In Data Loss Prevention 15.x, when you attempt to import the Information Centric Tagging 15.x classification taxonomy into the Enforce Server database, the import fails with the message: Failed to synchronize the ICT classification taxonomy.
The import is initiated from the Enforce Server administration console System > Settings > Information Centric Tagging page.
The ICT classification taxonomy import can fail if any of these prerequisites are not in place:
Hosts
file for the ICT server.Below are the specifics for implementing the prerequisites.
Configuring ICT for synchronizing the classification taxonomy with Data Loss Prevention
To create a user account that has access to the necessary ICT Administration Webservice methods:
Reference: Information Centric Tagging Deployment Guide
Configuring DLP for synchronizing the ICT classification taxonomy
To identify the user who has ICT access:
Reference: Data Loss Prevention 15.x Administration Guide
Configuring Windows on the Enforce Server to recognize the ICT server
To identify the ICT server, on the DLP Enforce Server:
%systemdrive%\Windows\System32\drivers\etc\
.Hosts
file to map the ICT server IP address to its host name, using the tabulated format: <IP> <FQDN of ICT server>
Importing the ICT taxonomy
When the ICT, DLP, and Windows prerequisites are in place, to import the ICT taxonomy:
Reference: Data Loss Prevention 15.x Administration Guide
User access failure log entries
If an ICT classification taxonomy import fails because of issues with the user account, you may see the following two error messages, one in DLP and one in ICT.
%systemdrive%\ProgramData\Symantec\DataLossPrevention\EnforceServer\15.[n]\logs\tomcat
:/ICT/Admin-Webservice/Classifications.asmx
. For example, the log entry in the directory%systemdrive%\inetpub\logs\LogFiles\
would be similar to this: