This article explains the Threshold Configuration settings found under Domain Controllers > Network in the ENow Admin Console, which cover the network aspects of domain controllers.
Where these thresholds are set: the values that apply to your environment are configured in the ENow Admin Console, under Server > Tuning Policy > Agent Options. Each check is evaluated against the threshold set there, so confirm the current values in your own console rather than assuming the defaults quoted below still apply.
GC Bind Time:
"GC" stands for Global Catalog, a distributed data repository that contains a searchable, partial representation of every object in every domain in a multi-domain Active Directory Domain Services (AD DS) forest. This check measures how long it takes to bind to the Global Catalog, and raises a warning and then a critical alert once that time passes the thresholds configured for the check — by default 5000 milliseconds for the warning and 10000 milliseconds for the critical. A long bind time can indicate network or GC performance issues.
LDAP Bind Time:
This is similar to GC Bind Time, but it specifically refers to the general LDAP service. LDAP (Lightweight Directory Access Protocol) is used for directory services like AD. A warning and then a critical alert are raised once the bind time passes the thresholds configured for the check — again 5000 and 10000 milliseconds by default. Slow LDAP binds could point to network latency or service performance problems.
See: Binding to an LDAP server — Microsoft Learn
GC Ports:
These settings allow you to configure monitoring for the Global Catalog server ports, both secure and non-secure. Clients use these ports to perform searches against the Global Catalog, which provides access to the partial attribute set of objects in the AD forest. An LDAP query sent to port 3268 (non-secure) or port 3269 (secure, over SSL/TLS) is directed to a Global Catalog server, which returns the search results. The options for monitoring the ports are:
- Do not monitor the GC non-secure port: deactivates monitoring of the non-secure GC port, 3268.
- Monitor the GC non-secure port: activates monitoring of the non-secure GC port, 3268, so connection failures and slow binds on that port are reported.
- Do not monitor the GC secure port: deactivates monitoring of the secure GC port, 3269.
- Monitor the GC secure port: activates monitoring of the secure GC port, 3269, to confirm that secure connections are being established as expected.
LDAP Ports:
Similar to GC Ports, but for the default LDAP ports — 389 for standard LDAP traffic and 636 for LDAPS:
- Do not monitor the LDAP non-secure port: deactivates monitoring of the non-secure LDAP port, 389.
- Monitor the LDAP non-secure port: activates monitoring of the non-secure LDAP port, 389, so connection failures and slow binds on that port are reported.
- Do not monitor the LDAP secure port: deactivates monitoring of the secure LDAP port, 636.
- Monitor the LDAP secure port: activates monitoring of the secure LDAP port, 636, to confirm that LDAPS connections are being established as expected.
Comments
0 comments
Please sign in to leave a comment.