IBM Support

QRadar: Test Connection to a LDAP Server on a Windows Domain Controller fails

Troubleshooting


Problem

You are trying to configure the Authentication module for LDAP using a Windows Domain Controller as the Authentication Server.

Symptom

Test Connection fails in the user interface.

Diagnosing The Problem

In the QRadar logs /var/log/qradar.error, you should see a PartialResultException error message similar to:
com.q1labs.uiframeworks.shared.ldap.LdapClientException: An unexpected error occurred see exception for details - javax.naming.PartialResultException [Root exception is javax.naming.CommunicationException: xxxx.domain.org:636 [Root exception is java.net.SocketTimeoutException: connect timed out]

Resolving The Problem

  1. Log in to the QRadar Console as admin.
  2. On the navigation menu ( Navigation menu icon ), click Admin.
  3. Go to Authentication> Authentication Module Settings.
  4. In the Server URL field, instead of ports 389 or 636, use the port for the Global catalog.
    • 3268 for non-SSL connection
    • 3269 for SSL connection
  5. Click Save.
  6. On the Admin tab, click Deploy Change.

    Results
    After the deploy completes administrators can verify the change using the Text Connection feature in the user interface.  If you continue to experience issues with the error message described in this technical note, open a case with QRadar Support.

Document Location

Worldwide

[{"Line of Business":{"code":"LOB24","label":"Security Software"},"Business Unit":{"code":"BU059","label":"IBM Software w\/o TPS"},"Product":{"code":"SSBQAC","label":"IBM Security QRadar SIEM"},"ARM Category":[{"code":"a8m0z000000cwsyAAA","label":"Admin Tasks"}],"ARM Case Number":"TS004928948","Platform":[{"code":"PF025","label":"Platform Independent"}],"Version":"7.4.0;7.4.1;7.4.2"}]

Document Information

Modified date:
30 April 2021

UID

ibm16415713