jhothersall Posted March 23, 2020 Posted March 23, 2020 Morning All, As you can imagine today we have gone from having maximum of 20 DirectAccess connections to over 40, we are having issues. I think it is one of 2 things, either the firewall at the LEA is stopping this many connection (it goes from my school website hostname to our server on-site). Or it is one of these errors - “Network Security monitor has gone from HEALTHY state to WARNING state on 23/03/2020 at 08:53 on SHU-DA01. The failure heuristic IDs for state change of Network Security are 80040006.” This is now back to HEALTHY but I am seeing this error is event viewer too. Or this screenshot. Would be great, if anyone could give us any guidance. Thanks James
jhothersall Posted March 24, 2020 Author Posted March 24, 2020 We did get some help from the original installer removing the old TLS versions but now getting this error ... The joys of DirectAccess..
KenZ Posted April 15, 2020 Posted April 15, 2020 Hi there are some known issues with using IKE/IPSec tunnels used by DirectAccess and NAT firewalls, and one of those is with SPIs (e.g. https://www.networkworld.com/article/2288666/chapter-4--common-ipsec-vpn-issues.html?page=6) My view would be that with the increased number of users using DirectAccess via your LEAs firewall, this has caused additional event log messages which has triggered the DA console to generate this warning. There may be a way to either increase the threshold before this generates the warning (only putting off the issue) or disabling the warning altogether. Regards Ken
chazzy2501 Posted April 15, 2020 Posted April 15, 2020 SAME, my DA server caps out at around 35 users... after that clients just sit there connecting. I only use iphttps. I asked swgfl if there were connection limits through the NAT and they stated that there is not.
jhothersall Posted April 21, 2020 Author Posted April 21, 2020 We have got this fixed, the issue is the TLS Setting on the server - We have had over 50+ with no issues. Our 3rd party used IISCrypto.exe to disable older SSL Protocols - https://www.nartac.com/Products/IISCrypto/ I think this will help you (look at the comments)- https://directaccess.richardhicks.com/2017/06/26/directaccess-reporting-fails-and-schannel-event-id-36871-after-disabling-tls-1-0/ we still get Event ID 36874 but no issues with DirectAccess. Before you do anything make a save state on your Hyper-V ...
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now