windows server 2019 unable to authenticate to secondary domain controller using Cisco ASA firewall

ojooo 1 Reputation point
2021-08-12T07:38:31.69+00:00

First of all, is it possible to authenticate on a domain with two domain controllers running Windows server 2019 to authenticate to the primary and the secondary domain controller, while both domain controllers are up and functional?

No errors have been found when running dcdiag on both domain controllers.

When authenticating from a Cisco ASA firewall the authentication and authorisation to the primary domain controller is succesful, but when authenticating or authorizing to the second domain controller it fails with a unknown error.

The configuration for both DC's is the same on the ASA, except for the IP adress.

So what could be the problem?

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,303 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Dave Patrick 426.2K Reputation points MVP
    2021-08-12T12:51:19.343+00:00

    What happens when you try? Please run;

    Dcdiag /v /c /d /e /s:%computername% >C:\dcdiag.log
    repadmin /showrepl >C:\repl.txt
    ipconfig /all > C:\dc1.txt
    ipconfig /all > C:\dc2.txt
    ipconfig /all > C:\problemworkstation.txt

    then put unzipped text files up on OneDrive and share a link.

    0 comments No comments

  2. ojooo 1 Reputation point
    2021-08-27T17:36:08.74+00:00

    Hi, sorry for the late response, here you can find the log files as requested.
    The only thing missing is the "problemworkstation" , because there isn't any, the problem is in the Cisco ASA.

    https://1drv.ms/u/s!AiJnqSX-_IInoHTypnY7gNkiEx-M?e=Sdud76

    0 comments No comments

  3. Dave Patrick 426.2K Reputation points MVP
    2021-08-27T17:52:34.847+00:00

    A couple of issues that may or not be related.

    User credentials does not have permission to perform this operation. The account used for this test must have network logon privileges.

    https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/replication-error-8453
    https://support.microsoft.com/en-us/topic/3489ffaf-0f43-2a29-0ee6-531524179491

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments

  4. Dave Patrick 426.2K Reputation points MVP
    2021-08-27T20:51:51.333+00:00

    Just checking if there's any progress or updates?

    --please don't forget to upvote and Accept as answer if the reply is helpful--

    0 comments No comments