Re: Hardware Load Balence of Kerberos
- From: "Brian Desmond [MVP]" <brian@xxxxxxxxxxxxxxxx>
- Date: Sat, 15 Jul 2006 20:54:16 -0500
I've done it with LDAP (ADAM), just setup your virtual server in the CSM for
port 389 and set it up to do tcp connects on 389 and ICMP pings as
keepalives - if either of those fails the real-server will drop out of the
VIP in the CSM.
--
Thanks,
Brian Desmond
Windows Server MVP - Directory Services
www.briandesmond.com
"Geoff" <nigeltufnel123@xxxxxxxxx> wrote in message
news:O7UB8S3pGHA.516@xxxxxxxxxxxxxxxxxxxxxxx
Joe,
In MOST cases you are correct...BUT....in some cases you are not. In the
case of LDAP, take a poorly written app the requires a ip address entered
for the LDAP host...or in the Kerberos case, device that depends on a
krb5.conf file.....now I know that I could add additional kdc entries to
the krb5.conf file, but I don't care to manage that on a large number of
devices. So, do you have any information that would address this scenario,
or a constructive reply to my original question ?
Thanks !!
Geoff
Joe Richards [MVP] wrote:
You shouldn't have to for LDAP nor Kerberos, there is load balancing and
redirection built into the product.
--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net
---O'Reilly Active Directory Third Edition now available---
http://www.joeware.net/win/ad3e.htm
============================================================================
Do not read this worthless blog entry on
Defending Security Infrastructures
http://blog.joeware.net/2006/07/11/445/
I'm serious, you will learn absolutely nothing about
Defending Security Infrastructures.
============================================================================
Geoff wrote:
Hello everyone
Has any here used a Hardware Load Balancer device such as Cisco
Arrowpoint to load balance AD Kerberos? We currently do it for AD DNS
and AD LDAP, and I'm investigating doing it for Kerberos as well.
Thanks ,
Geoff
.
- References:
- Hardware Load Balence of Kerberos
- From: Geoff
- Re: Hardware Load Balence of Kerberos
- From: Joe Richards [MVP]
- Re: Hardware Load Balence of Kerberos
- From: Geoff
- Hardware Load Balence of Kerberos
- Prev by Date: Re: Need Help Understanding Kerberos SPN Problem
- Next by Date: windows cannot connect to the new domain because: the system detected a possible attempt to compromise security
- Previous by thread: Re: Hardware Load Balence of Kerberos
- Next by thread: Re: Hardware Load Balence of Kerberos
- Index(es):
Relevant Pages
|