IBM QRadar

IBM QRadar

Join this online user group to communicate across Security product users and IBM experts by sharing advice and best practices with peers and staying up to date regarding product enhancements.

 View Only
  • 1.  Unable to connect to ldap server

    Posted Fri February 12, 2021 07:08 AM
    Hello Experts,

    I am trying to setup an LDAP Server integration with QRadar, but i see the error message "Unable to connect to ldap server" when i click the test connection button, i retrieved the DN from my active directory using the "Attribute editor", I am not suing ssl or tls. so i set both to false.

    I can telnet to my ldap server on port 389 from QRadar.

    for my authentication bind section i used a user that is part of the DN configured as my base DN.

    Kindly assist!!

    ------------------------------
    benjamin Nworah
    ------------------------------


  • 2.  RE: Unable to connect to ldap server

    Posted Fri February 12, 2021 08:21 AM

    Hello again Benjamin.

    Depending on the version you are using (not stated, but important), if I recall correctly there are bits of this functionality that are broken with regards AD and/or LDAP integration, or are no longer actively supported.

    I know this is both difficult and frustrating to set up if you do not control the AD/LDAP end as you need to see logs from both ends to work out why it is failing.

    The approach taken previously is working from the bottom upwards, to determine what in the stack is failing. 

    Bottom = Be sure that the traffic is leaving and arriving on the SIEM (i.e. there are no firewall rules blocking traffic). Network traffic passes?
    Middle = Test the connection to to the LDAP destination from a generic Linux host, to be sure you know which end is likely to be broken (not the SIEM). A common tool for that is "ldapsearch" - a search engine should guide. Is LDAP operating as expected? If yes, then points to the SIEM end.
    Top = Working side-by-side with the LDAP admin to go through the logs, determine the step it fails and go from there. What is in qradar.error? 

    I can't find the article that explains what is supported for AD/LDAP, but I know support has changed in recent versions.

    A forum search came up with this from March 2019 that may guide:
    https://community.ibm.com/community/user/security/communities/community-home/digestviewer/viewthread?GroupId=2497&MessageKey=e04a830e-b942-4b33-9e0d-190f7d1d4031&CommunityKey=f9ea5420-0984-4345-ba7a-d93b4e2d4864&tab=digestviewer



    ------------------------------
    Darren H.
    ------------------------------



  • 3.  RE: Unable to connect to ldap server

    Posted Fri February 12, 2021 02:21 PM
    Hello Daren,

    I have fixed the issue, i was using a group DN in the user base DN, that was why it was failing.

    Thank You. :)

    ------------------------------
    benjamin Nworah
    ------------------------------



  • 4.  RE: Unable to connect to ldap server

    Posted Thu October 13, 2022 07:27 AM

    Hi benlinux,

    I am still having issue in configuring LDAP auth with Qradar and I figure the issue is with the User Base DN. Would you be able to help out in this regard?



    ------------------------------
    Siem Admin
    ------------------------------