VDA Registration Error: "The Security Support Provider Interface (SSPI) negotiation failed."

VDA Registration Error: "The Security Support Provider Interface (SSPI) negotiation failed."

book

Article ID: CTX237342

calendar_today

Updated On:

Description

Environment:

  • 2 child domains
  • 'a.parent.local' & 'b.parent.local', 'parent.local' being the root domain
  • VDA resides in 'a.parent.local' and DDC is in 'a.parent.local'
Issue:
VDA unable to register itself with DDC

Error:
On the VDA we get the event:
"The Security Support Provider Interface (SSPI) negotiation failed."

Resolution

Opened Port UDP 389 on firewall and then the VDA will be able to register itself successfully.

Problem Cause

VDA performs an LDAP query to the root domain and as the firewall blocks the packets, they cannot get through.

Example: 2 such packets seen in network monitor.
 
2238/2/2018 13:0980.30.x.y10.10.x.yLDAPMessageLDAPMessage:Search Request, MessageID: 560
2248/2/2018 13:0980.30.x.y10.10.x.yLDAPMessageLDAPMessage:Search Request, MessageID: 561