AD sync issues observed on Aria Operations after upgrade of Domain controllers from Windows Server 2019 to 2022
search cancel

AD sync issues observed on Aria Operations after upgrade of Domain controllers from Windows Server 2019 to 2022

book

Article ID: 376493

calendar_today

Updated On:

Products

VMware Aria Suite

Issue/Introduction

  • The Domain controllers are configured with 2 NICs, one is for the management traffic and the seconds NIC is for logging.
  • Both the NICs are on different network segments.
  • This did not cause issues on Microsoft Server 2019 , however after upgrading to Server 2022 the traffic seems to move to the second NIC that is used for logging.
  • This causes name resolution to fail intermittently on any domain controller resulting in server un-reachable.
  • We see entries similar to this in analytics logs:

2024-08-28T04:20:39,896+0000 WARN  [ServerConnection on port 10000 Thread 1910] [xxxxxxxxxx] com.vmware.vcops.auth.server.ldap.LdapUtil.createContext - LDAP connection failed: DC-fqdn:3268
2024-08-28T04:20:39,896+0000 WARN  [ServerConnection on port 10000 Thread 1910] [xxxxxxxxxx] com.vmware.vcops.auth.server.ldap.LdapUtil.changeHost - Changing DC to DC-fqdn:3268
2024-08-28T04:20:51,449+0000 WARN  [ServerConnection on port 10000 Thread 1930] [xxxxxxxxxx] com.vmware.vcops.auth.server.ldap.LdapUtil.createContext - LDAP connection failed: DC-fqdn:3268
2024-08-28T04:20:51,452+0000 WARN  [ServerConnection on port 10000 Thread 1930] [xxxxxxxxxx] com.vmware.vcops.auth.server.ldap.LdapUtil.changeHost - Changing DC to DC-fqdn:3268
2024-08-28T04:21:21,463+0000 ERROR [ServerConnection on port 10000 Thread 1930] [xxxxxxxxxx] com.vmware.vcops.auth.server.UserAuthenticationServer.handleAuthenticationFail - Authentication Failed. Error: Source Unavailable:
com.vmware.vcops.auth.exception.SourceUnavailableException: Host DC-fqdn Unreachable

2024-08-27T17:45:27,373+0000 ERROR [ServerConnection on port 10000 Thread 1910] [jp7Rkx70h9mfcqXNOfttCa2SEiS0chGl] com.vmware.vcops.common.util.DomainServerResolver.getServers - Error while querying DNS servers [ dns://DC_IP ] for domain [ domain_name ] javax.naming.CommunicationException: DNS error

Environment

Aria Operations 8.17.x

Resolution

  • This is not an issue in Aria Suite/Operations.
  • Microsoft needs to be engaged to investigate further.

Workaround:

Is to disable the second NIC on all the domain controllers.