DNS Mapping Error for Active Directory application upon test connection

Which IIQ version are you inquiring about?

IIQ 8.4

Please share any images or screenshots, if relevant.

image

Share all details about your problem, including any error messages you may have received.

Hi all,

I am trying to setup an active directory application. When trying the test connection button, I am getting this DNS error. Currently, I have checked the below items are cleared:

  1. Domain is resolved as a nslookup of the server endpoint works
  2. Added ip address to coredns file
  3. Added necessary nsg and udr

On top of that also tested using LDAP application if we could reach the endpoint:

  1. Using the IP we are able to test connection successfully
  2. Using the fqdn, we are getting
    image

I am currently unsure what other setup is missing?

Hi @shijingg,

The tests you did are correct, but I have one dubt.

You are tring to connect using 636 port but with ldap protocol. This port is for ldaps protocol.
Can you try 389 with ldap or 636 with ldaps?

Also, you can have a protocol with DNS server that dont resolve the name correctly. Try to change it.

Do you have firewall between SP and AD? and its configured correctly?

Hi @enistri_devo, yes there is firewall between SP and AD. I believe the configuration is correct as I am able to test connection using LDAP to the IP address successfully. Am I correct to say that the firewall is cleared?

Could I understand more what do you mean by this? Also, you can have a protocol with DNS server that dont resolve the name correctly. Try to change it.

Sorry, I wrote wrong. The Correct version is:

Also, you can have a problem with DNS server that dont resolve the name correctly. Try to change it.

I think yes, so I think the problem is un DNS that couldnt resolve correctly the name.

@enistri_devo I am able to nslookup in the IQService on windows and able to resolve. So I think the DNS is being resolved?

could I also check for each service account I am user in my forest configuration they have to be added to the IQService? Because I have 2 separate Active Directory applications, but only one IQService.

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.