VCF Identity Broker (VIDB) Directory Sync Fails with "LDAP server is not reachable. This could be due to network issues, firewall blocks , an incorrect hostname, or invest BIND credentials . Please verify the configuration and retry the sync
search cancel

VCF Identity Broker (VIDB) Directory Sync Fails with "LDAP server is not reachable. This could be due to network issues, firewall blocks , an incorrect hostname, or invest BIND credentials . Please verify the configuration and retry the sync

book

Article ID: 442558

calendar_today

Updated On:

Products

VCF Operations

Issue/Introduction

When attempting to synchronize an Active Directory identity source within VCF Identity Broker (VIDB), the synchronization fails, and the directory status displays a retry resync state.

The following full error message is logged or displayed in the administrator console:

LDAP server is not reachable. This could be due to network issues, firewall blocks, an incorrect hostname, or invalid BIND credentials. Please verify the configuration and retry the sync

Environment

VMware Cloud Foundation 9.x

VCF Identity Broker

Cause

This issue occurs when the BIND user credentials configured for the Active Directory connection are invalid, expired, or locked out. Because VCF Identity Broker (VIDB) cannot authenticate against the LDAP server using the provided credentials, it fails to establish a proper connection, resulting in an "unreachable" server status even if network routing is fully functional.

Resolution

To resolve this issue, update the BIND credentials within the VCF Identity Broker (VIDB) administrator console and manually force a directory resynchronization.

Step-by-Step Instructions:

  1. Navigate: To the VCF Operations console > Fleet Management > Identity & Access > VCF Instances > Select the configured instance > Edit the directory

  2. Update Credentials: Locate the directory configuration settings section where the BIND User DN and Password are defined.

    • Input the corrected and active password for the BIND account.

  3. Save Changes: Click Save to apply the updated configuration.

  4. Trigger Manual Sync: Click Sync Now to initiate a manual directory resync.

  5. Verify Status: Monitor the sync log to ensure the directory successfully authenticates, pulls updates, and returns to a healthy status.

Additional Information

If the issue persists, The cause could be different, Refer https://knowledge.broadcom.com/external/article/427554/vcf-components-failed-to-login-with-vcf.html which has steps to check logs.