Troubleshoot networking issues for DirectAccess server troubleshooting - Windows Server (2024)

  • Article

This article discusses how to troubleshoot network and high availability issues for DirectAccess Server console.

Network address translation (NAT) 64 issue

When a client receives the DNS AAAA record, it tries to establish a TCP connection to that IPv6-based network. The client talks to the NAT64 service that will be responsible for making the connection to the internal IPv4 address. NAT64 is always used by DirectAccess your DA server is running in an IPv4-based internal network.

NAT64: Not working properly
Error:
NAT64 translation failures might be preventing remote clients from accessing IPv4 only severs in the corporate network.

Cause

This issue can be caused by one of the following factors:

  • NAT64 is not enabled on the server.
  • The NAT64 server cannot be accessed.
  • NAT64 translation has failed.

Resolution

If you have a native ipv6 connection, make sure that the NAT64 or DNS64 prefix is configured in the DirectAccess settings.

In the Remote Server Setup Wizard, make sure that the default Name Resolution Policy Table(NRPT)entry points to the internal address of the NAT64 or DNS64 server.

The "NAT64 not working properly" error is the usual behavior if there are too many connections to a single server. An over-provisioned server cannot support every client communication, and the NAT64 engine has a hard-stop limit on simultaneous sessions or transactions. If the engine hits a warning threshold against that limit, this warning is displayed regularly.

Be sure to watch the CPU and memory usage numbers. If you believe that your server is getting close to tapping out, start making plans to add another DirectAccess server node.

You can also fix the issue momentarily by restarting the Remote Access server.

Also, check the Remote Access Server administrative channel event log. You should find messages that are related to the NAT64 moving from a WARNING to a HEALTHY state.

Alternatively, regarding the limit on the NAT64 connection, add double ports for NAT64 without lowering the number of ephemeral ports for the DirectAccess server itself. The ports can be used by either NAT or the server for its own tasks, but not by both.

The following command adds a second IP on the internal interface, and then configures NAT64 for both IPs:

Set-NetNatTransitionConfiguration –IPv4AddressPortPool @("xxx.xxxx.xxxx.xxxx, 10000-47000", "xxx.xxx.xxx.xxx, 10000-47000")

Network adapters issue

Network adapters-related error messages refer to the local network interfaces of the selected DirectAccess server:

Network adapters: Not working properly
Error:
The network adapters are either disconnected or disabled.

Cause

The specified network adapters are not enabled or not connected.

Resolution

To resolve this issue, follow these steps:

  1. Enable the network adapters by using the Network and Sharing Center in Control Panel (ncpa.cpl).
  2. Verify network connectivity on the network adapters.

Make sure that you also verify the Remote Access Server administrative channel event log. You should find messages related to the monitoring of network interfaces moving from an UNHEALTHY status to a HEALTHY status.

Network location server issue

You configure a Windows Server DirectAccess server to use an intranet-based Network Location Server (NLS). In this situation, you might notice that the operations status in the remote access management console indicates a critical problem that affects NLS. However, you can browse the NLS server from the DirectAccess server.

The DirectAccess server must be able to ping the NLS server in addition to being able to successfully connect to the NLS by using an HTTP GET. However, inbound Internet Control Message Protocol (ICMP) is often blocked on web servers. Therefore, the DirectAccess server tags the service as failed. The issue can be resolved by modifying the host firewall policy to allow inbound ICMPv4 echo requests.

Network security error

The reason for this warning is written in the Details section of the RA Monitor:

Network security: Not working properly
Error:
A network security component is under a spoofing attack.

You may see that many packets that have a bad security parameters index (SPI) have been received in a short amount of time. Also, you will see that this warning is intermittent.

Cause

Many packets that have bad SPIs within a short amount of time might indicate a packet spoofing attack.

Resolution

Monitor the server for signs of a spoofing attack. If an attack is detected, apply mitigation measures to stop it.

Some clients send ESP packets that have incorrect SPIs (outdated SAs) or the Load Balancer-forwarding Encapsulating Security Payload (ESP) packets that have an incorrect SPI. Run a wfpdiag trace to show what is occurring, and stop the attack based on event 10039 - Microsoft-Windows-RemoteAccess-RemoteAccessServer.

Adding more servers is also helpful.

High availability error

This error appears as the operation status only if you're setting up a high-availability solution by using Microsoft NLB or an external Load Balancer to load the traffic across two or more Direct Access servers.

If the default NLB deployment method is selected, and the DirectAccess server is deployed on a virtual machine that's running in Microsoft Hyper-V, make sure that you select the Enable MAC address spoofing option.

Troubleshoot networking issues for DirectAccess server troubleshooting - Windows Server (1)

Troubleshoot networking issues for DirectAccess server troubleshooting - Windows Server (2024)
Top Articles
What happened to the piggy bank? | Fandom
How To Know What To Expect When Selling Your Old Jewelry?
Netronline Taxes
Warren Ohio Craigslist
King Fields Mortuary
123 Movies Babylon
Locate Td Bank Near Me
Espn Expert Picks Week 2
Guardians Of The Galaxy Vol 3 Full Movie 123Movies
Robert Malone é o inventor da vacina mRNA e está certo sobre vacinação de crianças #boato
Betonnen afdekplaten (schoorsteenplaten) ter voorkoming van lekkage schoorsteen. - HeBlad
finaint.com
Walmart Double Point Days 2022
Mail.zsthost Change Password
Justified Official Series Trailer
Zack Fairhurst Snapchat
Welcome to GradeBook
Danforth's Port Jefferson
Healthier Homes | Coronavirus Protocol | Stanley Steemer - Stanley Steemer | The Steem Team
Lowes Undermount Kitchen Sinks
Espn Horse Racing Results
Timeforce Choctaw
If you have a Keurig, then try these hot cocoa options
Shadbase Get Out Of Jail
Cain Toyota Vehicles
Ihub Fnma Message Board
eugene bicycles - craigslist
Masterbuilt Gravity Fan Not Working
3 Ways to Drive Employee Engagement with Recognition Programs | UKG
Biografie - Geertjan Lassche
Publix Christmas Dinner 2022
FSA Award Package
Planned re-opening of Interchange welcomed - but questions still remain
Issue Monday, September 23, 2024
Kagtwt
9781644854013
Dying Light Nexus
Ktbs Payroll Login
8 Ball Pool Unblocked Cool Math Games
Dee Dee Blanchard Crime Scene Photos
Coroner Photos Timothy Treadwell
Kenner And Stevens Funeral Home
Breaking down the Stafford trade
Dyi Urban Dictionary
Kjccc Sports
Aurora Southeast Recreation Center And Fieldhouse Reviews
DL381 Delta Air Lines Estado de vuelo Hoy y Historial 2024 | Trip.com
Meee Ruh
Suppress Spell Damage Poe
Ravenna Greataxe
Dr Seuss Star Bellied Sneetches Pdf
Latest Posts
Article information

Author: Jeremiah Abshire

Last Updated:

Views: 6283

Rating: 4.3 / 5 (74 voted)

Reviews: 89% of readers found this page helpful

Author information

Name: Jeremiah Abshire

Birthday: 1993-09-14

Address: Apt. 425 92748 Jannie Centers, Port Nikitaville, VT 82110

Phone: +8096210939894

Job: Lead Healthcare Manager

Hobby: Watching movies, Watching movies, Knapping, LARPing, Coffee roasting, Lacemaking, Gaming

Introduction: My name is Jeremiah Abshire, I am a outstanding, kind, clever, hilarious, curious, hilarious, outstanding person who loves writing and wants to share my knowledge and understanding with you.