The discovery accounts get locked out .

Hazik
Kilo Explorer

We are experiencing frequent account lockouts during Discovery because Discovery attempts multiple credentials before reaching the correct one.

Example:

Device:

  • IP: 172.xx.x.xx
  • Hostname: xxxxxxx.servereps.local
  • DNS Domain: servereps.local

Discovery attempts the following credentials in order:

  1. Linux Account
  2. CP_Alpharetta_SSH_01
  3. dctreg AD account
  4. HT_RW_Windows_servereps (correct credential)
  5. Dctseg AD SSH Credential
  6. saas
  7. Linux_Local_Account
  8. Linux Server_Alpharetta
  9. servicenow
  10. AD Account for Linux
  11. Linux Local Account
  12. CP_Alpharetta_SSH_02
  13. CP_PCI_SSH

Because the first few attempts fail, the account gets locked before Discovery reaches the valid credential. As a result, no devices in this domain are discovered.

Is there an OOTB way to configure Discovery so that:

  • Discovery selects credentials based on DNS domain, hostname pattern, IP range, or Classification.
  • Only relevant credentials are attempted for devices in servereps.local.
  • Credential testing order can be controlled to avoid account lockouts.

Has anyone implemented Credential Affinity or another approach to solve this at scale?

1 REPLY 1

Vijaya_Mnpram
Kilo Sage

@Hazik Yes. You can use Credential Affinity.  In the Discovery, first time discover below using the right credentials, then automatically that credentials will be added as affinity. Next time, when you schedule, it will not try whole list but instead use the affinity one. 

 

  • IP: 172.xx.x.xx
  • Hostname: xxxxxxx.servereps.local
  • DNS Domain: servereps.local