12-27-2017 07:58 PM
Hello guys,
We've recently changed the setting "Allow unlisted file name extensions" under "Request Filtering Settings" in IIS, and since then the Enterprise Vault webpage cannot be accessed.
We don't want to allow the unlisted files hence we don't want to remove this setting. We've already tried adding '.' in allow files. Not sure what else we could try.
Any help will be much appreciated!
Regards,
EVUser
Solved! Go to Solution.
12-28-2017 01:10 AM
Hi mate,
This IIS change is not supported by EV.
If the customer wants to make the EV environment more secure, there are other things to be considered, including enabling HTTPS, using RBA, etc. Have a look on below articles:
https://vox.veritas.com/t5/Archiving-and-eDiscovery/Making-Enterprise-Vault-More-Secure/ba-p/780389
https://vox.veritas.com/t5/Articles/How-to-secure-Enterprise-Vault/ta-p/813833
12-27-2017 10:45 PM
Hi there,
Can you advise what is the reason for making this change in the IIS?
12-28-2017 01:00 AM - edited 12-28-2017 01:03 AM
Hi Virgil,
Our end customer wanted to change this setting as advised by their network security team. And now we can't open http://localhost/enterprisevault/ URL. Customer is adamant on not reverting the setting and wants us to find a work-around. We did try putting a '.' in exceptions but that hasn't seemed to help.
12-28-2017 01:10 AM
Hi mate,
This IIS change is not supported by EV.
If the customer wants to make the EV environment more secure, there are other things to be considered, including enabling HTTPS, using RBA, etc. Have a look on below articles:
https://vox.veritas.com/t5/Archiving-and-eDiscovery/Making-Enterprise-Vault-More-Secure/ba-p/780389
https://vox.veritas.com/t5/Articles/How-to-secure-Enterprise-Vault/ta-p/813833
12-28-2017 01:20 AM
Thanks Virgil. That makes sense. Just for the record, is it documented anywhere that EV does not support such IIS tweaks?
12-28-2017 01:30 AM
Nope, it is not documented as far as I know. If you want an official confirmation, you can log a case and ask Veritas support to confirm that for you. Then, you can show that to the customer.