The discovery accounts get locked out .
Options
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
an hour ago
We are experiencing frequent account lockouts during Discovery because Discovery attempts multiple credentials before reaching the correct one.
Example:
Device:
- IP: 172.xx.x.xx
- Hostname: xxxxxxx.servereps.local
- DNS Domain: servereps.local
Discovery attempts the following credentials in order:
- Linux Account
- CP_Alpharetta_SSH_01
- dctreg AD account
- HT_RW_Windows_servereps (correct credential)
- Dctseg AD SSH Credential
- saas
- Linux_Local_Account
- Linux Server_Alpharetta
- servicenow
- AD Account for Linux
- Linux Local Account
- CP_Alpharetta_SSH_02
- CP_PCI_SSH
Because the first few attempts fail, the account gets locked before Discovery reaches the valid credential. As a result, no devices in this domain are discovered.
Is there an OOTB way to configure Discovery so that:
- Discovery selects credentials based on DNS domain, hostname pattern, IP range, or Classification.
- Only relevant credentials are attempted for devices in servereps.local.
- Credential testing order can be controlled to avoid account lockouts.
Has anyone implemented Credential Affinity or another approach to solve this at scale?
0 REPLIES 0