Deathmage wrote: » 1. As the two seperate location's 'north' and 'south' in two different AD forests? Nope. 2. Are the two locations in different IP ranges? Yep 3. If their in two different IP ranges, have they been added to the Sites and Services area for each forest's AD or solo AD forest? Yep 4. Can clients in location 'north' managed hosts in location 'south? and vis-versa? Yep 5. if these are indeed remote sites, do they have a VPN tunnel between each location? Believe so...I'll need to double check with our network team. 6. This tied in sites and services, but can you resolve the vCenter's in each location with DNS? - if their not setup in sites and services, DNS won't 'know' to ping across WAN's even if a VPN tunnel is established. Yep 7. Do you have proper network routes between each location so each network knows where to do when requests for network X from network Y? ...vis-versa. Again, I dunno. 8. if you have a firewall is the device blocking ICMP/DNS/Domain traffic from traversing the WAN's? Dunno. let me brainstorm some more here, check these out and we can go from here.
Essendon wrote: » SSO mode? Name of SSO domain the same for both vCenters?
Johnjones wrote: » It's weird that when I click "use windows credentials" I'm able to log in, but when I manually enter the SAME creds it won't let me in.
Johnjones wrote: » Yep. I see a ton of "Identity Manager Failed to find group" and I see a bunch of our AD groups. Also, I see "Failed to authenticate principal" for my login information. Now I just need to figure out why this is happening and it's only occurring on the South vCenter. Could this still possibility be a firewall problem?
Johnjones wrote: » I'm not using the appliance. Also, I am able to browse users/groups through SSO/configuration on the webclient. I've tried removing it, adding it back and setting as default but nothing. Thanks again.
Deathmage wrote: » Also, I think I remember seeing you mention it before but did you join the ESXi host's to the domain, is your vCenter on a VM or is it a physical box? if all else fails, something else to try, your AD records for your vCenter box could be corrupt in AD. See if you leave the domain and join WORKGROUP, reboot, and then rejoin the domain. You could have a AD breakdown with the vCenter server.
Essendon wrote: » I know you are trying to think outside the square, but these points are largely irrelevant to the problem at hand. Hosts joined to the domain or not wont influence why you cannot logon to the web client. vCenter being physical or virtual wouldn't matter at all (he's confirmed he can log into the thick client with no issues). Again, if the vCenter object was corrupt in AD, he'd be on P1 call with VMware and/or Microsoft, not asking us questions here. Terrible things happen when AD goes outa whack. Re-install, I think.