Jump to content

Recommended Posts

Posted

Hello all,

 

I posted a few months ago about issues with DA which I am still experiencing in set up. The DA client will not move beyond the 'Connecting' message when trying to build the connection. Speaking to the ISP, they could see the traffic entering port 443 (HTTPS which DA uses) and being forwarded to the correct server internally, but the server does not pick up the connection and none of the network shares etc work on the client.

 

All the correct DNS records exist in the DNS table which was one solution suggested for this issue.

 

I also get an error on the client that says IPHTTPS interface is not installed which seems ominous for DA as it uses IPHTTPS.

 

Many thanks! This issue has been on top of me for months...

Posted

Out of interest, do you have anything else installed on that server?

 

I remember having issues using port 443 with another bit of software as I had port 80 used for WSUS. Found out that if 80 was used for IIS, then 443 was automatically reserved for it.

 

It may be worth pointing out that Always On VPN is now the way Microsoft are nudging people to go.

Posted
No, it's a new Virtual Machine created purely to act as DA server.

 

Hmmm, that should be fine then... I used @sparkeh's guide after setting up a new 2012 R2 VM. http://www.edugeek.net/blogs/sparkeh/2253-directaccess-server-2012r2-windows-10-education-nat.html

 

Always on VPN has to be set up through SCCM right?

 

I didn't think so, but can't be possitive. Have been toying with looking at it myself, but haven't had the time yet.

Posted
Hello all,

 

I posted a few months ago about issues with DA which I am still experiencing in set up. The DA client will not move beyond the 'Connecting' message when trying to build the connection. Speaking to the ISP, they could see the traffic entering port 443 (HTTPS which DA uses) and being forwarded to the correct server internally, but the server does not pick up the connection and none of the network shares etc work on the client.

 

All the correct DNS records exist in the DNS table which was one solution suggested for this issue.

 

I also get an error on the client that says IPHTTPS interface is not installed which seems ominous for DA as it uses IPHTTPS.

 

Many thanks! This issue has been on top of me for months...

 

I’d start by running the Da troubleshooting tool (google it) on the client when trying to connect. I’ve always found the output when run in debug mode normally points me in the direction of the problem.

Posted
I’d start by running the Da troubleshooting tool (google it) on the client when trying to connect. I’ve always found the output when run in debug mode normally points me in the direction of the problem.

 

 

 

I'll try that now and see what information it provides. Thanks :)!

 

- - - Updated - - -

 

You mention port 443. Have you also allowed port 62000 through firewall as well?

 

I haven't allowed port 62000. Is that on the server/client/network firewall?

Posted

A few questions from me as I have been having this trouble and managed to get it working after a while:

 

1) Have you got Windows Firewall setup right on your server and client PC?

2) Have you got IPV6 enabled on both?

3) You say the DNS records are right, in your direct access configuration do you have the IPV4 to 6 translation address set as the DA DNS server?

 

I used these guides to help troubleshooting in case they are of any use

 

https://directaccess.richardhicks.com/2015/09/22/directaccess-dns-not-working-properly/

https://directaccess.richardhicks.com/2017/07/10/top-5-directaccess-troubleshooting-powershell-commands/

 

There were also some articles I found about disabling the other IPV6 transition technologies and forcing it to use HTTPS instead

 

Joel

Posted

62000 is required inbound and outbound from client to server. See below snippet from MS

 

IP-HTTPS—Transmission Control Protocol (TCP) destination port 443, and TCP source port 443 outbound. When the DirectAccess server has a single network adapter, and the network location server is on the DirectAccess server, then TCP port 62000 is also required.

 

Also, make sure firewall is not disabled on server and clients. You can turn off domain firewall but need public and private on

Posted (edited)

I havent touched 62000 on our DA deployment, only TCP 443 and it works fine (although our's has 2 NICs and is in our DMZ). The network location server should only be available externally.

 

Connect one of the problem machines to a 4G hotspot or home internet connection and run the DA diagnostic tools to see why it isn't happy, this will give you a very detailed log of what it's doing: https://www.microsoft.com/en-gb/download/details.aspx?id=41938

Edited by Blue_Cookeh
Posted

OP what is your config - 1 nic, 2 nics etc?

I had one recently that I was pulling my hair out on for a while looking at all these complicated things before realising the server had its windows firewall turned off. Just in case it's a simple thing like that.

Posted

The set up is one nic. I enabled port 62000 on both the client and the server which did not help.

 

Here is the output from the troubleshooting tool: errors at pretty much every stage!

[15/12/2017 09:00:34]: In worker thread, going to start the tests.

[15/12/2017 09:00:34]: Running Network Interfaces tests.

[15/12/2017 09:00:34]: PdaNet Broadband Connection (PdaNet Broadband Adapter): fe80::119:9a2a:f062:f505%14;: 10.1.19.2/255.255.255.0;

[15/12/2017 09:00:34]: Default gateway found for PdaNet Broadband Connection.

[15/12/2017 09:00:34]: PdaNet Broadband Connection has configured the default gateway 10.1.19.1.

[15/12/2017 09:00:46]: Warning - default gateway 10.1.19.1 for PdaNet Broadband Connection does not reply on ICMP Echo requests, the request or response is maybe filtered?

[15/12/2017 09:00:58]: The public DNS Server (8.8.8.8) does not reply on ICMP Echo requests, the request or response is maybe filtered?

[15/12/2017 09:00:58]: The public DNS Server (2001:4860:4860::8888) does not reply on ICMP Echo requests, the request or response is maybe filtered?

[15/12/2017 09:00:58]: Running Inside/Outside location tests.

[15/12/2017 09:00:58]: NLS is https://DirectAccess-NLS.domain.school:62000/insideoutside.

[15/12/2017 09:00:58]: NLS is not reachable via HTTPS, the client computer is not connected to the corporate network (external) or the NLS is offline.

[15/12/2017 09:00:58]: NRPT contains 2 rules.

[15/12/2017 09:00:58]: Found (unique) DNS server: fd3b:5119:6c32:3333::1

[15/12/2017 09:00:58]: Send an ICMP message to check if the server is reachable.

[15/12/2017 09:00:58]: DNS Server fd3b:5119:6c32:3333::1 does not reply on ICMP Echo requests.

[15/12/2017 09:00:58]: Running IP connectivity tests.

[15/12/2017 09:00:58]: The 6to4 interface is disabled.

[15/12/2017 09:00:58]: Teredo inferface status is offline.

[15/12/2017 09:00:58]: The configured DirectAccess Teredo server is win1710.ipv6.microsoft.com..

[15/12/2017 09:00:58]: The IPHTTPS interface is not operational, last error code is 0x80190194.

[15/12/2017 09:00:58]: The IPHTTPS interface status is failed to connect to the IPHTTPS server. Waiting to reconnect.

[15/12/2017 09:00:58]: Error - no IPv6 transition technology is operational!

[15/12/2017 09:00:58]: The configured IPHTTPS URL is https://85.92.177.122:443.

[15/12/2017 09:00:58]: IPHTTPS has a single site configuration.

[15/12/2017 09:00:58]: IPHTTPS URL endpoint is: https://85.92.177.122:443.

[15/12/2017 09:00:59]: Successfully connected to endpoint https://85.92.177.122:443.

[15/12/2017 09:00:59]: No response received from stkaths.school.

[15/12/2017 09:00:59]: Running Windows Firewall tests.

[15/12/2017 09:00:59]: The current profile of the Windows Firewall is Public.

[15/12/2017 09:00:59]: The Windows Firewall is enabled in the current profile Public.

[15/12/2017 09:00:59]: The outbound Windows Firewall rule Core Networking - Teredo (UDP-Out) is enabled.

[15/12/2017 09:00:59]: The outbound Windows Firewall rule Core Networking - IPHTTPS (TCP-Out) is enabled.

[15/12/2017 09:00:59]: Running certificate tests.

[15/12/2017 09:00:59]: No usable machine certificate found.

[15/12/2017 09:00:59]: Found 0 machine certificates on this client computer.

[15/12/2017 09:00:59]: Running IPsec infrastructure tunnel tests.

[15/12/2017 09:00:59]: Failed to connect to domain sysvol share \\domain.school\sysvol\domain.school\Policies.

[15/12/2017 09:00:59]: Running IPsec intranet tunnel tests.

[15/12/2017 09:00:59]: Failed to connect to fd3b:5119:6c32:1000::1 with status IcmpError.

[15/12/2017 09:00:59]: Failed to connect to fd3b:5119:6c32:1000::2 with status IcmpError.

[15/12/2017 09:00:59]: Failed to connect to HTTP probe at http://directaccess-WebProbeHost.domain.school.

[15/12/2017 09:00:59]: Running selected post-checks script.

[15/12/2017 09:00:59]: No post-checks script specified or the file does not exist.

[15/12/2017 09:00:59]: Finished running post-checks script.

[15/12/2017 09:00:59]: Finished running all tests.

 

Firewall is running on both client and server as is IPv6

Posted
your certificate hasnt expired has it (just a guess tbh). i never did manage to get this working with just 1 nic (but also never got beyond proof of concept testing)
Posted

worth also noting i had a similar issue to this before and after two days of troubleshooting i decided to blow the server away. This resolved the issue with exactly the same settings and deployment.

 

REALLY IMPORTANT - if you do the above, make sure the devices are on and update GPOs straight away. I didnt and my devices were unable to talk to the domain anymore as the NRPT address was pointing to old IPV6 address. The solution is to locate the reg key below and delete the key for you internal domain. Restart the machine and then it will now connect to domain

 

(HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\DnsClient\DnsPolicyConfig)

Posted

[15/12/2017 09:00:59]: No usable machine certificate found.

[15/12/2017 09:00:59]: Found 0 machine certificates on this client computer.

 

Do you have a PKI setup internally? Do your machines have machine certificates?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...