05.08.2013 Views

InterScanTM Messaging Security Virtual Appliance - Online Help ...

InterScanTM Messaging Security Virtual Appliance - Online Help ...

InterScanTM Messaging Security Virtual Appliance - Online Help ...

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Trend Micro InterScan <strong>Messaging</strong> <strong>Security</strong> <strong>Virtual</strong> <strong>Appliance</strong> Administrator’s Guide<br />

32-10<br />

TABLE 32-1. Troubleshooting issues<br />

ISSUE DESCRIPTION AND RESOLUTION<br />

Users are unable<br />

to log on to the<br />

EUQ management<br />

console<br />

using Kerberos<br />

single sign-on<br />

(SSO)<br />

Logging on to the EUQ console using SSO requires the<br />

following:<br />

1. LDAP1 or LDAP2 servers are enabled and specified<br />

as in use for Active Directory (IP address or domain<br />

name or FQDN).<br />

2. The DNS server configured for IMSVA contains the<br />

record of the Kerberos service.<br />

3. The endpoint operating system supports (and<br />

enables) Kerberos authentication:<br />

• Time should be synchronized between IMSVA and<br />

the Kerberos authentication service.<br />

• Using FireFox: The about:config link is configured to<br />

add the negotiate-auth trusted url list.<br />

• Using Internet Explorer: The EUQ console is added<br />

to the internal site list.<br />

<br />

The Windows integrated authentication setting in<br />

Internet Explorer is enabled.<br />

• Using Windows Vista or above, use the hostname as<br />

the instance when generating a keytab file.<br />

4. Only one EUQ console instance can be mapped to<br />

one user account. If the instance is mapped to more<br />

than one user, SSO will not work.<br />

5. If EUQ is deployed in a parent-child deployment, use<br />

the parent device’s 8447 port to access EUQ. SSO<br />

will not work if a child’s port is used.<br />

6. The account provided on the LDAP Settings screen<br />

has permission to look up all accounts for<br />

authentication.

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!