cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1479
Views
6
Helpful
6
Replies

CUCM behavior if LDAP server is down

mr_cisco_cisco
Level 1
Level 1

Suppose CUCM is integrated with LDAP and it's configured to re-sync every hour.  If the LDAP server is down for 24 hours what happens to the users in CUCM?  Will they be marked inactive?

1 Accepted Solution

Accepted Solutions

Hi,

Merely loss of connectivity with AD server will not mark them inactive. If the synchronization agreement configured under LDAP Integration on cucm is deleted then they will be marked active. As per the SRND "Once users are synchronized from LDAP into the Unified CM database, deletion of a synchronization configuration will cause users that were imported by that configuration to be marked inactive in the database. Garbage collection will subsequently remove those users."

http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/srnd/collab10/collab10/directry.html

However, if you have configured LDAP authentication as well then end user logins and services would be affected.

That's why you have the option to add upto three AD servers for Directory integration as well as authentication for high availability.

Manish

View solution in original post

6 Replies 6

Kevin Monteiro
Level 7
Level 7

Hello,

Here is the document with the explanation:

http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/srnd/collab10/collab10/directry.html#pgfId-1067953

It clearly explains everything in details with a example.

Rate the post accordingly.

Regards,

Kevin Monteiro

"If none of the directory servers responds, then the synchronization fails, but it will be attempted again according to the configured synchronization schedule."

So CUCM will keep trying indefinitely?

Seems that way.

One sync attempt per hour is not going to put much strain on the network.

If your LDAP server is down for more than an hour, you have bigger issues than just the CUCM sync ;)

Hi,

Merely loss of connectivity with AD server will not mark them inactive. If the synchronization agreement configured under LDAP Integration on cucm is deleted then they will be marked active. As per the SRND "Once users are synchronized from LDAP into the Unified CM database, deletion of a synchronization configuration will cause users that were imported by that configuration to be marked inactive in the database. Garbage collection will subsequently remove those users."

http://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/srnd/collab10/collab10/directry.html

However, if you have configured LDAP authentication as well then end user logins and services would be affected.

That's why you have the option to add upto three AD servers for Directory integration as well as authentication for high availability.

Manish

No, it will not continue indefinitely, did you read the link and how the garbage disposal mechanism works?????

HTH

java

if this helps, please rate

Re-read my question.