Troubleshooting guide
1-14
Cisco Wide Area Application Services Configuration Guide
OL-26579-01
Chapter 1 Configuring Application Acceleration
Enabling and Disabling the Global Optimization Features
The WAAS DNS server must be part of the DNS system of Windows Active Directory domains to
resolve DNS queries for traffic encryption.
To configure DNS settings, see the “Configuring the DNS Server” section on page 1-26.
Step 2 Configure NTP Settings to synchronize the time with Active Directory.
The WAAS device has to be in synchronization with Active Directory for Encrypted MAPI acceleration.
The WAAS NTP server must share time synchronization with the Active Directory Domain Controllers
domains for which traffic encryption is desired. Out of sync time will cause Encrypted MAPI
acceleration to fail.
To synchronize the time with Active Directory, see the “Configuring NTP Settings” section on page 1-5.
Step 3 Verify WAE devices are registered and online with the WAAS Central Manager.
To verify WAE devices are registered and online with the WAAS Central Manager, see the “Devices
Window” section on page 1-6.
Step 4 Configure SSL Peering Service.
Note SSL accelerator must be enabled and in the running state.
To configure SSL Peering Service, see the “Configuring SSL Peering Service” section on page 1-43.
Step 5 Verify WAN Secure mode is enabled.
The default mode is Auto. You can verify the state of WAN Secure mode using the following EXEC
command:
show accelerator wansecure
If necessary, you can change the state of WAN Secure using the following global configuration
command:
accelerator mapi wansecure-mode {always | auto | none}
Step 6 Configure windows domain settings and perform domain join. (Domain join automatically creates the
machine account in Active Directory.)
Note Performing a domain join of the WAE is not required on branch WAE devices.
Note This step is optional on data center WAEs if only user accounts are used for domain identity
configuration in the next step.
To configure Windows Domain Server Authentication settings, see the “Configuring Windows Domain
Server Authentication Settings” section on page 1-17 section.
Note You must use Kerberos authentication for Encrypted MAPI Acceleration. NTLM authentication
method is not supported.
Step 7 Configure domain identities. (Not required for branch WAEs.)