Security

Splunk LDAP to AD Auth Fails if AD server is IPv6-based

kindlund
New Member

Problem: Enabling Splunk LDAP authentication to an Active Directory server fails, if IPv6 is enabled on the server and tries to connect to the Active Directory server over an IPv6 address.

During this time, logging in using AD credentials either take 30 mins (very long time) or fails completely.

The workaround is to make sure you specify the IPv4 address of the Active Directory explicitly within Splunk. If you specify the DNS entry of the Active Directory, make sure when Splunk does an nslookup on the IP, that it doesn't use an IPv6 address.

FYI.

0 Karma

ithangasamy_spl
Splunk Employee
Splunk Employee

IPv6 support is available only from Splunk 4.3 release onwards, you should not see this problem in 4.3, if you do, to debug try disabling the referrals it could be the referrals issue

0 Karma
Get Updates on the Splunk Community!

Extending Observability Content to Splunk Cloud

Watch Now!   In this Extending Observability Content to Splunk Cloud Tech Talk, you'll see how to leverage ...

More Control Over Your Monitoring Costs with Archived Metrics!

What if there was a way you could keep all the metrics data you need while saving on storage costs?This is now ...

New in Observability Cloud - Explicit Bucket Histograms

Splunk introduces native support for histograms as a metric data type within Observability Cloud with Explicit ...