Blocked port causes joining SVM to Domain to fail: KDC Unreachable
Applies to
- ONTAP 9
- CIFS
- Active Directory
Issue
Commands like vserver active-directory create
, vserver cifs create
and vserver cifs modify
fail:
Error when creating - Failed to create the Active Directory machine account "LODDEMO".
Reason: Kerberos Error: KDC Unreachable
Details: Error: Machine account creation procedure failed
[ 98] Loaded the preliminary configuration.
[ 4149] TCP connection to ip 192.168.0.253, port 88 via interface 192.168.0.190 failed: Operation timed out.
**[ 24233] FAILURE: Could not authenticate as ** 'administrator@DEMO.NETAPP.COM': Cannot contact any KDC ** for requested realm (KRB5_KDC_UNREACH)