<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Redundant LDAP servers]]></title><description><![CDATA[<p dir="auto">I'm running pfSense 2.2.1 in a couple different locations with AD environments. All of these environments, of course, have multiple DCs. What I'd like to do is to be able to specify multiple servers for login auth, etc. That way, if the DC that I've pointed pfSense at goes down or is unavailable, then pfSense is still available for login. As it stands right now, when I reboot the DC that pfSense LDAPs against, I cannot login to the firewall.</p>
<p dir="auto">Additionally, this would be nice for OpenVPN too… :)</p>
<p dir="auto">If this is a current feature, please let me know how to do it. :) If not, maybe move this to feature requests.</p>
<p dir="auto">Thanks!</p>
]]></description><link>https://forum.netgate.com/topic/82002/redundant-ldap-servers</link><generator>RSS for Node</generator><lastBuildDate>Wed, 22 Apr 2026 17:03:53 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/82002.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 28 Mar 2015 14:06:01 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to Redundant LDAP servers on Sat, 02 May 2015 06:55:30 GMT]]></title><description><![CDATA[<p dir="auto">Yes, you could. You don't by default and that's all that matters, pretty much. Good luck convincing those unfortunate guys that need to mess with AD CA to mess with the templates.</p>
]]></description><link>https://forum.netgate.com/post/541478</link><guid isPermaLink="true">https://forum.netgate.com/post/541478</guid><dc:creator><![CDATA[doktornotor]]></dc:creator><pubDate>Sat, 02 May 2015 06:55:30 GMT</pubDate></item><item><title><![CDATA[Reply to Redundant LDAP servers on Sat, 02 May 2015 00:40:10 GMT]]></title><description><![CDATA[<p dir="auto">i didn't know the LDAP client was smart enough to try multiple servers if it got more than one A record from DNS.</p>
<p dir="auto">Couldn't you get SSL Certificates with the DC FQDN plus the AD domain name as a SAN in each server?</p>
]]></description><link>https://forum.netgate.com/post/541461</link><guid isPermaLink="true">https://forum.netgate.com/post/541461</guid><dc:creator><![CDATA[Derelict]]></dc:creator><pubDate>Sat, 02 May 2015 00:40:10 GMT</pubDate></item><item><title><![CDATA[Reply to Redundant LDAP servers on Fri, 01 May 2015 22:09:11 GMT]]></title><description><![CDATA[<p dir="auto">@pan_2:</p>
<blockquote>
<p dir="auto">You already have all necessary redundancy built-in. Provide AD domain name in "LDAP Server name", not some DCs FQDN.</p>
</blockquote>
<p dir="auto">Well that actually completely fails at least when SSL is involved.</p>
]]></description><link>https://forum.netgate.com/post/541440</link><guid isPermaLink="true">https://forum.netgate.com/post/541440</guid><dc:creator><![CDATA[doktornotor]]></dc:creator><pubDate>Fri, 01 May 2015 22:09:11 GMT</pubDate></item><item><title><![CDATA[Reply to Redundant LDAP servers on Fri, 01 May 2015 21:10:52 GMT]]></title><description><![CDATA[<p dir="auto">You already have all necessary redundancy built-in. Provide AD domain name in "LDAP Server name", not some DCs FQDN.</p>
]]></description><link>https://forum.netgate.com/post/541433</link><guid isPermaLink="true">https://forum.netgate.com/post/541433</guid><dc:creator><![CDATA[Soyokaze]]></dc:creator><pubDate>Fri, 01 May 2015 21:10:52 GMT</pubDate></item><item><title><![CDATA[Reply to Redundant LDAP servers on Wed, 01 Apr 2015 14:03:08 GMT]]></title><description><![CDATA[<p dir="auto">No such thing for WebGUI. For OpenVPN, you are able to select multiple LDAP servers for auth, using the CTRL key. Whether it works or not, no idea.</p>
]]></description><link>https://forum.netgate.com/post/532982</link><guid isPermaLink="true">https://forum.netgate.com/post/532982</guid><dc:creator><![CDATA[doktornotor]]></dc:creator><pubDate>Wed, 01 Apr 2015 14:03:08 GMT</pubDate></item><item><title><![CDATA[Reply to Redundant LDAP servers on Wed, 01 Apr 2015 13:44:33 GMT]]></title><description><![CDATA[<p dir="auto">Bump?</p>
]]></description><link>https://forum.netgate.com/post/532975</link><guid isPermaLink="true">https://forum.netgate.com/post/532975</guid><dc:creator><![CDATA[coachmark2]]></dc:creator><pubDate>Wed, 01 Apr 2015 13:44:33 GMT</pubDate></item></channel></rss>