Jump to content

Direct Access Stopped working 'Network Location Server: Not Working Properly'


Recommended Posts

Posted (edited)

Hi all,

 

The Direct Access system in a school I inherited has stopped working. I have no idea of the original setup as there was no documentation left. We are getting a critical error for the Network Location Server.

 

DAServer2DA.PNG

 

DAServer1.PNG

 

I have checked the certificates and none have expired, I have checked the Default Site bindings in IIS, where there are 4 entries but none have SSL certificates selected. One I have noticed after doing some research that there is no DNS entry for the Direct Access NLS, which is the same server as the DA server.

 

I have never setup a DA system so I am learning as I am going, so any help and advice would be appreciated.

 

Cheers

 

P.S. I have also just noticed an error in the infrastructure setup.

 

Infrac.PNG

 

Worrying as the servers are the same.

Edited by Theldron
Posted
Have you checked that the server thinks it's on your domain? i.e. it doesn't think its on a public or private network and has changed its own firewall settings. Try resetting the network location service.
Posted
Have you checked that the server thinks it's on your domain? i.e. it doesn't think its on a public or private network and has changed its own firewall settings. Try resetting the network location service.

 

The server is still attached to the domain ok. Sorry mate, how do I go about resetting network location service?

Posted
if your firewall says it's connected to the domain, then you don't need to reset the NLS. if the direct access server group policy has been altered then restoring the server will not help. (otherwise go for it) Check the GPO and see if it been recently changed. btw have you rebooted the server? mine gets funny if it boots before a DC is available.
Posted
if your firewall says it's connected to the domain, then you don't need to reset the NLS. if the direct access server group policy has been altered then restoring the server will not help. (otherwise go for it) Check the GPO and see if it been recently changed. btw have you rebooted the server? mine gets funny if it boots before a DC is available.

 

Hi mate, yeah I have tried a reboot. Tried a restore and checked the GPO all seem ok, but I still have the error and no connection to DA. Not sure if related but I was getting a load of DNS errors yesterday, with DNS Bad Key in event viewer. I found that one of the DNS servers could not resolve its IP in, DNS -> name servers. I resolved it manually and instantly all those issues stopped.

 

Should the bindings in IIS on the Direct Access server be linked to IIS certificates?

Posted (edited)
Just checked ours, you should have in forward lookup zones a zone for access.domainname with host(A) lookups, in the main domain zone should be DNS entries for directaccess-NLS, directaccess-webprobehost, and directaccess all Host (A) pointing at your DA server Edited by The_Techie
Posted
Just checked ours, you should have in forward lookup zones a zone for access.domainname with host(A) lookups, in the main domain zone should be DNS entries for directaccess-NLS, directaccess-webprobehost, and directaccess all Host (A) pointing at your DA server

 

Here is what I have in DNS:

 

DNS.PNG

 

DNS2.PNG

Posted
Hi, I have added the DNS entries and went back through the infrastructure setup anbd ensured the certificate was added, and we have all greens on the ticks.Yay!!!!! Just need someone to test. Thanks for all the help.
Posted (edited)

Still not working, tried it at home yesterday. All the ticks are green in the operation status but I don't know enough about it, as I said no documentation was left for it.

 

The direct access VPN stays on connecting and the Get-daconnectionstatus is error could not contactdirectaccessserver

 

I have found I can ping the DA server when connecting to an external connection, but I just cannot do anything else.

Edited by Theldron
Posted

I have run the DirectAccess Client Troubleshooting tool:

Interface test is tick

IP Connectivty Tests failed

Windows Firewall Test and Certificate tests passed.

Infrastructure Tunnel and User Tunnel test failed.

Posted
On a laptop that uses direct access but isn't working externally, bring it into the workplace and do a group policy update on it, admin command prompt and type gpupdate /force this should update the laptop with the new certificate and then hopefully start working outside of the workplace. If this works then all other computers that require direct access will need to be updated via group policy.
Posted
Hi, we think we have figured out the issue. There was updates to our website and it looks like somebody has accidently deleted the record pointing to the direct access link. We are waiting for confirmation. Thanks everyone for their help.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...