Incorrect or Unreachable Authentication Server for Mobile VPN with SSL

Applies To: Cloud-managed Fireboxes, Locally-managed Fireboxes

When you configure Mobile VPN with SSL, you specify the authentication server or servers you want to use for Mobile VPN with SSL user authentication. If the server specified is incorrect or unreachable, valid Mobile VPN with SSL users cannot authenticate.

Symptoms

When Mobile VPN with SSL is configured with an incorrect or unreachable authentication server, you might notice these symptoms:

  • Users cannot connect to the VPN despite valid credentials and group membership.
  • Firebox log messages show authentication attempts to an unexpected server.
  • admd log messages on the Firebox show authentication failures (user not in right group) if groups belong to a different server.
  • admd log messages on the Firebox show that requests time out or that the server does not respond to requests. Examples:
    • admd Authentication server x.x.x.x:1812 is not responding msg_id="1100-0003"
    • admd Authentication of SSLVPN user [user@RADIUS] from x.x.x.x was rejected, Recv timeout msg_id="1100-0005"
    • admd Authentication of SSLVPN user [[email protected]] from x.x.x.x was rejected, server is down or unreachable msg_id="1100-0005"

Diagnostic Steps

  1. In the Mobile VPN with SSL configuration, verify that the intended authentication server or servers are specified.
  2. If multiple authentication servers are specified, verify the default server. If users need to connect to a non-default server, they must specify the server in the Username text box when they connect.
  3. Verify that the server is reachable from the Firebox.

Possible Causes and Solutions

Possible Cause Solution
An incorrect authentication server is specified in the Mobile VPN with SSL configuration.

Update the authentication servers in the Mobile VPN with SSL configuration. For more information, go to:

Locally-managed: Manually Configure the Firebox for Mobile VPN with SSL

Cloud-Managed: Configure Mobile VPN with SSL for a Cloud-Managed Firebox

Users omit the authentication server in the Username text box when they try to connect to a non-default server.

The Mobile VPN with SSL client uses the default authentication server unless a user specifies an authentication server in the Username text box on the Mobile VPN with SSL client. To specify an authentication server in the Username text box, use the format of ad1_example.com\j_smith. For more information, go to:

Locally-Managed: Download, Install, and Connect the Mobile VPN with SSL Client

Cloud-Managed: Download, Install, and Connect the Mobile VPN with SSL Client

The authentication server is down or unreachable from the Firebox.

Verify that the authentication server is online and that the Firebox can reach the server. Resolve any issues with server health, routing, DNS, or firewall policies that prevent connection to the server on the required ports.

For information about how to test connectivity from a locally-managed Firebox to an Active Directory or LDAP server, go to Server Connection.

For more information about how to verify connectivity, go to Troubleshoot Network Connectivity.

Related Topics

Troubleshoot Mobile VPN with SSL

About Mobile VPN with SSL