This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Set up Kerberos in v18?

Is there any additional configuration needed to enable Kerberos authentication in v18?  I got a failure message on upgrade startup in the log viewer: Cannot initialize Kerberos authentication with domain." but have not been able to figure out how to troubleshoot it further.  Documentation doesn't seem to mention anything.  Thanks in advance.



This thread was automatically locked due to age.

Top Replies

  • Hello Dieter,

    I actually solved the puzzle with Lucar`s help and my problem is solved.

    About the GPO you may only use the link with http://fw... distribute.

    And you are not allowed to access the firewall with the name from the client over HTTPS anymore. Because otherwise the browsers will save the name as HSTS and from now on only want to log in via HTTPs. And then the NTLM authentication fails.

    If you still use the firewall as a user portal you have to think about which DNS names you want to store in the certificate. e.g. fw.xg.de for NTLM/Kerberos; portal.xg.de for userportal and xgadmin.xg.de for admin access via port 4444, which is also https.

    Many greetings

    Translated with www.DeepL.com/Translator (free version)

    Jump to answer
Parents Reply
  • Bill Roland said:
    Hi LuCar, thanks for that.

    Still, XG log viewer reports an error with Kerberos.  Unfortunately it doesn't provide anything in the way of useful information (maybe in version 26 the log viewer will be useful).  

    I agree with Bill. The other day I was getting mad to find why XG was blocking traffic and even the advanced shell did not help.

    Logging needs to be improved a lot.

    Bill do you see any logs from advanced shell?

    Tail - f /log/*.log

Children