Forum Discussion
kiml01_143042
Nimbostratus
Jun 03, 2014Allow agent: Logon denied due to validation error, Error Code: 3003 (No Network Access resource assigned)
We have one F5 SSL VPN user who is having his second round of trouble getting logged in.
We use LDAP to query AD for group membership, and allow access based on that.
the most relevant erro...
David_Stout
Nimbostratus
Jun 04, 2014Couple of things to check along the lines of issues I've had to resolve in the past. Not sure if these are relevant but they may help get you started.
- Password didn't expire or is set to be changed on next log in.
- The sAMAccountName is only returning LDAP attributes for a single domain account not multiple domain accounts
- Nested groups are not used
- Testing against LDAP using the LDP tool returns the correct result from AD
You can use the inbuilt LDAPSEARCH tool as well as LDP to query AD for groupmembership. This is the syntax i use
ldapsearch -xLLL -H 'ldap://X.X.X.X:3268' -b "dc=XXXXXX,dc=com" -s sub -D "" -w "(sAMAccountName=xxxxxxx)"
Hope that helps you get to the bottom of it.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
DevCentral Quicklinks
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com
Discover DevCentral Connects