<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hello All, in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/unable-to-contact-ldap-server/m-p/2628637#M196534</link>
    <description>&lt;P style="text-autospace: none;"&gt;&lt;SPAN style="font-size: 16.0pt; font-family: Arial; color: #262626;"&gt;Hello All,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&lt;SPAN style="font-size: 16.0pt; font-family: Arial; color: #262626;"&gt;I have a 2012R2 DC in native mode and an ASA 5515 running 9.2(2)4 and I am having this exact problem. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&lt;SPAN style="font-size: 16.0pt; font-family: Arial; color: #262626;"&gt;I cannot figure it out and TAC cannot figure it out. &amp;nbsp;TAC seems to think it is the DC rejecting the LDAP request by resetting something in the transaction between the DC and ASA. &amp;nbsp;I am doing some digging to determine if I have missed something in the configuration of my 2012R2 server.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&lt;SPAN style="font-size: 16.0pt; font-family: Arial; color: #262626;"&gt;I have used Microsoft's LDP.exe from both of my DCs and can connect, BIND and query the Active Directory with the same credentials as I have configured on the ASA. &amp;nbsp;So, my credentials are good and my DC is responding properly or so it seems.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&lt;SPAN style="font-size: 16.0pt; font-family: Arial; color: #262626;"&gt;In the Cisco guide referenced here (http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/98625-asa-ldap-authentication.html) why are anonymous LDAP query&amp;nbsp;privileges required? &amp;nbsp;In the configuration of the AAA, we submit&amp;nbsp;a username and a password to the DC to be able to query. &amp;nbsp;I have not specifically configured this and and wondering if I need to do so. &amp;nbsp;I have configured dozens of these solutions in the past but mainly with 2008R2 DCs and not 2012R2. &amp;nbsp;I have never specifically configured anonymous access&amp;nbsp;because of the security implications.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&lt;SPAN style="font-size: 16.0pt; font-family: Arial; color: #262626;"&gt;Does anyone have any thoughts on the matter?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&lt;SPAN style="font-size: 16.0pt; font-family: Arial; color: #262626;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 16.0pt; font-family: Arial; color: #262626;"&gt;-Don&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Feb 2016 05:02:14 GMT</pubDate>
    <dc:creator>dneumann</dc:creator>
    <dc:date>2016-02-04T05:02:14Z</dc:date>
    <item>
      <title>Unable to contact LDAP server</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-contact-ldap-server/m-p/2628633#M196530</link>
      <description>&lt;P&gt;Once again still struggling with our new ASA. My new problem is authenticating to our MS Domain Controller. It's a 2012r2 controller and for some reason I cannot connect to it.&lt;/P&gt;&lt;P&gt;I can ping it from the ASA no problem, but when I try to test the AAA authentication I get the following message.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;[-2147483641] Session Start&lt;BR /&gt;[-2147483641] New request Session, context 0x00007fff33818ef8, reqType = Authentication&lt;BR /&gt;[-2147483641] Fiber started&lt;BR /&gt;[-2147483641] Creating LDAP context with uri=ldap://10.2.0.101:389&lt;BR /&gt;[-2147483641] Connect to LDAP server: ldap://10.2.0.101:389, status = Failed&lt;BR /&gt;[-2147483641] Unable to read rootDSE. Can't contact LDAP server.&lt;BR /&gt;[-2147483641] Fiber exit Tx=0 bytes Rx=0 bytes, status=-2&lt;BR /&gt;[-2147483641] Session End&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Any and all help would be appreciated.&lt;/P&gt;&lt;P&gt;Stacey&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2019 05:35:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-contact-ldap-server/m-p/2628633#M196530</guid>
      <dc:creator>Stacey Hummer</dc:creator>
      <dc:date>2019-03-12T05:35:30Z</dc:date>
    </item>
    <item>
      <title>Hi Stacey, Here is the config</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-contact-ldap-server/m-p/2628634#M196531</link>
      <description>&lt;P&gt;Hi Stacey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Here is the config example for configuring LDAP authentication on Cisco ASA:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/98625-asa-ldap-authentication.html&lt;/P&gt;&lt;P&gt;Please verify the configs, and also share the Cisco ASA version you are working with.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Capturing below debugs on ASA can be helpful in identifying the cause of the issue:&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;debug aaa commom.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tushar Bangia&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note: Please do rate the post if you find it helpful!!&lt;/P&gt;&lt;P&gt;-------------------------------------------------------------&lt;/P&gt;</description>
      <pubDate>Thu, 05 Mar 2015 05:23:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-contact-ldap-server/m-p/2628634#M196531</guid>
      <dc:creator>Tushar Bangia</dc:creator>
      <dc:date>2015-03-05T05:23:30Z</dc:date>
    </item>
    <item>
      <title>Sorry all for not getting</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-contact-ldap-server/m-p/2628635#M196532</link>
      <description>&lt;P&gt;Sorry all for not getting back, but it seems the issue was with routing internally. The ASA was sending out requests but it ended up in a loop.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Mar 2015 14:20:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-contact-ldap-server/m-p/2628635#M196532</guid>
      <dc:creator>Stacey Hummer</dc:creator>
      <dc:date>2015-03-09T14:20:27Z</dc:date>
    </item>
    <item>
      <title>Hi Stacey, Glad to hear that</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-contact-ldap-server/m-p/2628636#M196533</link>
      <description>&lt;P&gt;Hi Stacey,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Glad to hear that issue has been fixed. Feel free to post your queries on this forum and we would be glad to help you.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Regards,&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Tushar Bangia&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Note : Please do rate post if you find it helpful!!&lt;/P&gt;</description>
      <pubDate>Tue, 10 Mar 2015 03:19:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-contact-ldap-server/m-p/2628636#M196533</guid>
      <dc:creator>Tushar Bangia</dc:creator>
      <dc:date>2015-03-10T03:19:57Z</dc:date>
    </item>
    <item>
      <title>Hello All,</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-contact-ldap-server/m-p/2628637#M196534</link>
      <description>&lt;P style="text-autospace: none;"&gt;&lt;SPAN style="font-size: 16.0pt; font-family: Arial; color: #262626;"&gt;Hello All,&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&lt;SPAN style="font-size: 16.0pt; font-family: Arial; color: #262626;"&gt;I have a 2012R2 DC in native mode and an ASA 5515 running 9.2(2)4 and I am having this exact problem. &amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&lt;SPAN style="font-size: 16.0pt; font-family: Arial; color: #262626;"&gt;I cannot figure it out and TAC cannot figure it out. &amp;nbsp;TAC seems to think it is the DC rejecting the LDAP request by resetting something in the transaction between the DC and ASA. &amp;nbsp;I am doing some digging to determine if I have missed something in the configuration of my 2012R2 server.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&lt;SPAN style="font-size: 16.0pt; font-family: Arial; color: #262626;"&gt;I have used Microsoft's LDP.exe from both of my DCs and can connect, BIND and query the Active Directory with the same credentials as I have configured on the ASA. &amp;nbsp;So, my credentials are good and my DC is responding properly or so it seems.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&lt;SPAN style="font-size: 16.0pt; font-family: Arial; color: #262626;"&gt;In the Cisco guide referenced here (http://www.cisco.com/c/en/us/support/docs/security/asa-5500-x-series-next-generation-firewalls/98625-asa-ldap-authentication.html) why are anonymous LDAP query&amp;nbsp;privileges required? &amp;nbsp;In the configuration of the AAA, we submit&amp;nbsp;a username and a password to the DC to be able to query. &amp;nbsp;I have not specifically configured this and and wondering if I need to do so. &amp;nbsp;I have configured dozens of these solutions in the past but mainly with 2008R2 DCs and not 2012R2. &amp;nbsp;I have never specifically configured anonymous access&amp;nbsp;because of the security implications.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&lt;SPAN style="font-size: 16.0pt; font-family: Arial; color: #262626;"&gt;Does anyone have any thoughts on the matter?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&lt;SPAN style="font-size: 16.0pt; font-family: Arial; color: #262626;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style="font-size: 16.0pt; font-family: Arial; color: #262626;"&gt;-Don&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Feb 2016 05:02:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-contact-ldap-server/m-p/2628637#M196534</guid>
      <dc:creator>dneumann</dc:creator>
      <dc:date>2016-02-04T05:02:14Z</dc:date>
    </item>
    <item>
      <title>Hello,</title>
      <link>https://community.cisco.com/t5/network-security/unable-to-contact-ldap-server/m-p/2628638#M196535</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;anyone figured out what is the problem? I today faced the same issue.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the ASA do i need to issue certificate for it?&amp;nbsp;&lt;/P&gt;
&lt;P&gt;On the Windows Server i receive following in the Event Viewer:&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Segoe UI',sans-serif;"&gt;A fatal alert was generated and sent to the remote endpoint. This may result in termination of the connection. The TLS protocol defined fatal error code is 40. The Windows SChannel error state is 1205.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Segoe UI',sans-serif;"&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style="text-autospace: none;"&gt;&lt;SPAN style="font-size: 9.0pt; font-family: 'Segoe UI',sans-serif;"&gt;Thank you&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Fri, 27 Jan 2017 11:28:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/unable-to-contact-ldap-server/m-p/2628638#M196535</guid>
      <dc:creator>Alexander Vasilev</dc:creator>
      <dc:date>2017-01-27T11:28:25Z</dc:date>
    </item>
  </channel>
</rss>

