<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Hi, in Web Security</title>
    <link>https://community.cisco.com/t5/web-security/wsa-ad-issue/m-p/2868076#M6509</link>
    <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;We're using&amp;nbsp;AD 2012 R2 and yes, SMBv1 is protocol is enabled (along with SMBv2). Also, no&amp;nbsp;event logs in the AD server pertaining to any errors such as errors&amp;nbsp;1058 and 1030.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
    <pubDate>Mon, 04 Apr 2016 04:45:23 GMT</pubDate>
    <dc:creator>Sea NT</dc:creator>
    <dc:date>2016-04-04T04:45:23Z</dc:date>
    <item>
      <title>WSA - AD Issue</title>
      <link>https://community.cisco.com/t5/web-security/wsa-ad-issue/m-p/2868074#M6507</link>
      <description>&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;Greetings,&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;There appears to be some issue between AD and WSA, wherein some user authentication specifics are not getting returned from the AD to WSA.&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;On testing the authentication settings in WSA, it was observed that there is some clocking mismatch with 10.140.20.51&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;What could possibly be the issue shown in the warning message above ?&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Checking DNS resolution of WSA hostname(s)...&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Success: Resolved 'AEADWS01-ADSSC.adssc.int' address: 10.140.18.208&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Success: Resolved 'webproxy1.adssc.int' address: 10.140.151.11&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Checking DNS resolution of Active Directory Server(s)...&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Success: Resolved '10.140.20.51' address: 10.140.20.51&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Success: Resolved '10.140.20.52' address: 10.140.20.52&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Checking DNS resolution of AD Server(s)' full computer name(s)...&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Success: Resolved 'ASPWPDCS01.adssc.int' address: 10.140.20.51&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Success: Resolved 'ASVWPDCS02.adssc.int' address: 10.140.20.52&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Validating configured Active Directory Domain...&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Success: Active Directory Domain Name for '10.140.20.51' : ADSSC.INT&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Success: Active Directory Domain Name for '10.140.20.52' : ADSSC.INT&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Attempting to get TGT...&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Success: Kerberos Tickets fetched from server '10.140.20.51' :&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Success: Kerberos Tickets fetched from server '10.140.20.52' :&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Checking local WSA time and server time difference...&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;STRONG&gt;&lt;EM&gt;&lt;SPAN style="color: red; font-size: 10pt;"&gt;Warning: Cannot check system time on AD server '10.140.20.51'&lt;/SPAN&gt;&lt;/EM&gt;&lt;/STRONG&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Success: AD Server time and WSA time difference within tolerance limit&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Attempting to fetch AD group information...&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P style="margin: 0in 0in 0pt;"&gt;&lt;EM&gt;&lt;SPAN style="font-size: 10pt;"&gt;Success: Able to query for AD Group Information from Active Directory server '10.140.20.51'.&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-family: 'Calibri','sans-serif'; font-size: 10pt;"&gt;Success: Able to query for AD Group Information from Active Directory server '10.140.20.52'.&lt;/SPAN&gt;&lt;/EM&gt;&lt;EM&gt;&lt;SPAN style="font-family: 'Calibri','sans-serif'; font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-family: 'Calibri','sans-serif'; font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;&lt;SPAN style="font-family: 'Calibri','sans-serif'; font-size: 10pt;"&gt;&lt;/SPAN&gt;&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Sun, 03 Apr 2016 14:55:00 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-ad-issue/m-p/2868074#M6507</guid>
      <dc:creator>Sea NT</dc:creator>
      <dc:date>2016-04-03T14:55:00Z</dc:date>
    </item>
    <item>
      <title>Hi </title>
      <link>https://community.cisco.com/t5/web-security/wsa-ad-issue/m-p/2868075#M6508</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;/P&gt;
&lt;P&gt;What AD server and version that you are using? are you using&amp;nbsp;AD 2012 R2? if yes, check whether&amp;nbsp;SMBv1 is disabled in the AD server since&amp;nbsp;WSA is only supporting SMBv1.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Also check the event logs in the AD server, whether&amp;nbsp;record any errors such as errors&amp;nbsp;1058 and 1030.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 03:09:28 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-ad-issue/m-p/2868075#M6508</guid>
      <dc:creator>Handy Putra</dc:creator>
      <dc:date>2016-04-04T03:09:28Z</dc:date>
    </item>
    <item>
      <title>Hi,</title>
      <link>https://community.cisco.com/t5/web-security/wsa-ad-issue/m-p/2868076#M6509</link>
      <description>&lt;P&gt;Hi,&lt;/P&gt;
&lt;P&gt;We're using&amp;nbsp;AD 2012 R2 and yes, SMBv1 is protocol is enabled (along with SMBv2). Also, no&amp;nbsp;event logs in the AD server pertaining to any errors such as errors&amp;nbsp;1058 and 1030.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;Thanks&lt;/P&gt;</description>
      <pubDate>Mon, 04 Apr 2016 04:45:23 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-ad-issue/m-p/2868076#M6509</guid>
      <dc:creator>Sea NT</dc:creator>
      <dc:date>2016-04-04T04:45:23Z</dc:date>
    </item>
    <item>
      <title>Hello Handy,</title>
      <link>https://community.cisco.com/t5/web-security/wsa-ad-issue/m-p/2868077#M6510</link>
      <description>&lt;P&gt;Hello Handy,&lt;/P&gt;
&lt;P&gt;I am in need of assistance. I came across this post you made and it seems like it is related to my issue. With our WSA on ASYNC OS 10.1.1 we cannot get authentication to work correctly when SMB V1 is turned off on the domain controllers. SMB V1 being on is not an option anymore. I am reading your post where you say the WSA only supports SMB V1 but is this still the case with the latest OS release? I am not having fun troubleshooting this. Another question is if we used the agents on the domain controllers would there be a need for SMB at all?&lt;/P&gt;</description>
      <pubDate>Fri, 12 May 2017 10:12:33 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-ad-issue/m-p/2868077#M6510</guid>
      <dc:creator>abadcabassa</dc:creator>
      <dc:date>2017-05-12T10:12:33Z</dc:date>
    </item>
    <item>
      <title>I am having the same problem,</title>
      <link>https://community.cisco.com/t5/web-security/wsa-ad-issue/m-p/2868078#M6511</link>
      <description>&lt;P&gt;I am having the same problem, after disabling SMB I have lost authentication of AD users, please help&lt;/P&gt;</description>
      <pubDate>Fri, 19 May 2017 06:58:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-ad-issue/m-p/2868078#M6511</guid>
      <dc:creator>KriegerPiloto</dc:creator>
      <dc:date>2017-05-19T06:58:38Z</dc:date>
    </item>
    <item>
      <title>Hi</title>
      <link>https://community.cisco.com/t5/web-security/wsa-ad-issue/m-p/2868079#M6512</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;SMB v1 needs to enabled in server, even I faced the same issue after disabling SMBv1.&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuo70696/?referring_site=bugquickviewredir&lt;/P&gt;
&lt;P&gt;&lt;/P&gt;
&lt;P&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCuo34050/?referring_site=bugquickviewredir&lt;/P&gt;</description>
      <pubDate>Mon, 22 May 2017 04:12:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/web-security/wsa-ad-issue/m-p/2868079#M6512</guid>
      <dc:creator>bonifaceaa</dc:creator>
      <dc:date>2017-05-22T04:12:20Z</dc:date>
    </item>
  </channel>
</rss>

