Troubleshooting
KB - Look for Kerberos log messages
Affects product
- Airlock Gateway
Question or problem
To investigate into Kerberos issues, start with the log messages described below.
Procedure-related prerequisites
- You must be logged in as an admin in the Airlock Gateway Configuration Center.
Instruction
Test preparation on Airlock Gateway:
- Go to: Application Firewall >> Reverse Proxy.
- Edit the Web application's mapping.
- Set the Operational mode to Integration.
- Click on the Activate button.
- The configuration has been updated successfully.
Test preparation - reproduce the issue:
- After changing the Operational mode in Airlock Gateway to Integration, try to reproduce the issue.
- The issue could be reproduced.
Test execution and verification:
- Go to: Log & Report >> Log Viewer.
- Click on Open to load saved searches.
- Select the saved search Logs - All Airlock Logs.
- Enter the search string below in the search field:
log_id:(WR-SG-SUMMARY or WR-SG-REJECT* or WR-SG-CAPI* or WR-SG-KERB*)
- Start the investigation with this search string.
- Verify the following:
There are no log messages with the log id
WR-SG-SUMMARY
theaction
below:rejected
blocked
There are no log messages with a log id starting with the names below describe a problem with Kerberos:
WR-SG-REJECT
WR-SG-KERB
WR-SG-CAPI
- There are no log messages indicating a Kerberos problem.
Outdated links or content?
In case of outdated links or bad content, please let us know by sending an email with a short description of your findings. Thank you very much!