Logs & Settings Action Plan for EWS issues with Active Directory Credentials

Please follow this action plan in order to collect the logs: 

1.Change log levels 

I. Change the LAC Log Level 

  1. Backup the Lync_Access_Control.xml file 
  2. Change the log severity level to debug and enable dumps: 
    • Change the <logging> tag in Lync_Access_Control.xml: 
      1. In <main> tag configure <severity>debug</severity> 
      2. In <dumps> tag change <enabled>true</enabled> 
  3. Save changes 

II. Change the EWS Log Level 

  1. Backup the EWS_Protector.xml file 
  2. Change the log severity level to debug and enable dumps: 
    • Change the <logging> tag in EWS_Protector.xml: 
      1. In <main> tag configure <severity>debug</severity> 
      2. In <dumps> tag change <enabled>true</enabled> 
  3. Save changes 

2. Replicate the issue 

3. Collect files 

  1.  Collect the log LAC_<poolname>_<date>.log and the Dumps folder from the relevant date 
  2.  Collect the log Bastion.<date>.log and the dumps folder from the relevant date 
  3. Collect the Lync_Access_Control.xml 
  4. Collect the log EWS_<poolname>_<date>.log and the Dumps folder from the relevant date 
  5. Collect the EWS_Protector.xml 
  6. Export Access Portal Logs 
  1. Open the Access Portal WebUI 
  2. Browse to /admin/logfiles 
  3. Change the log level to DEBUG 
  4. Replicate the issue 
  5. Click on Export 
  6. Send AGAT Support the AccessPortal.log file. 

4. Revert Changes 

I. Revert back to the old Lync_Access_Control.xml 

II. Revert back to the old Bastion.xml 

III. Revert back to the old EWS_Protector.xml 

IV. Restart the Bastion Service 

  1. Open PowerShell 
  2. Execute: Restart-Service bastion 
The following files are expected to be delivered following this plan:
  1. Access Portal logs and settings
  2. EWS_<poolname>_<date>.log from the relevant date
  3. EWS Traffic Dumps folder from the relevant date
  4. EWS_Protector.xml
  5. Bastion.<date>.log  folder from the relevant date from DMZ Reverse Proxy
  6. Bastion Traffic  dumps folder from the relevant date from DMZ Reverse Proxy
  7. Skype for Business Client logs

Default file location could be found here.


Please include the following information:
a. Time frames of issue
b. Users involved (SIP Address, AD username, UPN, etc.)