华为USG防火墙对接windows server 2025实现AD SSO单点登录
报错如下:
Jul 8 2025 15:02:24.870.5+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] Send UDP kerbores AS request packet successfully.
Jul 8 2025 15:02:24.940.1+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] Recevied kerbores packet successfully, username: whadmin, state: 2.
Jul 8 2025 15:02:24.940.2+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] Kerberos server's response is bad, ErrorCode: 52.
Jul 8 2025 15:02:24.940.3+08:00 FHQ_USG6300E AD/7/debug:[AD(Err):] Kerberos server's response is bad, ErrorCode: 52.
Jul 8 2025 15:02:24.940.4+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] Response too big for UDP;retry with TCP.
Jul 8 2025 15:02:24.940.5+08:00 FHQ_USG6300E AD/7/debug:AS-REP Parse ERROR!
Jul 8 2025 15:02:24.940.6+08:00 FHQ_USG6300E AD/7/debug:[AD(Err):] Make kerbores TGS Request packet by UDP failed, so try TCP .username: whadmin
Jul 8 2025 15:02:24.970.1+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] Make TCP kerbores AS Request packet successfully,username: whadmin
Jul 8 2025 15:02:24.970.2+08:00 FHQ_USG6300E AD/7/debug:AD SendPacketWithTCP, pstADConn->uiTemplateID=0
Jul 8 2025 15:02:24.970.3+08:00 FHQ_USG6300E AD/7/debug:ad select ip by source, uiTemplateNO=0
<FHQ_USG6300E>
Jul 8 2025 15:02:24.970.4+08:00 FHQ_USG6300E AD/7/debug:ad select ip by source, ip=x.x.x.x
Jul 8 2025 15:02:24.970.5+08:00 FHQ_USG6300E AD/7/debug:ad select ip by source, ip=x.x.x.x
Jul 8 2025 15:02:24.970.6+08:00 FHQ_USG6300E AD/7/debug:AD SendPacketWithTCP, ulSourceIp=168890864(new)
Jul 8 2025 15:02:25.20.1+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] Send packet to server OK with TCP (Server IP:x.x.x.x,port:88)
Jul 8 2025 15:02:25.20.2+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] Recevied kerbores packet successfully, username: whadmin, state: 2.
Jul 8 2025 15:02:25.20.3+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] recv TCP AS response from AD server this time is 1460
Jul 8 2025 15:02:25.20.4+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] Recevied kerbores packet successfully, username: whadmin, state: 2.
Jul 8 2025 15:02:25.20.5+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] recv TCP AS response from AD server this time is 198
Jul 8 2025 15:02:25.20.6+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] Total received TCP AS response from AD server is :1658
Jul 8 2025 15:02:25.20.7+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] check tag 2 ok.
Jul 8 2025 15:02:25.20.8+08:00 FHQ_USG6300E AD/7/debug:AD Make Tgs Req OK!
<FHQ_USG6300E>
Jul 8 2025 15:02:25.20.1+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] Make TCP kerbores TGS Request packet successfully,username: whadmin
Jul 8 2025 15:02:25.20.2+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] Send packet to server OK with TCP (Server IP:x.x.x.x,port:88)
Jul 8 2025 15:02:25.20.3+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] Send TCP kerbores TGS Request packet successfully.
Jul 8 2025 15:02:25.30.1+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] Recevied kerbores packet successfully, username: whadmin, state: 3.
Jul 8 2025 15:02:25.30.2+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] recv TCP TGS response from AD server this time is 1460
Jul 8 2025 15:02:25.30.3+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] Recevied kerbores packet successfully, username: whadmin, state: 3.
Jul 8 2025 15:02:25.30.4+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] recv TCP TGS response from AD server this time is 116
Jul 8 2025 15:02:25.30.5+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] Total received TCP TGS response from AD server is :1576
Jul 8 2025 15:02:25.30.6+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] check tag 2, may don't have tag 2.
Jul 8 2025 15:02:25.30.7+08:00 FHQ_USG6300E AD/7/debug:[AD(Pkt):] Give the Kerberos Ticket to LDAP for verifying.Length is [1488]
Jul 8 2025 15:02:25.30.8+08:00 FHQ_USG6300E AD/7/debug:[AD(Evt):] kerbores authenication accept.
Jul 8 2025 15:02:25.30.9+08:00 FHQ_USG6300E AD/7/debug: free AD connect success !
社区内有其他一篇文章是说密码带了特殊字符,我这里并不是这个原因。
原因没有查到,但是更换域控版本到windows server 2022,服务正常能够正常导入用户信息。
更多推荐
所有评论(0)