Monitoring Benefit
The LDAP test verifies that each DC or RODC can connect locally to LDAP and that LSASS is listening for LDAP connections.
How do we verify the results ENow recorded?
From EMS 8.0 onward these results are held in the ENow SQL database rather than in a file on the web server. Open the monitoring page for this server in the ENow console to review what ENow recorded.
On that page, locate Port389, Port636, and BindTime to see the values ENow recorded.
How do we verify the results received on the Compass client?
From the DC or RODC, open the following file from Explorer using Notepad:
\Program Files (x86)\ENow\Mailscape Agent\LogFiles\MailscapeAgent2007.log
Find the string "LDAP" in the log and note the LDAP bind results and any errors that may follow. If an error is detected where the port is unavailable, we recommend running PortQry from the EMS web server to the DC or RODC in question.
Run the following command to test connectivity over port 389 using the UDP protocol to a specific DC or RODC:
.\PortQry.exe -n ServerName -p udp -e 389
Based on how Compass functions, anything other than a result of LISTENING will be considered a failed test.
Below is sample output for a passing test. Server name, domain, and IP address will differ in your environment.
PS C:\PortQryV2> .\PortQry.exe -n DC01 -p udp -e 389 Querying target system called: DC01 Attempting to resolve name to IP address... Name resolved to 192.0.2.10 querying... UDP port 389 (unknown service): LISTENING or FILTERED Using ephemeral source port Sending LDAP query to UDP port 389... LDAP query response: currentdate: 08/27/2020 17:24:42 (unadjusted GMT) subschemaSubentry: CN=Aggregate,CN=Schema,CN=Configuration,DC=example,DC=com dsServiceName: CN=NTDS Settings,CN=DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=example,DC=com namingContexts: DC=example,DC=com defaultNamingContext: DC=example,DC=com schemaNamingContext: CN=Schema,CN=Configuration,DC=example,DC=com configurationNamingContext: CN=Configuration,DC=example,DC=com rootDomainNamingContext: DC=example,DC=com supportedControl: 1.2.840.113556.1.4.319 supportedLDAPVersion: 3 supportedLDAPPolicies: MaxPoolThreads highestCommittedUSN: 421997 supportedSASLMechanisms: GSSAPI dnsHostName: DC01.example.com ldapServiceName: example.com:dc01$@EXAMPLE.COM serverName: CN=DC01,CN=Servers,CN=Default-First-Site-Name,CN=Sites,CN=Configuration,DC=example,DC=com supportedCapabilities: 1.2.840.113556.1.4.800 isSynchronized: TRUE isGlobalCatalogReady: TRUE domainFunctionality: 7 forestFunctionality: 7 domainControllerFunctionality: 7 ======== End of LDAP query response ======== UDP port 389 is LISTENING PS C:\PortQryV2>
Note: the LDAP test over UDP might not work against some domain controllers. One reason for this is that IPv6 has been disabled on the domain controller; re-enabling IPv6 restores the UDP LDAP response. Follow Microsoft's current guidance for configuring IPv6 in Windows, or contact ENow Support for assistance.
Comments
0 comments
Article is closed for comments.