Symantec Access Management

  • 1.  CA Directory Server Issue : "Unable to synchronize with peer"

    Posted Oct 26, 2015 11:49 AM

    Hello All,

    We are seeing Multiwrite-DISP: Unable to synchronize with peer in CA Directory server. This Directory server is integrated with CA Sitminder for user authentication. We are seeing this error in every 10 minutes.But the replication is happening. What could be the reason for this? How will this impact the CA SIteminder system.



  • 2.  Re: CA Directory Server Issue : "Unable to synchronize with peer"
    Best Answer

    Posted Oct 26, 2015 06:27 PM

    This alarm occurs when DSA A tries to synchronize DSA B using MW-DISP after start-up/outage, and the connection attempt (DSP BIND) is refused. Recovery (MW-DISP) is then attempted every 1 minute to try and make a successful connection to DSA B. The error however is only displayed every 10th iteration to save a bit of junking up the alarm log during an extended outage.

     

    To determine the cause, you will need to check the connectivity between DSA A and DSA B to see why the bind is being refused. Maybe the alarm/warn log of DSA B has a clue? This kind of issue is typically configuration related.

     

    I'm surprised that replication is working. Replication doesn't start until recovery has been successful, otherwise, the DSA will be replicating over the top of stale data. If you telnet to DXconsole and run "get dsp;" this will show the status of replication. A status of "OK" on both DSA A and DSA B indicate the recovery has completed successfully and replication is working as expected.



  • 3.  Re: CA Directory Server Issue : "Unable to synchronize with peer"

    Posted Nov 01, 2015 11:04 PM

    Hi Justin. Thanks for the help. We have verified and found some firewall is blocking the replication. Thanks for the help.