<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Failed to join AD server for CIFS setup : Wrong Realm in request in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Failed-to-join-AD-server-for-CIFS-setup-Wrong-Realm-in-request/m-p/131863#M8794</link>
    <description>&lt;P&gt;Hi Georgevj:&lt;/P&gt;&lt;P&gt;&amp;nbsp; Thanks for your reply, PSB:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is the old AD server is still on the network?&lt;/P&gt;&lt;P&gt;Yes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a conflict between NetBIOS names of old and new domains?&lt;/P&gt;&lt;P&gt;No&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you try the admin user name as "&lt;A href="mailto:sg020857-a@broadcom.net" target="_blank"&gt;sg020857-a@broadcom.net&lt;/A&gt;" instead of &amp;nbsp;"&lt;A href="http://broadcom.net" target="_blank"&gt;broadcom.net&lt;/A&gt;\sg020857-a" ?&lt;/P&gt;&lt;P&gt;Just use sg020857-a will be OK.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Consider the same environment and settings on another filer is OK...&lt;/P&gt;</description>
    <pubDate>Wed, 14 Jun 2017 02:50:38 GMT</pubDate>
    <dc:creator>LesterLiu</dc:creator>
    <dc:date>2017-06-14T02:50:38Z</dc:date>
    <item>
      <title>Failed to join AD server for CIFS setup : Wrong Realm in request</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Failed-to-join-AD-server-for-CIFS-setup-Wrong-Realm-in-request/m-p/131716#M8790</link>
      <description>&lt;P&gt;We have two FS2040 filers: fs-bei-01 and fs-bei-02&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Their CIFS service is OK in current domain.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;We planned to change the DC server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I tried to terminate CIFS service and run cifs setup on fs-bei-01, however, we faced error when joining the AD.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It is strange that I tried to change DC server on fs-bei-02 too later with same configurations, and fs-bei-02 successfully changed to another AD server.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;The OS and time source and DNS settings are all the same for two filers. I don't know how to debug this issue, there always the same error print. The detailed log is attached below:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;fs-bei-01&amp;gt; cifs setup&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;This process will enable CIFS access to the filer from a Windows(R) system.&lt;BR /&gt;Use "?" for help at any prompt and Ctrl-C to exit without committing changes.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; This filer is currently a member of the Active Directory domain&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 'CORP.AD.BROADCOM.COM'.&lt;BR /&gt;Do you want to continue and change the current filer account information? [n]: y&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Your filer is currently visible to all systems using WINS. The WINS&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; name servers currently configured are: [ 10.149.192.22, 10.149.192.23&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ].&lt;/P&gt;&lt;P&gt;(1) Keep the current WINS configuration&lt;BR /&gt;(2) Change the current WINS name server address(es)&lt;BR /&gt;(3) Disable WINS&lt;/P&gt;&lt;P&gt;Selection (1-3)? [2]: 2&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; You can enter up to 4 IPv4 WINS server addresses.&lt;BR /&gt;IPv4 address(es) of your WINS name server(s) [135.36.132.211]:&lt;BR /&gt;Would you like to specify additional WINS name servers? [y]:&lt;BR /&gt;IPv4 address(es) of your WINS name server(s) [135.36.132.212]:&lt;BR /&gt;Would you like to specify additional WINS name servers? [y]:&lt;BR /&gt;IPv4 address(es) of your WINS name server(s) [135.36.132.53]:&lt;BR /&gt;Would you like to specify additional WINS name servers? [n]:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; This filer is currently configured as a multiprotocol filer.&lt;BR /&gt;Would you like to reconfigure this filer to be an NTFS-only filer? [n]:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; NIS is currently enabled but NIS group caching is disabled. This may&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; have a severe impact on CIFS authentication if the NIS servers are&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; slow to respond or unavailable. It is highly recommended that you&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; enable NIS group caching.&lt;BR /&gt;Would you like to enable NIS group caching? [y]:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; By default, the NIS group cache is updated once a day at midnight. If&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; you would like to update the cache more often or at a different time,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; specify a list of hours (1-24, representing the hours in a day) that&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; describe when the update should be performed.&lt;BR /&gt;Enter the hour(s) when NIS should update the group cache [24]:&lt;BR /&gt;Would you like to specify additional hours? [n]:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The default name for this CIFS server is 'FS-BEI-01'.&lt;BR /&gt;Would you like to change this name? [n]:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Data ONTAP CIFS services support four styles of user authentication.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Choose the one from the list below that best suits your situation.&lt;/P&gt;&lt;P&gt;(1) Active Directory domain authentication (Active Directory domains only)&lt;BR /&gt;(2) Windows NT 4 domain authentication (Windows NT or Active Directory domains)&lt;BR /&gt;(3) Windows Workgroup authentication using the filer's local user accounts&lt;BR /&gt;(4) /etc/passwd and/or NIS/LDAP authentication&lt;/P&gt;&lt;P&gt;Selection (1-4)? [1]: 1&lt;BR /&gt;What is the name of the Active Directory domain? [CORP.AD.BROADCOM.COM]: Broadcom.net&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; In Active Directory-based domains, it is essential that the filer's&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; time match the domain's internal time so that the Kerberos-based&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication system works correctly. If the time difference between&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; the filer and the domain controllers is more than 5 minutes,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; authentication will fail. Time services are currently not configured&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; on this filer.&lt;BR /&gt;Would you like to configure time services? [n]:&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; In order to create an Active Directory machine account for the filer,&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; you must supply the name and password of a Windows account with&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; sufficient privileges to add computers to the BROADCOM.NET domain.&lt;BR /&gt;Enter the name of the Windows user [Administrator@BROADCOM.NET]: broadcom.net\sg020857-a&lt;BR /&gt;Password for BROADCOM.NET\sg020857-a:&lt;BR /&gt;Could not authenticate with domain controller: Wrong Realm in request.&lt;BR /&gt;CIFS - unable to log into domain as BROADCOM.NET\sg020857-a.&lt;BR /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Please try again (Ctrl-C to exit).&lt;BR /&gt;Enter the name of the Windows user [BROADCOM.NET\sg020857-a]:&lt;BR /&gt;fs-bei-01&amp;gt;&lt;BR /&gt;fs-bei-01&amp;gt;&lt;BR /&gt;fs-bei-01&amp;gt; ping WCISVMGC02.Broadcom.net&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;BR /&gt;WCISVMGC02.Broadcom.net is alive&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I also tried Disable WINS option and tried to set time server with the domain name, the result is always the same, It seems that there is no request send to the AD server, it is illegle to login the destination in the current status...&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Could any one help?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thanks in advance!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;Lester.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 14:59:42 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Failed-to-join-AD-server-for-CIFS-setup-Wrong-Realm-in-request/m-p/131716#M8790</guid>
      <dc:creator>LesterLiu</dc:creator>
      <dc:date>2025-06-04T14:59:42Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to join AD server for CIFS setup : Wrong Realm in request</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Failed-to-join-AD-server-for-CIFS-setup-Wrong-Realm-in-request/m-p/131805#M8792</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Is the old AD server is still on the network? Is there a conflict between NetBIOS names of old and new domains?&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;Did you try the admin user name as "sg020857-a@broadcom.net" instead of &amp;nbsp;"broadcom.net\sg020857-a" ?&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 13 Jun 2017 05:15:52 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Failed-to-join-AD-server-for-CIFS-setup-Wrong-Realm-in-request/m-p/131805#M8792</guid>
      <dc:creator>georgevj</dc:creator>
      <dc:date>2017-06-13T05:15:52Z</dc:date>
    </item>
    <item>
      <title>Re: Failed to join AD server for CIFS setup : Wrong Realm in request</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Failed-to-join-AD-server-for-CIFS-setup-Wrong-Realm-in-request/m-p/131863#M8794</link>
      <description>&lt;P&gt;Hi Georgevj:&lt;/P&gt;&lt;P&gt;&amp;nbsp; Thanks for your reply, PSB:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is the old AD server is still on the network?&lt;/P&gt;&lt;P&gt;Yes&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Is there a conflict between NetBIOS names of old and new domains?&lt;/P&gt;&lt;P&gt;No&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Did you try the admin user name as "&lt;A href="mailto:sg020857-a@broadcom.net" target="_blank"&gt;sg020857-a@broadcom.net&lt;/A&gt;" instead of &amp;nbsp;"&lt;A href="http://broadcom.net" target="_blank"&gt;broadcom.net&lt;/A&gt;\sg020857-a" ?&lt;/P&gt;&lt;P&gt;Just use sg020857-a will be OK.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Consider the same environment and settings on another filer is OK...&lt;/P&gt;</description>
      <pubDate>Wed, 14 Jun 2017 02:50:38 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Failed-to-join-AD-server-for-CIFS-setup-Wrong-Realm-in-request/m-p/131863#M8794</guid>
      <dc:creator>LesterLiu</dc:creator>
      <dc:date>2017-06-14T02:50:38Z</dc:date>
    </item>
  </channel>
</rss>

