Problem: Enabling Splunk LDAP authentication to an Active Directory server fails, if IPv6 is enabled on the server and tries to connect to the Active Directory server over an IPv6 address.
During this time, logging in using AD credentials either take 30 mins (very long time) or fails completely.
The workaround is to make sure you specify the IPv4 address of the Active Directory explicitly within Splunk. If you specify the DNS entry of the Active Directory, make sure when Splunk does an nslookup on the IP, that it doesn't use an IPv6 address.
FYI.
IPv6 support is available only from Splunk 4.3 release onwards, you should not see this problem in 4.3, if you do, to debug try disabling the referrals it could be the referrals issue