
Port 123 is only required if the Network Time Protocol server is set to the local Domain
Controller on the Configuration > System > Time Zone page.
■
The network connection between the appliance and the Domain Controller is working.
If the above checks fail to identify the problem, please contact Sophos Technical Support .
C.2.16 Subdomain failed to authenticate
The configuration detection for one or more of your subdomains did not complete successfully.
Click the "show details" link to see a list of the subdomains for which the settings could not be
detected. Group policy for non-primary groups from those subdomains might not be applied as
expected.
You can also check the following
■
The global catalog points to a single Active Directory forest containing a single Active Directory
tree.
■
The root domain of your Active Directory forest has an explicit trust relationship with all domains
in the forest.
■
The same administrator credentials work for all child domain controllers.
■
All child domain controllers are accessible via the network and port 389 is open between the
appliance and all domain controllers within the Active Directory forest.
If you cannot successfully connect to your Active Directory forest, you can manually change the
port number for the Active Directory LDAP server (on the Configuration > System > Active
Directory page) to 389 to force the appliance to access the Active Directory server as a single
domain.
C.2.17 Could not join the Secondary Domain Controller
The appliance could not join the specified Secondary Domain Controller. This may be because
the Secondary Domain Controller is unreachable, or because the required object has not yet
been replicated from the Primary Domain Controller to the Secondary Domain Controller.
C.3 eDirectory Troubleshooting
The common error messages that you may encounter when configuring eDirectory access are
described in this section, as are the corrective actions that you can take to respond to them. The
following errors may be displayed at the bottom of the page when you click Verify Settings on
the Configuration > System > eDirectory page.
Important: If your Web Appliance is having difficulty in identifying or correctly identifying a user
then it is likely due to changes in your network topology or your eDirectory server. If there have
been such changes, it is recommended that you turn eDirectory integration to Off, update your
eDirectory settings, rerun Verify Settings and Apply those settings if the verify operation was
successful.
208 | Appliance Behavior and Troubleshooting | Sophos Web Appliance