Security

Splunk LDAP to AD Auth Fails if AD server is IPv6-based

kindlund
New Member

Problem: Enabling Splunk LDAP authentication to an Active Directory server fails, if IPv6 is enabled on the server and tries to connect to the Active Directory server over an IPv6 address.

During this time, logging in using AD credentials either take 30 mins (very long time) or fails completely.

The workaround is to make sure you specify the IPv4 address of the Active Directory explicitly within Splunk. If you specify the DNS entry of the Active Directory, make sure when Splunk does an nslookup on the IP, that it doesn't use an IPv6 address.

FYI.

0 Karma

ithangasamy_spl
Splunk Employee
Splunk Employee

IPv6 support is available only from Splunk 4.3 release onwards, you should not see this problem in 4.3, if you do, to debug try disabling the referrals it could be the referrals issue

0 Karma
Get Updates on the Splunk Community!

Wondering How to Build Resiliency in the Cloud?

IT leaders are choosing Splunk Cloud as an ideal cloud transformation platform to drive business resilience,  ...

Updated Data Management and AWS GDI Inventory in Splunk Observability

We’re making some changes to Data Management and Infrastructure Inventory for AWS. The Data Management page, ...

Introducing the Splunk Community Dashboard Challenge!

Welcome to Splunk Community Dashboard Challenge! This is your chance to showcase your skills in creating ...