Error 18870 means that first factor (AD password) is failing.
Does the VIP Enterprise Gateway support the DNS round-robin? The VIP EG doesn’t support round-robin. It will try to auto-connect with the available failover user store
What best practice can avoid a service impact if LDAP / AD service is down on one or more servers? Configure multiple user stores as failover to avoid the service impact.
What error is seen in the VIP EG log if the first factor (AD password) is timing out?
When LDAP Timeout happens, the log contains 0x4B03. i.e. 19428
When LDAP First factor fails, the log contains 0x49B6. i.e. 18870