Forum Discussion
SanderCYBR
Dec 02, 2021Copper Contributor
Error Installing ATP sensor on DC
Hi, Installing on Windows server 2019 DC Worked on one DC and failed on the second one. It says its about proxy or SSL incpection but using the same network configuration for both DC..... Only...
Martin_Schvartzman
Microsoft
Jun 16, 2022No. It's not required for .NET v2.0. But you may be encountering a different issue.
Did you install the sensor with the proxyUrl switch, or are you using a transparent proxy? It (the proxy) might be doing SSL inspection and it's breaking the sensor's communication.
aexlz
Jun 16, 2022Brass Contributor
We installed it with the proxyURL switch and it is doing SSL inspection.
I did not read anything in the documentation that SSL inspection is forbidded...
I did not read anything in the documentation that SSL inspection is forbidded...
- EliOfekJun 17, 2022
Microsoft
https://docs.microsoft.com/en-us/defender-for-identity/troubleshooting-known-issues#applyinternal-failed-two-way-ssl-connection-to-service-error
The sensor is doing mutual authentication, thus ssl inspection will fail it.- aexlzJun 17, 2022Brass ContributorThank you for yor confirmation. We will disable ssl inspection.
However: It would be an advantage if this was cleary stated in the documentation like e.g. for Defender for Endpoint:
https://docs.microsoft.com/en-us/microsoft-365/security/defender-endpoint/linux-support-connectivity?view=o365-worldwide#troubleshooting-steps-for-environments-with-static-proxy- Martin_SchvartzmanJul 06, 2022
Microsoft