The Policy Server logs the following error in `smps.log` when it searches an LDAP user store:
...Error# '81' during search: 'error: Can't contact LDAP server' Search Query = '(uid=<userid>)' for server '<ldap_host>:<port>'...
The LDAP server (or a network device in the path) closed the connection on its side, but the Policy Server did not close it, so the Policy Server still treats the connection as open. A CA Directory DSA disconnects a user that stays idle longer than the `user-idle-time` value [1]. Stateful network devices such as load balancers and firewalls can also end idle connections without notifying either end [2].
When the Policy Server next uses that connection, the search fails with LDAP error 81, which is logged in `smps.log`. The Policy Server trace log (`smtracedefault.log`, with the relevant LDAP trace components enabled) then shows the Policy Server recovering in the following sequence:
...Error# '81' during search: 'error: Can't contact LDAP server' Search Query = '(...)' for server '<ldap_host>:<port>'Reconnect to server '<ldap_host>:<port>' as it's previous connections are closed and it is available for connecting nowLdap Search callout succeeds. (Search) Base: '<base_dn>', Filter: '(uid=<userid>)'. Status: 1 entries....
The `Reconnect to server` message is how the Policy Server reports that it detected the closed connection and is re-establishing it [3]. It is seen in the Policy Server trace log (`smtracedefault.log`). The Policy Server closes the broken connection, opens a new one, and completes the Agent request successfully. This is the Policy Server working as designed and does not by itself indicate a problem.