|
|
Re:[求助]邮件服务器上装norton antivirus for exchange的问题
我已经解决了!<br>
<br>
<br>
Situation:<br>
You are trying to install Norton AntiVirus for Microsoft Exchange (NAVMSE) version 2.1x to a Microsoft Exchange 2000 server. The NAVMSE installation requires an Exchange service account and password, but Exchange 2000 does not use a service account to run. You want to know the correct procedure for installing NAVMSE on an Exchange 2000 server.<br>
<br>
Solution:<br>
The installation of NAVMSE 2.1x to a Microsoft Exchange 2000 server using Active Directory should be approached with caution. Administrators encountering errors related to Active Directory when installing NAVMSE are encouraged to call Technical Support to report the problem and, if possible, to work toward a solution.<br>
<br>
NOTICE: Active Directory can be configured in many ways, from simple to complex. Even in its simplest form, the Active Directory schema is still very complex, which makes it difficult to generate a document that will fit all configurations. We encourage Administrators to use their discretion, their knowledge of Active Directory, and knowledge of their specific Active Directory configuration when using this document to install NAVMSE to Exchange 2000. As with any installation of new software, Symantec Technical Support strongly recommends that you back up all files and the registry prior to installing.<br>
<br>
Previous versions of this document could result in changes to Active Directory that would cause errors either during or after the installation of NAVMSE. We believe this document accounts for most configurations, but administrators should be aware of the errors that have been known to occur. We cannot guarantee this document will be suitable for all Active Directory configurations. <br>
<br>
The following are some of the problems encountered when installing NAVMSE 2.x to Microsoft Exchange 2000: <br>
<br>
Error: 'User does not have Act as part of the Operating System privileges...' when installing Norton AntiVirus for Microsoft Exchange 2.1x. <<a target=_blank href=http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2001022014075054?Open&src=bar_sch_nam&docid=2000102023022154&nsf=ent-gate.nsf&view=361fc4a260e563b1882568180069e1c0&dtype=&prod=&ver=&osv=&osv_lvl=>>http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2001022014075054?Open&src=bar_sch_nam&docid=2000102023022154&nsf=ent-gate.nsf&view=361fc4a260e563b1882568180069e1c0&dtype=&prod=&ver=&osv=&osv_lvl=></a>;<br>
<br>
The following link may be helpful in correcting this problem when the recommended installation does not work: How to troubleshoot the creation of a Norton AntiVirus for Microsoft Exchange service account under Windows 2000 with Active Directory <<a target=_blank href=http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2001041207415354?Open&src=bar_sch_nam&docid=2000102023022154&nsf=ent-gate.nsf&view=361fc4a260e563b1882568180069e1c0&dtype=&prod=&ver=&osv=&osv_lvl=>>http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2001041207415354?Open&src=bar_sch_nam&docid=2000102023022154&nsf=ent-gate.nsf&view=361fc4a260e563b1882568180069e1c0&dtype=&prod=&ver=&osv=&osv_lvl=></a>;<br>
<br>
Your clients cannot log on to the network after creating the Norton AntiVirus for Microsoft Exchange service account. <<a target=_blank href=http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2001011109442454?Open&src=bar_sch_nam&docid=2000102023022154&nsf=ent-gate.nsf&view=361fc4a260e563b1882568180069e1c0&dtype=&prod=&ver=&osv=&osv_lvl=>>http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2001011109442454?Open&src=bar_sch_nam&docid=2000102023022154&nsf=ent-gate.nsf&view=361fc4a260e563b1882568180069e1c0&dtype=&prod=&ver=&osv=&osv_lvl=></a>;<br>
<br>
This error is infrequent, and will cause a temporary loss of network access for some or all clients. The problem can be corrected by reassigning group permissions. <br>
<br>
The following link may be helpful in correcting this problem when the recommended installation does not work: How to troubleshoot the creation of a Norton AntiVirus for Microsoft Exchange service account under Windows 2000 with Active Directory <<a target=_blank href=http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2001041207415354?Open&src=bar_sch_nam&docid=2000102023022154&nsf=ent-gate.nsf&view=361fc4a260e563b1882568180069e1c0&dtype=&prod=&ver=&osv=&osv_lvl=>>http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2001041207415354?Open&src=bar_sch_nam&docid=2000102023022154&nsf=ent-gate.nsf&view=361fc4a260e563b1882568180069e1c0&dtype=&prod=&ver=&osv=&osv_lvl=></a>;<br>
<br>
<br>
Recommended installation procedure:<br>
NAVMSE 2.1 supports Exchange 2000. However, you must create an Exchange Administrator account prior to installing to an Exchange 2000 server. Exchange 2000 no longer uses an Exchange administrator account as its service account, so you must create one for NAVMSE to use. Exchange 2000 limits each account to a single mailbox, a separate account and mailbox must be created for each Exchange 2000 server. During the NAVMSE installation, you must enter this new account as the Exchange service account.<br>
<br>
There are three basic steps to setting up NAVMSE 2.x for Exchange 2000: <br>
<br>
Create a NAVMSE service account <br>
Set the required policies for the NAVMSE service account<br>
<br>
NOTE: There are two sets of instructions for setting the required policies, one for when the Exchange 2000 server is a Domain Controller, and one set of instructions for when the Exchange 2000 server is NOT a Domain Controller.<br>
<br>
Install NAVMSE<br>
<br>
<br>
The following sections provide detailed steps:<br>
<br>
To create a NAVMSE service account: <br>
<br>
Log on as the Domain Administrator or equivalent account ensuring that you have rights as the Local Administrator with full control over Active Directory. <br>
Click Start, select Programs, select Microsoft Exchange, and then click Active Directory Users & Computers. <br>
In the console tree, right-click Users, select New, and then click User. <br>
Enter the requested information to create the user account. <br>
Type NAVMSE as the logon name, click next. <br>
Add the password twice. Select password never expires, click next. <br>
Check "Create an Exchange mailbox" on the third screen of the wizard, click Next. <br>
Click Finish; the new NAVMSE service account should appear in the details pane when Users is selected in the console tree. <br>
Add the new NAVMSE service account to the Domain Administrators group: <br>
<br>
In the details pane, right-click the new NAVMSE service account that was just created, and then click Properties. <br>
Click the "Member Of" tab. <br>
Click Add. <br>
Select Domain Administrator, click Add, click OK. Domain Administrators and Domain Users should now appear in the list. <br>
Click Apply <br>
Click OK.<br>
<br>
<br>
To set the required policies for the NAVMSE service account on a computer that is NOT a Domain Controller:<br>
<br>
NOTE: The following instructions set the required policies for the NAVMSE service account in the Default Domain Policy. These settings could be overwritten if the "Act as part of the operating system" and the "Log on as a service" rights are defined in a Group Policy that has a higher precedence than the Default Domain Policy. If this is the case, then the "Act as part of the operating system" and "Log on as a service" rights need to be set in the Group Policy that has the highest precedence.<br>
<br>
<br>
From Active Directory Users & Computers, in the console tree, right-click the domain node, and then click Properties. <br>
Click the Group Policy tab. <br>
Select the Default Domain Policy, click Edit. This brings up the Group Policy window for the Default Domain Policy. <br>
In the console tree, navigate to and select User Rights Assignments, which can be found in the following location:<br>
<br>
Computer Configuration \ Windows Settings \ Security Settings \ Local Policies \ User Rights Assignments<br>
<br>
In the details pane, right-click "Log on as a service," and then click Security. <br>
Check "Define these policy settings," and then click Add. <br>
Browse to and select the NAVMSE service account that was created. <br>
Click Add, click OK on Select Users or Groups, click OK on Add user or group, and then click OK on Security Policy Setting. The "Log on as a service" should now have the NAVMSE service account as part of its Computer Setting. <br>
Repeat steps 5 through 8 to assign the "Act as part of the operating system" rights to the NAVMSE service account. <br>
Close the Group Policy window, and then click OK to close the Properties window. <br>
Close Active Directory Users & Computers. <br>
To apply the changes made to the Default Domain Policy to the Exchange Server 2000 computer, select Run from the Start menu, then enter the command:<br>
<br>
secedit /refreshpolicy MACHINE_POLICY<br>
<br>
Select OK.<br>
<br>
<br>
Follow these steps if the Exchange 2000 server is a Domain Controller: <br>
<br>
<br>
NOTE: The required policies for the NAVMSE service account on a Domain Controller need to be set in the Default Domain Controller Policy. These settings will overwrite any settings that may have been set in the Default Domain Policy, or any other lower level Group Policy. The Default Domain Controller Policy window can be found via the Active Directory Users & Computers window can be found as described below.<br>
<br>
<br>
From Active Directory Users & Computers, in the console tree, expand the domain node, then right-click on Domain Controllers, and then click Properties. <br>
Click the Group Policy tab. <br>
Select the Default Domain Controller Policy, click Edit. This brings up the Group Policy window for the Default Domain Controller Policy. <br>
In the console tree, navigate to and select User Rights Assignments, which can be found in the following location:<br>
<br>
Computer Configuration \ Windows Settings \ Security Settings \ Local Policies \ User Rights Assignments<br>
<br>
In the details pane, right-click "Logon as a service" and then click Security. <br>
Check "Define these policy settings," and then click Add. <br>
Browse to and select the NAVMSE service account that was created. <br>
Click Add, click OK on Select Users or Groups, click OK on Add user or group, and then click OK on Security Policy Setting. The "Logon as a service" should now have the NAVMSE service account as part of its Computer Setting. <br>
Repeat steps 5 through 8 to assign the "Act as part of the operating system" rights to the NAVMSE service account. <br>
Close the Domain Controller Security Policy window. <br>
To apply the changes made to the Default Domain Controller Policy to the Exchange Server 2000 computer, select Run from the Start menu, then enter the command:<br>
<br>
secedit /refreshpolicy MACHINE_POLICY<br>
<br>
Select OK. <br>
<br>
To install NAVMSE: <br>
<br>
Log off, and then log on using the NAVMSE service account that was just created. <br>
Run the NAVMSE installation program. <br>
Enter the NAVMSE service account information when prompted for the Microsoft Exchange service account information. <br>
After installing NAVMSE, Log off as the NAVMSE account. <br>
Logon as the Domain Administrator or equivalent account.<br>
<br>
<br>
NOTE: If you are installing in VAPI or Combo mode on Exchange 2000, then you must stop and then restart MSExchangeIS immediately after the installation is complete in order for VAPI (or COMBO) mode to work correctly. Microsoft is aware of this problem and expects to have it fixed in Exchange 2000 Service Pack one.<br>
<br>
Symantec does not recommend using VAPI or COMBO mode on a server receiving SMTP mail without Service Pack 1 for Exchange 2000. For more information, see the document Norton AntiVirus for Microsoft Exchange 2.1.x does not scan incoming SMTP mail on Exchange 2000 <<a target=_blank href=http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2000121515205654?Open&src=bar_sch_nam&docid=2000102023022154&nsf=ent-gate.nsf&view=361fc4a260e563b1882568180069e1c0&dtype=&prod=&ver=&osv=&osv_lvl=>>http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2000121515205654?Open&src=bar_sch_nam&docid=2000102023022154&nsf=ent-gate.nsf&view=361fc4a260e563b1882568180069e1c0&dtype=&prod=&ver=&osv=&osv_lvl=></a>;.<br>
<br>
See the document How to install Service Pack 1 for Microsoft Exchange 2000 on a server with Norton AntiVirus for Microsoft Exchange 2.1x <<a target=_blank href=http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2001062711441654?Open&src=bar_sch_nam&docid=2000102023022154&nsf=ent-gate.nsf&view=361fc4a260e563b1882568180069e1c0&dtype=&prod=&ver=&osv=&osv_lvl=>>http://service1.symantec.com/SUPPORT/ent-gate.nsf/docid/2001062711441654?Open&src=bar_sch_nam&docid=2000102023022154&nsf=ent-gate.nsf&view=361fc4a260e563b1882568180069e1c0&dtype=&prod=&ver=&osv=&osv_lvl=></a>;.<br>
<br>
|
|