Failed Topology Status for an Active Directory domain after previously showing Complete
search cancel

Failed Topology Status for an Active Directory domain after previously showing Complete

book

Article ID: 248080

calendar_today

Updated On:

Products

Endpoint Security Complete Endpoint Threat Defense for Active Directory

Issue/Introduction

An AD Gateway has been added and the Topology Status went to Complete. After an arbitrary amount of time the status changes to Failed. It may take a week before it fails, and re-running the topology does not resolve the issue.

Cause

AD Gateway process token, and associated Kerberos ticket, expire and are not automatically renewed.

Resolution

Our Engineering team is investigating this issue and will update this document when a solution becomes available. 

 

To work around this issue please do one of the following on the AD Gateway device:

  • Schedule a daily or weekly task (depending on ticket expiration) to run: smc -restart
  • Schedule reboots to occur prior to ticket expiration

Additional Information

CRE-11000