I get an error -626 and ndsconfig returns a value of 78.

Hello guys,
Here is a brief summary of the network design. We have a School server in the Network A. The Main eDir is in a Network B.
The school server to access the Main eDir goes through a DNAT configured on our firewall.
During the different steps I can browse my ldap on the main eDir without any issue.
This to complete the information about Existing Tree Information, Local Server Configuration and Linux User Management Configuration for example.
However, at the moment of the eDir configuration (I use the GUI) the software returns an error -626 and ndsconfig returns a value of 78.
Our issue seam to arise when using the NCP for replication I guess. The questions are: is it possible to DNAT NCP and if it is what is missing?
Of course, if I were installing another server on the Network B and try with the same settings it will work.
I have seen in different posts that replication is not possible through NAT. However I can't find anything regarding the ncp protocol that would explain why our DNAT shouldn't work.
I opened these ports.
389 LDAP
636 LDAPS
524 NCP
427 SLP
8443 iManager
8009 NRM
8030 iMonitor
8028 iMonitor
Is there a formal documentation that I can relate to?
Thank you in advance and I wish you already a great weekend.

It could potentially work, but normally it does not work unless you do
some really interesting stuff with routing. Here is why:
When one server looks up how to reach another server, the way that
referral is given includes the target server's IP address, as seen by the
target server. As a result, if you are on 17u2.16.0.1 for serverA, and
you ask to talk to serverB which has address 192.168.0.1, the referral
(within the NCP packet) will tell the server to access 192.168.0.1. Since
neither 172.16.x.x nor 192.168.x.x are routable normally, and since you're
using DNAT, the addresses won't get to their destination and you have a
connection problem (-626).
The ability NCP has to provide addresses to clients and servers via
referrals, NDS Pings, and the like is really powerful because it means, in
a network that allows it, that any client/server can find any
replica-hosting server to be accessed directly. The downside of this is
that technologies which mess with the network layer by hiding IP addresses
break the way clients would access servers.
LDAP, for example, doesn't usually report anything about how to reach a
server. Normally a client knows which server to ask from the very start
and then goes there. Even with eDirectory, if an LDAP client accesses an
eDirectory server that does not have a replica of the desired object, then
by default the eDirectory server (not the LDAP client) goes and follows
referrals to find and return the object.
For these reasons, NAT is normally not supported between eDirectory
servers. Could you make it work? Probably assuming you can get your
routers to handle things properly, but it's going to be more than just
dropping things in place and hoping they work, and it will be more than
just allowing TCP/UDP ports through.
Good luck.
If you find this post helpful and are logged into the web interface,
show your appreciation and click on the star below...

Similar Messages

Maybe you are looking for

  • Photo and video editor on nokia n8 belle

    Hi, my phone crashed, with a stupid demo game, and I had to use the 3 buttons reset.  Now, I do not have access to nokia video and photo editor. How can I reinstall this?  Thanks in advance

  • Error in First step of Process Chain

    Hi everybody, i have created a process chain with a start process (direct scheduling) to InfoPackage to load into InfoCube-so delete indexes and generate indexes were automatically inserted becoz of default chain option. i have checked the chain-- th

  • Payment Summary Overrides - ETP

    Hi Gurus, I have a requirement to be able to override the following 3 pieces of Information as a part of override process for ETP Payment Summaries Pre 1 July 1983 Days Post 30 June 1983 Days ETP Payment Date I have tried executing Payment Summary ov

  • PCo 2.1 and Proficy iFix using OPC DA

    I'm finding some interesting behavior when trying to access Proficy iFIX  HMI / SCADA with PCo 2.1 using OPC DA. PCo Version 2.1.0.55 iFIX version 5.1 SCADA OS: Windows XP Pro, SP3 MII Version 12.1.5 Build(99) What happens is that when I do a tag lis

  • Undeliverable mail question

    hi, What does this dsn mean? And could it be spam? the subject is "Undeliverable mail" Message body: Failed to deliver to '[email protected]' SMTP module(domain yyyyy.com) reports: yyyyy.com: no response Two attachments came along with the message. O