VMware Networking Community
jkensy
Enthusiast
Enthusiast

LDAP/Domain config NSX Manager "Could not establish communication with the NSX Manager"

Hi all - brand new lab deploy of NSX 6.4.1 - NSX Manager is registered to vCenter, etc.  This is vSphere 6.5, NSX 6.4.1.  I went in and configured the domain LDAP setup for  NSX Manager authentication but then realized I'd rather use a service account for LDAP authentication.  Blew out the domain configuration, recreated, and now I see the screenshot attached.

Any thoughts on what to do?  Fortunately it's vanilla in a lab, but I can see this having to be performed if domains merge or change, etc.

Thanks!

Reply
0 Kudos
3 Replies
rajeevsrikant
Expert
Expert

If possible can you share the NSX manager logs & also the previous screen showing where you entered the domain name & the netbios name.

NSX - Implement identity service support for Active Directory, NIS, and LDAP with Single Sign-On (SS...

Reply
0 Kudos
cnrz
Expert
Expert

Does the svc-vra-ad account has read permission to browse all objects in the AD domain tree? As the only change is the user, AD could not be responding

NSX 6 Documentation Center

Also is the service account for  SSO Integration of NSX Manager -Vcenter or for Identity based Firewall?

Reply
0 Kudos
RussBurden
Contributor
Contributor

I have this exact same issue, but with vsphere 6.7 and NSX 6.4.5.  I receive Could not establish communication with NSX Manager. Please contact administrator., but if I change the user to a qualified name, like user@domain, I receive a login failure.  I have used this domain and user for other ldap integrations, including the vcenter integration, which works perfectly.

Also, this work correctly in vcenter 6.0 with NSC 6.3.x as well, just when I upgraded to vcenter 6.7 and NSX 6.4.5 is when this issue started occurring.

When the first error occurs, there are no error messages in the NSX manager logs, but the second one definitely shows a login failure.

I have this credential being used for other ldap integrations and works perfectly, I have also tested it with the apache directory studio as well..

Reply
0 Kudos