Troubleshooting

KB - Look for Kerberos log messages

Affects product

  • Airlock Gateway

Question or problem

To investigate into Kerberos issues, start with the log messages described below.

Procedure-related prerequisites

  • You must be logged in as an admin in the Airlock Gateway Configuration Center.

Instruction

Test preparation on Airlock Gateway:

  1. Go to: Application Firewall >> Reverse Proxy.
  2. Edit the Web application's mapping.
  3. Set the Operational mode to Integration.
  4. Click on the Activate button.
  5. The configuration has been updated successfully.

Test preparation - reproduce the issue:

  1. After changing the Operational mode in Airlock Gateway to Integration, try to reproduce the issue.
  2. The issue could be reproduced.

Test execution and verification:

  1. Go to: Log & Report >> Log Viewer.
  2. Click on Open to load saved searches.
  3. Select the saved search Logs - All Airlock Logs.
  4. Enter the search string below in the search field:
  5. log_id:(WR-SG-SUMMARY or WR-SG-REJECT* or WR-SG-CAPI* or WR-SG-KERB*)
  6. Start the investigation with this search string.
  7. Verify the following:
  8. There are no log messages with the log id WR-SG-SUMMARY the action below:

    rejected

    blocked

  9. There are no log messages with a log id starting with the names below describe a problem with Kerberos:

    WR-SG-REJECT

    WR-SG-KERB

    WR-SG-CAPI

  10. There are no log messages indicating a Kerberos problem.

Outdated links or content?

In case of outdated links or bad content, please let us know by sending an email with a short description of your findings. Thank you very much!