Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    DC Cluster for LDAP Authentication?

    Scheduled Pinned Locked Moved General pfSense Questions
    4 Posts 3 Posters 511 Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • S
      sreece
      last edited by sreece

      Hello,

      Currently, I have Microsoft AD authentication server used by OpenVPN for the cert+user authentication pointed to one of my two domain controllers. I was wondering if it's possible to point it instead to a DNS record that is pointed to both servers, or possibly round-robin the load to each DC? Is this worth looking into, or should I just live with the single point of failure if the current DC was down?

      I'm using STARTTLS, so I know there'd have to be an internal cert that matched the server name I use in the LDAP hostname, but that's for another post.

      Thanks for any advice!

      stephenw10S N 2 Replies Last reply Reply Quote 0
      • stephenw10S
        stephenw10 Netgate Administrator @sreece
        last edited by

        I've never tried it but I know you can use HAProxy to load balance LDAP. pfSense itself could authenticate against that.

        However in OpenVPN you can just define multiple authentication servers and it will try the other one if the first does not respond.

        Steve

        S 1 Reply Last reply Reply Quote 1
        • N
          Napsterbater @sreece
          last edited by

          @sreece said in DC Cluster for LDAP Authentication?:

          I'm using STARTTLS, so I know there'd have to be an internal cert that matched the server name I use in the LDAP hostname, but that's for another post.

          You can look at Network Load Balancing, it is built into Windows Server.

          1 Reply Last reply Reply Quote 0
          • S
            sreece @stephenw10
            last edited by sreece

            @stephenw10 Good advice. I just used my generated pfsense LDAP CA to issue another cert for the second DC and imported the CA cert and generated server cert into the certificate store on that domain controller. Totally forgot you could choose more that one auth server in the OpenVPN server config. Thanks for reminding me!

            1 Reply Last reply Reply Quote 1
            • First post
              Last post
            Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.