp; - Kerberos Traffic&lt;/LI&gt;
&lt;LI&gt;port 3268 (TCP) - Global Catalog&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;Note: if using SSL to secure AD you'd need LDAPs(636) and MSFT-GC-SSL(3269)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Given the error states "&lt;STRONG&gt;&lt;EM&gt;Operation: SiteDiscovery&lt;/EM&gt;&lt;/STRONG&gt;" i'd check the vserver can contact the global catalogue (just a suspicion, couldn't find any related information to that specificially). For a more verbose list see the following firewall port requirements:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd772723(v=ws.10)" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd772723(v=ws.10)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/Matt&lt;/P&gt;</description>
    <pubDate>Fri, 19 Jul 2019 02:23:09 GMT</pubDate>
    <dc:creator>mbeattie</dc:creator>
    <dc:date>2019-07-19T02:23:09Z</dc:date>
    <item>
      <title>Been having a strange LDAP issue lately</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/149713#M33306</link>
      <description>&lt;P&gt;Multiple times a day I get the following error in the logs:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;DIV class="x-form-item " tabindex="-1" role="presentation"&gt;&lt;LABEL class="x-form-item-label" for="gwt-debug-ENGR-VastEventsPageEventLabelField"&gt;Event:&lt;/LABEL&gt;
&lt;DIV id="x-form-el-gwt-debug-ENGR-VastEventsPageEventLabelField" class="x-form-element x-form-el-gwt-debug-ENGR-VastEventsPageEventLabelField" role="presentation"&gt;
&lt;DIV id="gwt-debug-ENGR-VastEventsPageEventLabelField" class=" x-form-label x-component" title="secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery)." aria-describedby="x-auto-227"&gt;secd.ldap.noServers: None of the LDAP servers configured for Vserver (*******) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="x-form-clear-left" role="presentation"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;DIV class="x-form-item " tabindex="-1" role="presentation"&gt;&lt;LABEL class="x-form-item-label" for="gwt-debug-ENGR-VastEventsPageMessageNameLabelField"&gt;Message Name:&lt;/LABEL&gt;
&lt;DIV id="x-form-el-gwt-debug-ENGR-VastEventsPageMessageNameLabelField" class="x-form-element x-form-el-gwt-debug-ENGR-VastEventsPageMessageNameLabelField" role="presentation"&gt;
&lt;DIV id="gwt-debug-ENGR-VastEventsPageMessageNameLabelField" class=" x-form-label x-component" aria-describedby="x-auto-228"&gt;secd.ldap.noServers&lt;/DIV&gt;
&lt;DIV class=" x-form-label x-component" aria-describedby="x-auto-228"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=" x-form-label x-component" aria-describedby="x-auto-228"&gt;Thing is, when I look up the error and then try the diags, they work fine. The FAS has no trouble talking to the AD servers that are doing LDAP. For example:&lt;/DIV&gt;
&lt;DIV class=" x-form-label x-component" aria-describedby="x-auto-228"&gt;&amp;nbsp;&lt;/DIV&gt;
&lt;DIV class=" x-form-label x-component" aria-describedby="x-auto-228"&gt;
&lt;P&gt;******::&amp;gt; ldap check -vserver *****&lt;/P&gt;
&lt;P&gt;Vserver: *****&lt;BR /&gt;Client Configuration Name: Linux&lt;BR /&gt;LDAP Status: up&lt;BR /&gt;LDAP Status Details: Successfully connected to LDAP server "10.***.***.***".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;There are no issues with users accessing files that I'm aware of. I'm at a loss as to what the cause or resolution is. I'm not a UNIX guy myself and the LInux admin is disinterested in working on diagnosing it since it is "working fine and just generating warnings".&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any ideas?&lt;/P&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;
&lt;/DIV&gt;</description>
      <pubDate>Thu, 18 Jul 2019 22:01:51 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/149713#M33306</guid>
      <dc:creator>Sycraft</dc:creator>
      <dc:date>2019-07-18T22:01:51Z</dc:date>
    </item>
    <item>
      <title>Re: Been having a strange LDAP issue lately</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/149716#M33307</link>
      <description>&lt;P&gt;Hi Sycraft,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Does your verver have a route to the domain controller\global catalgue server? I had a quick search for you in NetApp Support. I can't be sure if this is related given the limited details but check the following:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A title="https://kb.netapp.com/app/answers/answer_view/a_id/1080502" href="https://kb.netapp.com/app/answers/answer_view/a_id/1080502" target="_blank" rel="noopener"&gt;https://kb.netapp.com/app/answers/answer_view/a_id/1080502&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Are there any additional logs you can post? Also is your vserver in any type of secured network zone with firewall restrictions that could be blocking access to the domain controller\global catalogue? I check the following ports are allowed between your vserver and DC&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;UL&gt;
&lt;UL&gt;
&lt;LI&gt;port 389 (UDP and TCP) – LDAP&lt;/LI&gt;
&lt;LI&gt;port 464 (TCP) - Kerberos Kpasswd&lt;/LI&gt;
&lt;LI&gt;port 88 (UDP and TCP)&amp;nbsp; - Kerberos Traffic&lt;/LI&gt;
&lt;LI&gt;port 3268 (TCP) - Global Catalog&lt;/LI&gt;
&lt;/UL&gt;
&lt;/UL&gt;
&lt;P&gt;Note: if using SSL to secure AD you'd need LDAPs(636) and MSFT-GC-SSL(3269)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Given the error states "&lt;STRONG&gt;&lt;EM&gt;Operation: SiteDiscovery&lt;/EM&gt;&lt;/STRONG&gt;" i'd check the vserver can contact the global catalogue (just a suspicion, couldn't find any related information to that specificially). For a more verbose list see the following firewall port requirements:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd772723(v=ws.10)" target="_blank" rel="noopener"&gt;https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/dd772723(v=ws.10)&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope that helps&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;/Matt&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 02:23:09 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/149716#M33307</guid>
      <dc:creator>mbeattie</dc:creator>
      <dc:date>2019-07-19T02:23:09Z</dc:date>
    </item>
    <item>
      <title>Re: Been having a strange LDAP issue lately</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/149738#M33314</link>
      <description>&lt;P&gt;Ya it can reach the GC just fine, all 6 DCs are Global Catalog servers in this domain, and it can reach all of them. It is not in any kind of restricted space, just our regular server subnet which has no outbound firewall, and an inbound firewall that allows traffic from the subnets where the DCs live explicitly.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What's stranger still is there's no issue on the CIFS SVM. We have two SVMs, one for CIFS, one for NFS. The CIFS SVM is happy as can be, no errors, just the NFS one that is generating errors. It is working fine as far as I know at serving files, hence why our UNIX guy doesn't want to work on the issue, just throwing errors in the logs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What additonal logs would be useful in trying to diagnose this issue?&lt;/P&gt;</description>
      <pubDate>Fri, 19 Jul 2019 21:00:32 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/149738#M33314</guid>
      <dc:creator>Sycraft</dc:creator>
      <dc:date>2019-07-19T21:00:32Z</dc:date>
    </item>
    <item>
      <title>Re: Been having a strange LDAP issue lately</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/149774#M33326</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks, that eliminates a lot of potential troubleshooting areas. Next I'd start by checking for any other secd errors that might be related and determine how frequently the issue occurrs.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;event log show -message-name secd.*&lt;/PRE&gt;
&lt;P&gt;&lt;SPAN style="font-family: courier new,courier,monospace;"&gt;&lt;/SPAN&gt;/Matt&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 01:03:33 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/149774#M33326</guid>
      <dc:creator>mbeattie</dc:creator>
      <dc:date>2019-07-23T01:03:33Z</dc:date>
    </item>
    <item>
      <title>Re: Been having a strange LDAP issue lately</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/149800#M33328</link>
      <description>&lt;P&gt;Looks like every couple hours there's a LSA no servers and LDAP no servers emergency. For reference ENGR-Linuxstore is the NFS server, ENGR-NAS is the CIFS server and 10.140.96.31 and 51 are two of the DCs. They are also used as the primary and secondary DNS servers for all our systems.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The log follows:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Time Node Severity Event&lt;BR /&gt;------------------- ---------------- ------------- ---------------------------&lt;BR /&gt;7/23/2019 16:01:02 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.51 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/23/2019 15:00:39 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/23/2019 14:00:52 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/23/2019 13:22:46 ENGR-Vast_A EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/23/2019 13:22:44 ENGR-Vast_A EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/23/2019 13:08:54 ENGR-Vast_B EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/23/2019 13:08:54 ENGR-Vast_B EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/23/2019 13:00:39 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/23/2019 12:24:36 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.51 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/23/2019 12:00:36 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/23/2019 11:47:11 ENGR-Vast_B ERROR secd.cifsAuth.denied: vserver (ENGR-NAS) Cannot authenticate CIFS user. Error: User authentication procedure failed&lt;BR /&gt;CIFS SMB2 Share mapping - Client Ip = 10.140.96.31&lt;BR /&gt;[ 0 ms] LM Compatibility level set to ntlmv2-krb disallowed NTLM authentication&lt;BR /&gt;**[ 0] FAILURE: CIFS authentication failed&lt;BR /&gt;7/23/2019 11:00:48 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/23/2019 10:00:32 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/23/2019 09:24:51 ENGR-Vast_A EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/23/2019 09:24:49 ENGR-Vast_A EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/23/2019 09:16:17 ENGR-Vast_B ERROR secd.cifsAuth.denied: vserver (ENGR-NAS) Cannot authenticate CIFS user. Error: User authentication procedure failed&lt;BR /&gt;CIFS SMB2 Share mapping - Client Ip = 10.140.96.31&lt;BR /&gt;[ 0 ms] LM Compatibility level set to ntlmv2-krb disallowed NTLM authentication&lt;BR /&gt;**[ 0] FAILURE: CIFS authentication failed&lt;BR /&gt;7/23/2019 09:14:15 ENGR-Vast_B ERROR secd.cifsAuth.denied: vserver (ENGR-NAS) Cannot authenticate CIFS user. Error: User authentication procedure failed&lt;BR /&gt;CIFS SMB2 Share mapping - Client Ip = 10.140.96.31&lt;BR /&gt;[ 0 ms] LM Compatibility level set to ntlmv2-krb disallowed NTLM authentication&lt;BR /&gt;**[ 0] FAILURE: CIFS authentication failed&lt;BR /&gt;7/23/2019 09:13:16 ENGR-Vast_A ERROR secd.dns.server.timed.out: DNS server 10.140.96.31 did not respond to vserver = ENGR-NAS within timeout interval.&lt;BR /&gt;7/23/2019 09:11:44 ENGR-Vast_B EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/23/2019 09:11:43 ENGR-Vast_B EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/23/2019 09:01:18 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/23/2019 08:01:23 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.51 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/23/2019 07:01:03 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/23/2019 06:01:07 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/23/2019 05:24:56 ENGR-Vast_A EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/23/2019 05:24:54 ENGR-Vast_A EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/23/2019 05:10:02 ENGR-Vast_B EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/23/2019 05:10:01 ENGR-Vast_B EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/23/2019 05:00:52 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/23/2019 04:01:57 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/23/2019 03:00:42 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/23/2019 02:06:58 ENGR-Vast_A ERROR secd.cifsAuth.denied: vserver (ENGR-NAS) Cannot authenticate CIFS user. Error: User authentication procedure failed&lt;BR /&gt;CIFS SMB2 Share mapping - Client Ip = 10.140.96.31&lt;BR /&gt;[ 0 ms] LM Compatibility level set to ntlmv2-krb disallowed NTLM authentication&lt;BR /&gt;**[ 0] FAILURE: CIFS authentication failed&lt;BR /&gt;7/23/2019 02:04:49 ENGR-Vast_A ERROR secd.cifsAuth.denied: vserver (ENGR-NAS) Cannot authenticate CIFS user. Error: User authentication procedure failed&lt;BR /&gt;CIFS SMB2 Share mapping - Client Ip = 10.140.96.31&lt;BR /&gt;[ 0 ms] LM Compatibility level set to ntlmv2-krb disallowed NTLM authentication&lt;BR /&gt;**[ 0] FAILURE: CIFS authentication failed&lt;BR /&gt;7/23/2019 02:00:31 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/23/2019 01:24:00 ENGR-Vast_A EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/23/2019 01:23:55 ENGR-Vast_A EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/23/2019 01:03:40 ENGR-Vast_B EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/23/2019 01:03:39 ENGR-Vast_B EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/23/2019 01:01:14 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.51 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/23/2019 00:04:49 ENGR-Vast_B ERROR secd.cifsAuth.denied: vserver (ENGR-NAS) Cannot authenticate CIFS user. Error: User authentication procedure failed&lt;BR /&gt;CIFS SMB2 Share mapping - Client Ip = 10.140.96.31&lt;BR /&gt;[ 0 ms] LM Compatibility level set to ntlmv2-krb disallowed NTLM authentication&lt;BR /&gt;**[ 0] FAILURE: CIFS authentication failed&lt;BR /&gt;7/23/2019 00:02:40 ENGR-Vast_B ERROR secd.cifsAuth.denied: vserver (ENGR-NAS) Cannot authenticate CIFS user. Error: User authentication procedure failed&lt;BR /&gt;CIFS SMB2 Share mapping - Client Ip = 10.140.96.31&lt;BR /&gt;[ 0 ms] LM Compatibility level set to ntlmv2-krb disallowed NTLM authentication&lt;BR /&gt;**[ 0] FAILURE: CIFS authentication failed&lt;BR /&gt;7/23/2019 00:00:40 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.51 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/23/2019 00:00:28 ENGR-Vast_B ERROR secd.cifsAuth.denied: vserver (ENGR-NAS) Cannot authenticate CIFS user. Error: User authentication procedure failed&lt;BR /&gt;CIFS SMB2 Share mapping - Client Ip = 10.140.96.31&lt;BR /&gt;[ 0 ms] LM Compatibility level set to ntlmv2-krb disallowed NTLM authentication&lt;BR /&gt;**[ 0] FAILURE: CIFS authentication failed&lt;BR /&gt;7/22/2019 23:00:33 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 22:00:44 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.51 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 21:25:34 ENGR-Vast_A EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/22/2019 21:25:32 ENGR-Vast_A EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/22/2019 21:00:50 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 20:56:56 ENGR-Vast_B EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/22/2019 20:56:55 ENGR-Vast_B EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/22/2019 20:00:35 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.51 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 19:00:32 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 18:01:44 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 17:25:10 ENGR-Vast_A EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/22/2019 17:25:08 ENGR-Vast_A EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/22/2019 17:00:35 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.52 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 16:56:45 ENGR-Vast_B EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/22/2019 16:56:44 ENGR-Vast_B EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/22/2019 16:01:41 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.51 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 15:00:44 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 14:01:23 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 13:31:45 ENGR-Vast_A EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;Press &amp;lt;space&amp;gt; to page down, &amp;lt;return&amp;gt; for next line, or 'q' to quit... &lt;BR /&gt;Time Node Severity Event&lt;BR /&gt;------------------- ---------------- ------------- ---------------------------&lt;BR /&gt;7/22/2019 13:31:40 ENGR-Vast_A EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/22/2019 13:10:08 ENGR-Vast_A ERROR secd.cifsAuth.denied: vserver (ENGR-NAS) Cannot authenticate CIFS user. Error: User authentication procedure failed&lt;BR /&gt;CIFS SMB2 Share mapping - Client Ip = 10.140.96.32&lt;BR /&gt;[ 0 ms] LM Compatibility level set to ntlmv2-krb disallowed NTLM authentication&lt;BR /&gt;**[ 0] FAILURE: CIFS authentication failed&lt;BR /&gt;7/22/2019 13:02:05 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 12:55:05 ENGR-Vast_B EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/22/2019 12:55:05 ENGR-Vast_B EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/22/2019 12:25:13 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 12:00:28 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 11:51:26 ENGR-Vast_B ERROR secd.cifsAuth.denied: vserver (ENGR-NAS) Cannot authenticate CIFS user. Error: User authentication procedure failed&lt;BR /&gt;CIFS SMB2 Share mapping - Client Ip = 10.140.96.31&lt;BR /&gt;[ 0 ms] LM Compatibility level set to ntlmv2-krb disallowed NTLM authentication&lt;BR /&gt;**[ 0] FAILURE: CIFS authentication failed&lt;BR /&gt;7/22/2019 11:01:08 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 10:00:50 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.52 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 09:33:16 ENGR-Vast_A EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/22/2019 09:33:14 ENGR-Vast_A EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/22/2019 09:00:31 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 08:52:24 ENGR-Vast_B EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/22/2019 08:52:24 ENGR-Vast_B EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/22/2019 08:00:36 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.51 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 07:00:31 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.52 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 06:01:13 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 05:31:53 ENGR-Vast_A EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/22/2019 05:31:50 ENGR-Vast_A EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/22/2019 05:00:42 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 04:46:10 ENGR-Vast_B EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/22/2019 04:46:09 ENGR-Vast_B EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/22/2019 04:00:55 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 03:01:17 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.51 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 02:01:31 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.51 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 01:29:22 ENGR-Vast_A EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/22/2019 01:29:20 ENGR-Vast_A EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;7/22/2019 01:02:05 ENGR-Vast_B ERROR secd.ldap.query.timed.out: Vserver 'ENGR-Linuxstore': LDAP server 10.140.96.31 did not respond to query within timeout (5 seconds) interval.&lt;BR /&gt;7/22/2019 00:38:26 ENGR-Vast_B EMERGENCY secd.lsa.noServers: None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network.&lt;BR /&gt;7/22/2019 00:38:26 ENGR-Vast_B EMERGENCY secd.ldap.noServers: None of the LDAP servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network for LDAP service type (Service: LDAP (Active Directory), Operation: SiteDiscovery).&lt;BR /&gt;93 entries were displayed.&lt;/P&gt;</description>
      <pubDate>Tue, 23 Jul 2019 23:45:01 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/149800#M33328</guid>
      <dc:creator>Sycraft</dc:creator>
      <dc:date>2019-07-23T23:45:01Z</dc:date>
    </item>
    <item>
      <title>Re: Been having a strange LDAP issue lately</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/149801#M33329</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Could be a network issue. "&lt;EM&gt;&lt;STRONG&gt;None of the LSA servers configured for Vserver (ENGR-Linuxstore) are currently accessible via the network&lt;/STRONG&gt;&lt;/EM&gt;". Is there a default route for the NFS vserver? Can the vserver's management LIF route to the DC's?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;PRE&gt;&amp;gt;vserver route show -vserver ENGR-Linuxstore

&amp;gt;vserver services name-service ldap show -vserver ENGR-Linuxstore&lt;/PRE&gt;
&lt;P&gt;/Matt&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 24 Jul 2019 00:51:59 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/149801#M33329</guid>
      <dc:creator>mbeattie</dc:creator>
      <dc:date>2019-07-24T00:51:59Z</dc:date>
    </item>
    <item>
      <title>Re: Been having a strange LDAP issue lately</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/149920#M33354</link>
      <description>&lt;P&gt;So the solution was found when troubleshooting an unrelated problem:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Somehow the computer account in Active Directory had lost its assocation with the server (or the other way around). We deleted the Active Directory configuration on the SVM, reset the computer account in AD, and then added the Active Directory configuration back. The errors stopped after that.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;It would seem the username/password the SVM had in the AD was enough for lookup for accounts, but the proper computer account assocation was required for the other functions that were failing.&lt;/P&gt;</description>
      <pubDate>Fri, 23 Aug 2019 19:19:22 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/149920#M33354</guid>
      <dc:creator>Sycraft</dc:creator>
      <dc:date>2019-08-23T19:19:22Z</dc:date>
    </item>
    <item>
      <title>Re: Been having a strange LDAP issue lately</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/155127#M34890</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;after upgrading our AD servers the following errors started to appear frequently&amp;nbsp;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;"None of the LSA servers configured for Vserver (svmname) are currently accessible via the network."&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I've applied this workaround ad fixed the&amp;nbsp;secd.lsa.noServers problem.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&lt;BR /&gt;&lt;EM&gt;vserver cifs security modify -vserver svmname -smb1-enabled-for-dc-connections false -smb2-enabled-for-dc-connections true&lt;BR /&gt;&lt;BR /&gt;&lt;/EM&gt;source:&amp;nbsp;&lt;A href="https://community.netapp.com/t5/General-Discussion/Message-secd-lsa-noServers-None-of-the-LSA-servers-configured/td-p/154999" target="_blank"&gt;https://community.netapp.com/t5/General-Discussion/Message-secd-lsa-noServers-None-of-the-LSA-servers-configured/td-p/154999&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 26 Mar 2020 16:24:13 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/155127#M34890</guid>
      <dc:creator>LORENZO_CONTI</dc:creator>
      <dc:date>2020-03-26T16:24:13Z</dc:date>
    </item>
    <item>
      <title>Re: Been having a strange LDAP issue lately</title>
      <link>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/158952#M36277</link>
      <description>&lt;P&gt;Thank you so much!!&lt;/P&gt;</description>
      <pubDate>Tue, 25 Aug 2020 11:45:08 GMT</pubDate>
      <guid>https://community.netapp.com/t5/ONTAP-Discussions/Been-having-a-strange-LDAP-issue-lately/m-p/158952#M36277</guid>
      <dc:creator>TOPHAN</dc:creator>
      <dc:date>2020-08-25T11:45:08Z</dc:date>
    </item>
  </channel>
</rss>

