
If you chose the Auto-detect advanced settings option, the remaining fields of the Active
Directory settings are automatically filled. The appliance will first look for an Active Directory
global catalog at port 3268. If it can't find that, it defaults to a single-domain Active Directory
configuration using port 389.
Note: With Auto-detect advanced settings selected, the appliance will choose a domain
controller based on the lowest ping time.
The Detect Settings dialog box is displayed, showing the results of the connection attempt.
Successful operations are indicated with a green check mark icon; failed operations are
indicated with a red "x" icon. The Detecting subdomains step can also show an orange
exclamation mark, which indicates that one or more trusted (child) domains could not be
synchronized. To the right of the Detecting subdomains verification item is a Show details
button, which you can click to view the results of attempts to connect to the subdomains of
your Active Directory forest. The subdomains are listed in one of two groupings: Authentication
Successful or Authentication Failed.
If there are failed operations in the Detect Settings process, a troubleshooting message is
displayed below the list of verification checks. This message links to explanatory text that will
assist you in correcting the problem. If you encounter failed operations, read the troubleshooting
message, then Close the Detect Settings dialog box, correct the Active Directory Settings
in the left column, and click Verify Settings again.
When all Verify Settings operations are successful, all of the required Active Directory text
boxes are filled.
Important: If the verification of a connection to an Active Directory subdomain fails because
that server is down at the time that you run the verification, bringing the server back up will
not enable Active Directory synchronization with the appliance. You must have a successful
Verify Settings operation for any connection to a subdomain server to enable communications
between it and the appliance.
6. Click Apply.
7. [Optional] Click Synchronize Now to have the appliance immediately synchronize user and
group information with the configured Active Directory server. This can only be done after
steps 4, 5 and 6 have been completed successfully.
Related concepts
Grouped Appliance Troubleshooting
on page 210
on page 131
on page 132
Related tasks
on page 133
Configuring Active Directory to support Kerberos for Mac OS X
on page 134
Configuring an Authentication Profile
on page 135
4.4.5.2 Trusted Domains and Subdomains
The Web Appliance supports trusted domains and trusted subdomains in Active Directory. For
example, the root parent domain
example.local
could have both
dev.example.local
and
sales.example.local
as trusted subdomains. This same parent domain could have a trust
Sophos Web Appliance | Configuration | 127