Netlogonの応答が遅いことによるNT Error (0x103)でのCIFS認証の問題
環境
- ONTAP 9
- CIFS
- Active Directory
- NTLM
問題
- CIFSサーバがドメインユーザで認証を試み、ドメインコントローラ(DC)サーバからSTATUS_PENDING(NT Error 0x103)を受信します
- ONTAPは3秒のタイムアウト後にTCPセッションを閉じます
- DCサーバはタイムアウト後にNetlogonデータでVserverに応答します
EMS Log
:
[?] Mon Feb 07 14:57:34 +0100 [<node_name>: secd: secd.cifsAuth.problem:error]: vserver (<Vserver_Name>) General CIFS authentication problem. Error: Ontap admin cifs authentication basic procedure failed (Retries: 2) **[ 3263] Attempt 1 FAILURE: Unexpected state: Error 6776 at file:src/FrameWork/Socket.cpp func:ReceiveDataOnSocket line:1233 **[ 3263] Attempt 1 FAILURE: Pass-through authentication request failed.
Secd.log
:
Mon May 16 2022 15:30:49 +02:00 Successfully authenticated with DC dc1.domain.local { in connectToDomainController() at src/connection_manager/secd_connection.cpp:302 }
Mon May 16 2022 14:30:52 +02:00 Error!!! Call timeout after 3 seconds aborting with 1 commands pending { in ReceiveDataOnSocket() at src/FrameWork/Socket.cpp:1231 }
-
Netlogon.log
:05/16 15:30:49 [LOGON] Domain: SamLogon: Network logon of domain\usr01 from \\Computer01 (via CIFS1) Entered
05/16 15:30:56 [LOGON] Domain: SamLogon: Network logon of domain\usr01 from \\Computer01 (via CIFS1) Returns 0x0
<-- 7秒