Kerberos Authentication Blocked

Microsoft.Windows.RemoteAccess.Monitor.DA_KERB_HEURISTIC_AUTH (UnitMonitor)


Ports required for Kerberos authentication are blocked. Kerberos authentication is required to authenticate clients using Kerberos proxy on this server. \
For clients to communicate with the proxy, firewalls must allow HTTPS traffic (port 443 by default). The Kerberos proxy must be able to send Kerberos authentication protocol traffic via port 88, and Kerberos change password protocol traffic via port 464 to domain controllers.

Knowledge Base article:

Summary

Ports required for Kerberos authentication are blocked. Kerberos authentication is required to authenticate clients using Kerberos proxy on this server. For clients to communicate with the proxy, firewalls must allow HTTPS traffic (port 443 by default). The Kerberos proxy must be able to send Kerberos authentication protocol traffic via port 88, and Kerberos change password protocol traffic via port 464 to domain controllers.

Causes

1. Port 443 or the HTTPS protocol is blocked on the Remote Access server.

2. Port 88 or 464 is blocked on the Remote Access server.

Resolutions

1. Ensure that port 443 and the HTTPS protocol are not blocked.

2. Ensure that Port 88 and port 464 is not blocked on the Remote Access server, or on domain controllers.

Element properties:

TargetMicrosoft.Windows.RemoteAccess.DirectAccessServer.Class
Parent MonitorSystem.Health.AvailabilityState
CategoryCustom
EnabledTrue
Alert GenerateTrue
Alert SeverityError
Alert PriorityNormal
Alert Auto ResolveTrue
Monitor TypeMicrosoft.Windows.RemoteAccess.Monitor.Heuristic.MonitorType
RemotableTrue
AccessibilityPublic
Alert Message
Kerberos authentication blocked

Error Description - {0}
Error Cause - {1}
Error Resolution - {2}
RunAsDefault