Quantcast
Channel: Forcepoint Community
Viewing all articles
Browse latest Browse all 2011

Problem with Authenticating users

$
0
0

Hello to you all,

I'm having very unusual problem and not sure what to troubleshoot at this stage.

Symptoms are similar to http://community.websense.com/forums/p/1661/5708.aspx

In short,

I have two filtering servers and one policy server.
users are authenticated via LDAP and different browsing policies apply based on user's group memberships in ou.

Both filtering servers report to Policy server and policy gui shows "no errors found" all communicates just fine.
Database downloads to both and all appears to be working.


However, I recently found that if I go through one filtering server proxy I get a page blocked when go through the other I do not get the page blocked.

After some troubleshooting I found that my user is not authenticated while going via second proxy.

I pasted logs below for review. I did go and check the dc communication etc. but I thought the Policy Server communicates with the AD only.
And that works because if I change anything in the policy and go via one proxy the changes are in place.

When I go through the other server the changes are not in place.

Could anyone tell me where to look, troubleshoot?

Thank you!

logs:

Normal 0 false false false EN-IE X-NONE X-NONE MicrosoftInternetExplorer4

Accepting connections on port 55805...

Core code has connected.

 

Using version 5

Core code has connected.

 

Using version 5

time= Tue Jul 17 17:16:34 2012   version= 5

server= LOCAL SERVER IP ADDRESS  source= LOCAL CLIENT IP ADDRESS  dest= 173.194.67.104

URL= http://www.google.com/

protocol= 1 - http  port= 80  networkDirection= Inbound

method=

contentType =

category= 76 - SEARCH ENGINES AND PORTALS

categoryReason= 0 - CatNone

disposition= 1026 - Category Not Blocked

roleId= 0

user=

bytes sent= 559  bytes received= 543

  duration= 0 ms   scan duration= 0 ms

policyName=

 

time= Tue Jul 17 17:17:31 2012   version= 5

server= LOCAL SERVER IP ADDRESS 2  source= LOCAL CLIENT IP ADDRESS  dest= 173.194.67.94

URL= http://www.google.ie/

protocol= 1 - http  port= 80  networkDirection= Inbound

method=

contentType =

category= 76 - SEARCH ENGINES AND PORTALS

categoryReason= 0 - CatNone

disposition= 1025 - Category Blocked

roleId= 0

user= LDAP://ADsrv,OU=Helpdesk,OU=StandardUsers,OU=ITServices,OU=UserAccounts

,OU=UserGroups,DC=xx,DC=xx/lastname,\,firstname

bytes sent= 565  bytes received= 145

  duration= 1000 ms   scan duration= 0 ms

policyName=

 


Viewing all articles
Browse latest Browse all 2011

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>