Technical Tip: Dual Domain Controller for Kerberos Authentication on FortiProxy
| Description | This article describes how to configure dual Domain Controller in High Availability for Kerberos Authentication on FortiProxy. |
| Scope | Microsoft Windows Server 2016 and FortiProxy. |
| Solution |
 
nslookup -type=SRV _kerberos._tcp.domain.com
It should reflect the IP address of the Domain Controllers.
 
   
  
 
   
 
 
   
 
 
Note: Upon testing, the Kerberos ticket is not automatically changed to the Secondary Domain Controller in the scenario that the Primary Domain Controller goes down while the ticket is still active. Once the ticket is expire and the Primary Domain Controller is still down, it will request another ticket from the Secondary Domain Controller. |

















