Got it

user can't be online at AD server

Latest reply: May 11, 2018 20:58:40 1261 1 1 0 0
      Issue Description

Customer have two AD server and master and slave. After they installed ADSSO on server and configured user-based security-policy on USG, some users’ online information can synchronize to firewall, but some users can’t online on AD server.

transparent.gif Alarm Information

[2017-12-24 15-32-11][DBG]UserOnLine, UserName: xxxx', Domain: 'automation', Computer: 'xxxx'

[2017-12-24 15-32-11][DBG]szADsPath = LDAP://10.10.x.x/CN=xxxx,OU=Finance,OU=USERS &Groups,DC=x,DC=com

[2017-12-24 15-32-11][DBG]user 'x' Logon from 10.10.y.y

[2017-12-24 15-32-11][DBG]record time 1514097879, message time 1514100731<?xml:namespace prefix = "o" />

[2017-12-24 15-32-11][DBG]Fake logon detected,because logon time too far!

[2017-12-24 16-18-27][INF]UserOffLine enter.

transparent.gif Handling Process

1.    Checked the ADSSO configuration, the ComminucationTimeWindow are 5 seconds, it is too short. When the time is over 5 seconds, the users cant be online and show fake logonon both AD server. The default CommunicationTimeWindow is 1800 seconds, so we changed it to 1800 and restart ADSSO progress.

     (When one user have fake logon alarm at two AD server, thats abnormal, user cant be online. When the user are online at one AD server, another AD server will check the status too, and the second AD server show fake logon alarm, that is nornaml.)

      920bafc4f89743ac8886cf27206dc92b

2.    If the system is above window8.1 and windows server 2012, the user online status will be 5 minutes delay. So we configured group policy to disable the delay time.



transparent.gif Root Cause

The CommunicationTimeWindow configured too short.

transparent.gif Solution

Change CommunicationTimeWindow to 1800 seconds.

    ad979d859ab8422383f2c8e882563f3e

:)
View more
  • x
  • convention:

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.