Forum Discussion

Danny_V's avatar
Danny_V
Icon for Nimbostratus rankNimbostratus
Sep 02, 2019

AD - Update Groups from AD

Hi.

 

I am having problems when trying to update / fetch groups from Active Directory.

I found a log entry saying status code: 01490200 - Unable to get domain groups for server /Common/aaa.ad.resurs.local.

 

Is there any more info I can get. Maybe a debug or something?

I need some advice, thanks.

1 Reply

  • Hello,

     

    1. I would set the Access Policy logs on debug. If you are on 13.x and above go into Access>Event Logs>Settings, you can change the log level here.
    2. At the same time run a tcpdump on the server to see what is being returned or if APM can not reach the server:

     

    #tcpdump -ni 0.0:nnn -s0 '((host x.x.x.x) and (port 88 or port 389)) or ((port 88 or port 389 or port 445 or port 464) or (port 53))' -vvv -w /shared/tmp/ad_test_2019-09-09.pcap