到達不能なLDAPサーバによるsecd.kerberos.preauthエラー
環境
- ONTAP 9
- LDAPクライアント
問題
- EMSノケイコクイヘント
secd.kerberos.preauth: A Kerberos pre-authentication failure occurred for SVM "svm1" due to invalid credentials for SVM1$@DOMAIN.LOCAL.
secd.conn.auth.failure: Vserver (svm1) could not authenticate over the network to server (ldap01). Error: Can't contact LDAP server (Service: LDAP (NIS & Name Mapping), Operation: Check LDAP Config).
- SecDログ
info : TCP connection to ip 10.20.30.122, port 636 failed: Connection refused. { in _connect() at src/connection_manager/secd_connection_shim.cpp:594 }
- パケットトレース
10.20.30.123 → 10.20.30.122 TCP 74 60655 → 636 [SYN] Seq=0 Win=65535 Len=0 MSS=1460 WS=256 SACK_PERM TSval=1868178423 TSecr=0
10.20.30.122 → 10.20.30.123 TCP 54 636 → 60655 [RST, ACK] Seq=1 Ack=1 Win=0 Len=0