<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Error: LQ_DN_UNAVAILABLE in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796944#M1032888</link>
    <description>&lt;P&gt;There are a lot of messages in my Syslog in Firepower Management Center:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Dec 17 2015 10:02:15 firepower SF-IMS[9098]: [28745] ADI:adi.ldap_query_handler [ERROR] Remote LDAP Query failed with error: LQ_DN_UNAVAILABLE &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;And most of users can't be recoznized:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Dec 17 2015 10:02:15 firepower SF-IMS[9098]: [28745] ADI:adi.LdapRealm [INFO] no DN found for user '********_***'.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;What's the reason of these errors?&lt;/P&gt;</description>
    <pubDate>Tue, 12 Mar 2019 12:50:48 GMT</pubDate>
    <dc:creator>lyutov_dv</dc:creator>
    <dc:date>2019-03-12T12:50:48Z</dc:date>
    <item>
      <title>Error: LQ_DN_UNAVAILABLE</title>
      <link>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796944#M1032888</link>
      <description>&lt;P&gt;There are a lot of messages in my Syslog in Firepower Management Center:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Dec 17 2015 10:02:15 firepower SF-IMS[9098]: [28745] ADI:adi.ldap_query_handler [ERROR] Remote LDAP Query failed with error: LQ_DN_UNAVAILABLE &lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;And most of users can't be recoznized:&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Dec 17 2015 10:02:15 firepower SF-IMS[9098]: [28745] ADI:adi.LdapRealm [INFO] no DN found for user '********_***'.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;What's the reason of these errors?&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 12:50:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796944#M1032888</guid>
      <dc:creator>lyutov_dv</dc:creator>
      <dc:date>2019-03-12T12:50:48Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796945#M1032894</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;It seems you are on 6.0 version ? Did&amp;nbsp; you face the issue after upgrade. I guess you are running into a known issue . Can you try to check :&lt;/P&gt;
&lt;P&gt;tail -f /var/log/messages&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also : pmtool status |grep -i Down (on the defense center).&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Aastha Bhardwaj&lt;/P&gt;
&lt;P&gt;Rate if that helps!!!&lt;/P&gt;</description>
      <pubDate>Thu, 17 Dec 2015 21:50:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796945#M1032894</guid>
      <dc:creator>Aastha Bhardwaj</dc:creator>
      <dc:date>2015-12-17T21:50:28Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796946#M1032902</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;Yes, I use 6.0 version, but I've installed it recently and I've never used previous versions.&lt;/P&gt;
&lt;P&gt;The result of &lt;STRONG&gt;pmtool status |grep -i Down:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;RUAScheduledDownload - Period 3600 - Next run Fri Dec 18 01:02:30 2015&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;/STRONG&gt;Is it OK? What should i do to solve this problem?&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2015 00:48:21 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796946#M1032902</guid>
      <dc:creator>lyutov_dv</dc:creator>
      <dc:date>2015-12-18T00:48:21Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796947#M1032903</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Can you send : tail -f /var/log/messages , there are 2 internal bugs which has been filed for this . So need to check further.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Regards,&lt;/P&gt;
&lt;P&gt;Aastha Bhardwaj&lt;/P&gt;
&lt;P&gt;Rate if that helps!!!&lt;/P&gt;</description>
      <pubDate>Fri, 18 Dec 2015 18:29:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796947#M1032903</guid>
      <dc:creator>Aastha Bhardwaj</dc:creator>
      <dc:date>2015-12-18T18:29:36Z</dc:date>
    </item>
    <item>
      <title>The result of tail -f /var</title>
      <link>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796948#M1032905</link>
      <description>&lt;P&gt;The result of &lt;STRONG&gt;tail -f /var/log/messages&lt;/STRONG&gt; in attachment.&lt;/P&gt;
&lt;P&gt;The same errors i see in Syslog of FMC (Firepower Management Center)&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Sat, 19 Dec 2015 01:22:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796948#M1032905</guid>
      <dc:creator>lyutov_dv</dc:creator>
      <dc:date>2015-12-19T01:22:14Z</dc:date>
    </item>
    <item>
      <title>If you are seeing these</title>
      <link>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796949#M1032908</link>
      <description>&lt;P&gt;If you are seeing these messages it means that there was a log in event for a user that&amp;nbsp;can't&amp;nbsp;be found in the corresponding realm via an LDAP query.&lt;/P&gt;
&lt;P&gt;Once the device receives a log on event (either passive authentication from a User Agent of ISE, or active authentication from captive portal) if the user does not exist from the last user download the system will attempt to pull information for the user from AD. It uses the settings in the realm object(s). When it can't find the user from an LDAP query it will print this message.&lt;/P&gt;
&lt;P&gt;This message can be logged very excessively because the system will check every minute for all users that have a log in that it doesn't have information for.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;The most typical cause of this issue is a misconfiguration in the realm Base DN. If the user isn't found in the Base DN in the realm then the base DN likely needs to be adjusted. If the LDAP/AD server can't be reached in general you may also see these messages.&lt;/P&gt;
&lt;P&gt;I have file a bug for the excessive logging of these error messages as they flood the logs:&lt;/P&gt;
&lt;P&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCvb06707&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;This bug is ONLY for the excessive logging of the error message, and the error message itself is not a bug, it is just a way to tell that there is an issue finding a user, and it's likely related to the realm config.&lt;/P&gt;</description>
      <pubDate>Fri, 02 Sep 2016 14:57:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796949#M1032908</guid>
      <dc:creator>John Groetzinger</dc:creator>
      <dc:date>2016-09-02T14:57:01Z</dc:date>
    </item>
    <item>
      <title>In my case, I can tell by the</title>
      <link>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796950#M1032910</link>
      <description>&lt;P&gt;In my case, I can tell by the names that it's looking for users that are no longer with the company and are not to be found on the DC anymore. &amp;nbsp;How can I tell it to forget about them?&lt;/P&gt;</description>
      <pubDate>Wed, 03 May 2017 20:56:39 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796950#M1032910</guid>
      <dc:creator>avanvooren1</dc:creator>
      <dc:date>2017-05-03T20:56:39Z</dc:date>
    </item>
    <item>
      <title>Were you able to get an</title>
      <link>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796951#M1032915</link>
      <description>&lt;P&gt;Were you able to get an answer to this question? &amp;nbsp;We have several thousand users that no longer exist and this causes several of these messages to appear in the syslog. &amp;nbsp;What is the danger in purging the user table? &amp;nbsp;Do we need to add a step to our termination process where we delete the user out of the FireSight database?&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2017 14:57:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796951#M1032915</guid>
      <dc:creator>darin.gottman1</dc:creator>
      <dc:date>2017-05-19T14:57:26Z</dc:date>
    </item>
    <item>
      <title>No, I have not resolved it .</title>
      <link>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796952#M1032918</link>
      <description>&lt;P&gt;No, I have not resolved it . The issue is one of those issues that annoy more than actually cause problems. &amp;nbsp;Please do post anything you try and let me know if it works.&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2017 20:29:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/error-lq-dn-unavailable/m-p/2796952#M1032918</guid>
      <dc:creator>avanvooren1</dc:creator>
      <dc:date>2017-05-19T20:29:01Z</dc:date>
    </item>
  </channel>
</rss>

