The discovery accounts get locked out .
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
6 hours ago
We are experiencing frequent account lockouts during Discovery because Discovery attempts multiple credentials before reaching the correct one.
Example:
Device:
- IP: 172.xx.x.xx
- Hostname: xxxxxxx.servereps.local
- DNS Domain: servereps.local
Discovery attempts the following credentials in order:
- Linux Account
- CP_Alpharetta_SSH_01
- dctreg AD account
- HT_RW_Windows_servereps (correct credential)
- Dctseg AD SSH Credential
- saas
- Linux_Local_Account
- Linux Server_Alpharetta
- servicenow
- AD Account for Linux
- Linux Local Account
- CP_Alpharetta_SSH_02
- CP_PCI_SSH
Because the first few attempts fail, the account gets locked before Discovery reaches the valid credential. As a result, no devices in this domain are discovered.
Is there an OOTB way to configure Discovery so that:
- Discovery selects credentials based on DNS domain, hostname pattern, IP range, or Classification.
- Only relevant credentials are attempted for devices in servereps.local.
- Credential testing order can be controlled to avoid account lockouts.
Has anyone implemented Credential Affinity or another approach to solve this at scale?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
2 hours ago
@Hazik Yes. You can use Credential Affinity. In the Discovery, first time discover below using the right credentials, then automatically that credentials will be added as affinity. Next time, when you schedule, it will not try whole list but instead use the affinity one.
- IP: 172.xx.x.xx
- Hostname: xxxxxxx.servereps.local
- DNS Domain: servereps.local