Multiple LDAP servers in a single profile - behavior

Reply
Rboehme
L2 Linker

Multiple LDAP servers in a single profile - behavior

Dear comm,

 

when I have several LDAP servers in a profile for user authentication. How is this list utilized? Is only the first entry used? Are authentication requests distributed over all configured servers? How does it work?

 

Kind regards,

 

Rene

 

 

Tags (2)
TranceforLife
L6 Presenter

Hi,

 

l think this option is purely for redundancy. My guess is that AD servers are sharing the same user database:

 

https://live.paloaltonetworks.com/t5/Management-Articles/Using-More-than-Four-LDAP-Servers-in-a-Palo...

Rboehme
L2 Linker

Dear Trancefor,

 

thank you for your answer. I am confused by this:

 

Usually four LDAP servers are more than enough to authenticate all the users in the domain, and to provide redundancy in case a LDAP server goes down.

 

This sounds like:"Hey, I will use one LDAP forever, if it goes down, I just will pick the next in the list".

 

Sometimes, larger companies have more than four LDAP servers with distributed environments in which users connect to dedicated LDAP servers. Users may contact LDAP servers that are not one of the four servers, and will try to authenticate to them.

 

So this sounds to me like (if the first statement above is true):"Hey I will use the first LDAP server of the first entry of the authentication sequence. If this authentication fails, I will contact the first LDAP server of the second entry of the authentication profile."

 

Bascially if you have two groups of LDAP servers:

 

Group1: 1,2,3,4

Group2:5,6,7,8

Authentication Sequence: Group1,Group2

 

Assuming no LDAP server goes down ever: LDAP1 will be contacted and LDAP5 might be contacted, the rest of the server will never be contacted. Am I right here?

 

Kind regards,


Rene

BPry
Cyber Elite

@Rboehme,

The servers in Group1 will be polled and contact will stop once a user is matched authenticated. If the entire Group1 does not find a match it will continue to Group2. If The first polling server in Group1 never goes down then I believe your assumption is correct that the others will never be consulted. 

Like what you see?

Show your appreciation!

Click Like if a post is helpful to you or if you just want to show your support.

Click Accept as Solution to acknowledge that the answer to your question has been provided.

The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!

These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!

The LIVEcommunity thanks you for your participation!