Why after securing LDAP communication with LDAPS there are still connections with LDAP server on port 389?
​
Applies to
- ONTAP 9
- LDAP
- LDAPS
- Domain Controller Discovery (DC Discovery)
Answer
- DC Discovery is the procedure that uses port 389 in communication with DC's while discovering LDAP servers
- Dynamic server discovery is used by ONTAP for discovering Domain Controller's (DC's) and their associated services, such as LSA, NETLOGON, Kerberos, and LDAP
- It discovers all the DC's, including preferred DC's, as well as all the DC's in the local site and all remote DC's every 4 hours