Quantcast
Channel: Forefront Edge Security – DirectAccess, UAG and IAG フォーラム
Viewing all articles
Browse latest Browse all 1485

Direct access 2012 connectivity filas but registered on DA server

$
0
0

Hi all

 Im trying to get my windows 8.1 client to connect to my newly built DirectAcesss server 2012.

 The Direct access server is configured and running with all checks passed. (2 nic configuration)

 Client log:

 [22/09/2015 09:55:39]: In worker thread, going to start the tests.
 [22/09/2015 09:55:39]: Running Network Interfaces tests.
 [22/09/2015 09:55:39]: Wi-Fi (Intel(R) Centrino(R) Advanced-N 6205): fe80::a8e3:6fcb:56e6:c870%4;: 10.200.1.91/255.255.255.0;
 [22/09/2015 09:55:39]: Default gateway found for Wi-Fi.
 [22/09/2015 09:55:39]: iphttpsinterface (iphttpsinterface): 2002:6e6e:6e03:1000:d90c:6a4b:b092:1a08;: 2002:6e6e:6e03:1000:edf0:3395:bddc:ed9e;: fe80::d90c:6a4b:b092:1a08%9;
 [22/09/2015 09:55:39]: No default gateway found for iphttpsinterface.
 [22/09/2015 09:55:39]: Wi-Fi has configured the default gateway 10.200.1.1.
 [22/09/2015 09:55:39]: Default gateway 10.200.1.1 for Wi-Fi replies on ICMP Echo requests, RTT is 2 msec.
 [22/09/2015 09:55:39]: Received a response from the public DNS server (8.8.8.8), RTT is 16 msec.
 [22/09/2015 09:55:39]: The public DNS Server (2001:4860:4860::8888) does not reply on ICMP Echo requests, the request or response is maybe filtered?
 [22/09/2015 09:55:39]: Running Inside/Outside location tests.
 [22/09/2015 09:55:39]: NLS is https://nls.domain.local/.
 [22/09/2015 09:55:39]: NLS is not reachable via HTTPS, the client computer is not connected to the corporate network (external) or the NLS is offline.
 [22/09/2015 09:55:39]: NRPT contains 2 rules.
 [22/09/2015 09:55:39]:        Found (unique) DNS server: 2002:6e6e:6e03:3333::1
 [22/09/2015 09:55:39]:        Send an ICMP message to check if the server is reachable.
 [22/09/2015 09:55:51]: DNS Server 2002:6e6e:6e03:3333::1 does not reply on ICMP Echo requests.
 [22/09/2015 09:55:51]: Running IP connectivity tests.
 [22/09/2015 09:55:51]: The 6to4 interface is enabled.
 [22/09/2015 09:55:51]: Teredo inferface status is offline.
 [22/09/2015 09:55:51]:       The configured DirectAccess Teredo server is win8.ipv6.microsoft.com..
 [22/09/2015 09:55:51]: The IPHTTPS interface is operational.
 [22/09/2015 09:55:51]:       The IPHTTPS interface status is IPHTTPS interface active.
 [22/09/2015 09:55:51]:       The configured IPHTTPS URL ishttps://da.emo-domain:443.
 [22/09/2015 09:55:51]: IPHTTPS has a single site configuration.
 [22/09/2015 09:55:51]: IPHTTPS URL endpoint is: https://da.emo-domain:443.
 [22/09/2015 09:55:51]:       Successfully connected to endpointhttps://da.emo-domain:443.
 [22/09/2015 09:55:51]: No response received from domain.local.
 [22/09/2015 09:55:51]: Running Windows Firewall tests.
 [22/09/2015 09:55:51]: The current profile of the Windows Firewall is Private.
 [22/09/2015 09:55:51]: The Windows Firewall is enabled in the current profile Private.
 [22/09/2015 09:55:51]: The outbound Windows Firewall rule Core Networking - Teredo (UDP-Out) is enabled.
 [22/09/2015 09:55:51]: The outbound Windows Firewall rule Core Networking - IPHTTPS (TCP-Out) is enabled.
 [22/09/2015 09:55:51]: Running certificate tests.
 [22/09/2015 09:55:51]: Found 1 machine certificates on this client computer.
 [22/09/2015 09:55:51]: Checking certificate CN=mizlt458.domain.local with the serial number [serial].
 [22/09/2015 09:55:51]:       The certificate [serial] contains the EKU Client Authentication.
 [22/09/2015 09:55:51]:       The trust chain for the certificate [serial] was sucessfully verified.
 [22/09/2015 09:55:51]: Running IPsec infrastructure tunnel tests.
 [22/09/2015 09:55:51]: Failed to connect to domain sysvol share \\domain.local\sysvol\domain.local\Policies.
 [22/09/2015 09:55:51]: Running IPsec intranet tunnel tests.
 [22/09/2015 09:55:51]: Successfully reached 2002:6e6e:6e03::6e6e:6e03, RTT is 18 msec.
 [22/09/2015 09:56:03]: Failed to connect to 2002:6e6e:6e03:5::1 with status TimedOut.
 [22/09/2015 09:56:03]: Failed to connect to HTTP probe at http://directaccess-WebProbeHost.domain.local.
 [22/09/2015 09:56:03]: Running selected post-checks script.
 [22/09/2015 09:56:03]: No post-checks script specified or the file does not exist.
 [22/09/2015 09:56:03]: Finished running post-checks script.
 [22/09/2015 09:56:03]: Finished running all tests.


 netsh namespace show policy:

 DNS Name Resolution Policy Table Settings


 Settings for nls.domain-eu.local
 ----------------------------------------------------------------------
 DNSSEC (Certification Authority)        :
 DNSSEC (Validation)                     : disabled
 DNSSEC (IPsec)                          : disabled
 DirectAccess (Certification Authority)  :
 DirectAccess (DNS Servers)              :
 DirectAccess (IPsec)                    : disabled
 DirectAccess (Proxy Settings)           : Use default browser settings
 Generic (DNS Servers)                   :
 Generic (VPN Trigger)                   : disabled
 IDN (Encoding)                          : UTF-8 (default)


 Settings for .domain-eu.local
 ----------------------------------------------------------------------
 DNSSEC (Certification Authority)        :
 DNSSEC (Validation)                     : disabled
 DNSSEC (IPsec)                          : disabled
 DirectAccess (Certification Authority)  :
 DirectAccess (DNS Servers)              : 2002:6e6e:6e03:3333::1
 DirectAccess (IPsec)                    : disabled
 DirectAccess (Proxy Settings)           : Bypass proxy
 Generic (DNS Servers)                   :
 Generic (VPN Trigger)                   : disabled
 IDN (Encoding)                          : UTF-8 (default)

 netsh namespace show effective:

 DNS Effective Name Resolution Policy Table Settings


 Settings for nls.domain-eu.local
 ----------------------------------------------------------------------
 DirectAccess (Certification Authority)  :
 DirectAccess (IPsec)                    : disabled
 DirectAccess (DNS Servers)              :
 DirectAccess (Proxy Settings)           : Use default browser settings


 Settings for .domain-eu.local
 ----------------------------------------------------------------------
 DirectAccess (Certification Authority)  :
 DirectAccess (IPsec)                    : disabled
 DirectAccess (DNS Servers)              : 2002:6e6e:6e03:3333::1
 DirectAccess (Proxy Settings)           : Bypass proxy


 Ipconfig:

 Microsoft Windows [Version 6.3.9600]
 (c) 2013 Microsoft Corporation. All rights reserved.

 C:\Users\adminbarnes>netsh namespace show policy

 DNS Name Resolution Policy Table Settings


 Settings for nls.mizuno-eu.local
 ----------------------------------------------------------------------
 DNSSEC (Certification Authority)        :
 DNSSEC (Validation)                     : disabled
 DNSSEC (IPsec)                          : disabled
 DirectAccess (Certification Authority)  :
 DirectAccess (DNS Servers)              :
 DirectAccess (IPsec)                    : disabled
 DirectAccess (Proxy Settings)           : Use default browser settings
 Generic (DNS Servers)                   :
 Generic (VPN Trigger)                   : disabled
 IDN (Encoding)                          : UTF-8 (default)


 Settings for .mizuno-eu.local
 ----------------------------------------------------------------------
 DNSSEC (Certification Authority)        :
 DNSSEC (Validation)                     : disabled
 DNSSEC (IPsec)                          : disabled
 DirectAccess (Certification Authority)  :
 DirectAccess (DNS Servers)              : 2002:6e6e:6e03:3333::1
 DirectAccess (IPsec)                    : disabled
 DirectAccess (Proxy Settings)           : Bypass proxy
 Generic (DNS Servers)                   :
 Generic (VPN Trigger)                   : disabled
 IDN (Encoding)                          : UTF-8 (default)

 C:\Users\adminbarnes>netsh namespace show effective

 DNS Effective Name Resolution Policy Table Settings


 Settings for nls.mizuno-eu.local
 ----------------------------------------------------------------------
 DirectAccess (Certification Authority)  :
 DirectAccess (IPsec)                    : disabled
 DirectAccess (DNS Servers)              :
 DirectAccess (Proxy Settings)           : Use default browser settings


 Settings for .mizuno-eu.local
 ----------------------------------------------------------------------
 DirectAccess (Certification Authority)  :
 DirectAccess (IPsec)                    : disabled
 DirectAccess (DNS Servers)              : 2002:6e6e:6e03:3333::1
 DirectAccess (Proxy Settings)           : Bypass proxy

 Windows IP Configuration

    Host Name . . . . . . . . . . . . : mizlt458
    Primary Dns Suffix  . . . . . . . : domain.local
    Node Type . . . . . . . . . . . . : Hybrid
    IP Routing Enabled. . . . . . . . : No
    WINS Proxy Enabled. . . . . . . . : No
    DNS Suffix Search List. . . . . . : domain.local

 Wireless LAN adapter Local Area Connection* 2:

    Media State . . . . . . . . . . . : Media disconnected
    Connection-specific DNS Suffix  . :
    Description . . . . . . . . . . . : Microsoft Wi-Fi Direct Virtual Adapter
    Physical Address. . . . . . . . . : 08-11-96-80-47-75
    DHCP Enabled. . . . . . . . . . . : Yes
    Autoconfiguration Enabled . . . . : Yes

 Wireless LAN adapter Wi-Fi:

    Connection-specific DNS Suffix  . :
    Description . . . . . . . . . . . : Intel(R) Centrino(R) Advanced-N 6205
    Physical Address. . . . . . . . . : 08-11-96-80-47-74
    DHCP Enabled. . . . . . . . . . . : Yes
    Autoconfiguration Enabled . . . . : Yes
    Link-local IPv6 Address . . . . . : fe80::a8e3:6fcb:56e6:c870%4(Preferred)
    IPv4 Address. . . . . . . . . . . : 10.200.1.91(Preferred)
    Subnet Mask . . . . . . . . . . . : 255.255.255.0
    Lease Obtained. . . . . . . . . . : 22 September 2015 09:39:26
    Lease Expires . . . . . . . . . . : 23 September 2015 10:25:00
    Default Gateway . . . . . . . . . : 10.200.1.1
    DHCP Server . . . . . . . . . . . : 10.200.1.1
    DHCPv6 IAID . . . . . . . . . . . : 67637654
    DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1D-8E-5F-0E-5C-26-0A-88-7B-FA

    DNS Servers . . . . . . . . . . . : 194.168.4.100
                                        194.168.8.100
    NetBIOS over Tcpip. . . . . . . . : Enabled

 Ethernet adapter Ethernet:

    Media State . . . . . . . . . . . : Media disconnected
    Connection-specific DNS Suffix  . : domain.local
    Description . . . . . . . . . . . : Intel(R) 82579LM Gigabit Network Connecti
 on
    Physical Address. . . . . . . . . : 5C-26-0A-88-7B-FA
    DHCP Enabled. . . . . . . . . . . : Yes
    Autoconfiguration Enabled . . . . : Yes

 Tunnel adapter isatap.{ABC7C9ED-8C92-4CCB-8}:

    Media State . . . . . . . . . . . : Media disconnected
    Connection-specific DNS Suffix  . :
    Description . . . . . . . . . . . : Microsoft ISATAP Adapter #2
    Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
    DHCP Enabled. . . . . . . . . . . : No
    Autoconfiguration Enabled . . . . : Yes

 Tunnel adapter iphttpsinterface:

    Connection-specific DNS Suffix  . :
    Description . . . . . . . . . . . : iphttpsinterface
    Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
    DHCP Enabled. . . . . . . . . . . : No
    Autoconfiguration Enabled . . . . : Yes
    IPv6 Address. . . . . . . . . . . : 2002:6e6e:6e03:1000:d90c:(P
 referred)
    Temporary IPv6 Address. . . . . . : 2002:6e6e:6e03:1000:edf0:3395:bddc:ed9e(P
 referred)
    Link-local IPv6 Address . . . . . : fe80::d90c:6a4b:(Preferred)
    Default Gateway . . . . . . . . . :
    DHCPv6 IAID . . . . . . . . . . . : 352321536
    DHCPv6 Client DUID. . . . . . . . : 00-01-00-01-1D-8E-5F-
   NetBIOS over Tcpip. . . . . . . . : Disabled

 Tunnel adapter 6TO4 Adapter:

    Media State . . . . . . . . . . . : Media disconnected
    Connection-specific DNS Suffix  . :
    Description . . . . . . . . . . . : Microsoft 6to4 Adapter
    Physical Address. . . . . . . . . : 00-00-00-00-00-00-00-E0
    DHCP Enabled. . . . . . . . . . . : No
    Autoconfiguration Enabled . . . . : Yes


matt barnes


Viewing all articles
Browse latest Browse all 1485

Trending Articles