NSX Federation standby site Identity Firewall AD synchronization status failure
search cancel

NSX Federation standby site Identity Firewall AD synchronization status failure

book

Article ID: 375020

calendar_today

Updated On:

Products

VMware NSX

Issue/Introduction

In VMware NSX-T, a federation setup has a Global Manager and at least one Local Manager. 

The sync status from the GM and LM both show successful and green.

However, from the Identity Firewall AD settings in the standby LM, the synchronization status for the LDAP server is showing failure.

The active LM does not have this failure status.

The error message indicates "Cannot connect to any LDAP server in domain <domain-name>" and a timestamp can be found from the browser's developer console, which is a while ago (not up-to-date). 

There are no other averse effects of this issue. The LDAP users can still log in to NSX. 

This is a cosmetic issue. 

Environment

VMware NSX-T 3.x

Cause

This is caused by the standby LM site that has an outdated AD synchronization status

Resolution

Send a POST API call to https://<Standby-site-LM>/policy/api/v1/infra/full-sync-action?action=request_full_sync