Determining the Domain Controller a ProxySG is currently connecting to in an IWA-Direct deployment

book

Article ID: 167432

calendar_today

Updated On:

Products

ProxySG Software - SGOS

Issue/Introduction

When using IWA Direct authentication, the proxy will establish a connection into the required Windows domain. Where a domain has multiple domain controllers, it can be useful to know to which domain controller the proxy is currently connected, as this can identify slowness or communication issues.

Resolution

Use the following proxy URL:

https://proxy:8082/lsa/stats

The subsequent output will show the currently-connected domain controller. It will also identify all the domain controllers within the domain.

Domain: COMPANY.ORG

Status Online
Current Schannel DC DC4.company.org
Last Schannel DC DC2.company.org
Number of Schannel transactions 27763
Avg Schannel transaction time (ms) 16
Max Schannel transaction time (ms) 3526
Number of Schannel lock timeouts 0
Number of Schannel waiters 0
Max Schannel watiers 19

Domain Controllers

Name Address Site name Flags Avg SC resp time (ms) Max SC resp time (ms) Avg LDAP ping time (ms) Max LDAP ping time (ms) Num of LDAP pings Num of Sch timeouts Avg SC wait time (ms) Max SC wait time (ms) Num SC rsts Num SC sucess Num SC fail
DC2.company.org 192.168.107.120 SITE1 (0x17C) GLOBAL_CATALOG KDC WRITEABLE 12 3526 2 47 10731 0 7 2536 2 13707 50
DC3.company.org 192.168.107.121 SITE1 (0x17C) GLOBAL_CATALOG KDC WRITEABLE 10 198 2 50 9063 0 2 202 1 12751 0
DC5.company.org 172.16.130.18 SITE2 (0x1FC) GLOBAL_CATALOG KDC WRITEABLE 0 0 1 1 1 0 0 0 0 0 0
DC1.company.org 172.16.130.20 SITE2 (0x1FC) GLOBAL_CATALOG KDC WRITEABLE 0 0 2 2 1 0 0 0 0 0 0
DC4.company.org 172.16.130.21 SITE2 (0x1FC) GLOBAL_CATALOG KDC WRITEABLE 12 184 1 89 5567 0 6 116 5 1252 3