J_Worth Posted August 8, 2016 Posted August 8, 2016 Hello all, We have just had a new Smoothwall appliance installed and all seems to be working well apart from the fact I cannot get DirSync to work. Everytime I enter the DirSync username and password I get: "Unable to establish a connection the authentication service. Contact Technical Support." I have added: - microsoftonline.com - windows.net - microsoft.com - microsoftonline-p.com to the Authentication exceptions and the servers have direct access to the internet - they don't go through the web filter. Any help would be greatly appreciated. Many thanks.
Steve21 Posted August 8, 2016 Posted August 8, 2016 When you say you entered the dirsync username and password do you mean the local account within AD? As you'll get that error if you didn't give it your o365 admin username/password too Steve
J_Worth Posted August 8, 2016 Author Posted August 8, 2016 I've given it both a local AD account as well as an O365 admin username/password and Forefront Identity Manager prompts with that error message.
Steve21 Posted August 8, 2016 Posted August 8, 2016 And the o365 one is the full email style username? What's it show in the dirsync logs when it errors? Steve
J_Worth Posted August 8, 2016 Author Posted August 8, 2016 Full email style username has been added for the O365 one. Here is an entry in Event Viewer: Unable to establish a connection to the authentication service. Contact Technical Support. GetAuthState() failed with -2147186688 state. HResult:0. Contact Technical Support. (0x80048862) AND Failed credential provisioning ping. Error: Microsoft.Online.Coexistence.ProvisionException: Unable to establish a connection to the authentication service. Contact Technical Support
Steve21 Posted August 8, 2016 Posted August 8, 2016 You tried adding the full o365 category to the auth bypass for that server? There's a pre-made category with most of them in. (We have ours entirely whitelisted from the AAD server), just noticed the ones you said above are only a small set of the ones needed. Would also advise running "netsh winhttp show proxy" on the server just to make sure you don't have an old proxy set on it still. Steve
J_Worth Posted August 8, 2016 Author Posted August 8, 2016 Yep, the full O365 category has been added to the Auth Bypass. When running netsh winhttp show proxy it shows as Direct Access (no proxy) - I have set the Server VLAN to go direct and not via the web filter.
J_Worth Posted August 9, 2016 Author Posted August 9, 2016 Managed to resolve this issue. The firewall on Smoothwall was blocking the traffic. Set the allow all policy for the dirsync server and it all works now.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now