Wanted to share some things I learned while troubleshooting another domain join issue.
In my case, I upgraded my FAC HA LB cluster from 5.4.1 > 6.0.3 and afterwards the secondary/slave unit would not re-join 1 of my domains. The master re-joined all 4 properly, but the slave just would not rejoin a single domain for some reason.
TL;DR:
The quickest way to fix an issue like this probably just to delete the machine account from the domain, and re-join using a service account that has Domain Administrator privileges. Once the FAC has properly re-joined the domain, you can remove the Domain Administrator privileges from the account. The FAC will create the machine account for you, with all of the necessary settings it wants it to have. Letting the FAC create the machine account is definitely the best approach, imho.
Debugging Active Directory domain issues
[ol]> shell[/ol]
bash-3.1#
/bin/smbop list[/ol]
------
2: mycorp.com
3: othercorp.com
1: yetanother.com
4: domain.icareabout.com
The Fortinet Security Fabric brings together the concepts of convergence and consolidation to provide comprehensive cybersecurity protection for all users, devices, and applications and across all network edges.
Copyright 2023 Fortinet, Inc. All Rights Reserved.