TS Gateway Network access Policy engine received failure from IAS and the error was "16388"Hello,<br> <br> I'm not sure if this is more appropriate here, or in the Network Access Protection forum...<br> <br> When I try to connect to my Terminal Services server through my TS Gateway I get the following two events logged on the TS Gateway:<br> <br> Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational<br> Source:        Microsoft-Windows-TerminalServices-Gateway<br> Date:          10/24/2008 8:26:47 AM<br> Event ID:      641<br> Task Category: (4)<br> Level:         Error<br> Keywords:      (33554432)<br> User:          NETWORK SERVICE<br> Computer:      $TS_GATEWAY_NAME<br> Description:<br> TS Gateway Network access Policy engine received failure from IAS and the error was &quot;16388&quot;<br> Event Xml:<br> &lt;Event xmlns=&quot;http://schemas.microsoft.com/win/2004/08/events/event&quot;&gt;<br>   &lt;System&gt;<br>     &lt;Provider Name=&quot;Microsoft-Windows-TerminalServices-Gateway&quot; Guid=&quot;{4d5ae6a1-c7c8-4e6d-b840-4d8080b42e1b}&quot; /&gt;<br>     &lt;EventID&gt;641&lt;/EventID&gt;<br>     &lt;Version&gt;0&lt;/Version&gt;<br>     &lt;Level&gt;2&lt;/Level&gt;<br>     &lt;Task&gt;4&lt;/Task&gt;<br>     &lt;Opcode&gt;22&lt;/Opcode&gt;<br>     &lt;Keywords&gt;0x4000000002000000&lt;/Keywords&gt;<br>     &lt;TimeCreated SystemTime=&quot;2008-10-24T14:26:47.651Z&quot; /&gt;<br>     &lt;EventRecordID&gt;443&lt;/EventRecordID&gt;<br>     &lt;Correlation /&gt;<br>     &lt;Execution ProcessID=&quot;348&quot; ThreadID=&quot;3744&quot; /&gt;<br>     &lt;Channel&gt;Microsoft-Windows-TerminalServices-Gateway/Operational&lt;/Channel&gt;<br>     &lt;Computer&gt;$TS_GATEWAY_FQDN&lt;/Computer&gt;<br>     &lt;Security UserID=&quot;S-1-5-20&quot; /&gt;<br>   &lt;/System&gt;<br>   &lt;UserData&gt;<br>     &lt;EventInfo xmlns=&quot;aag&quot;&gt;<br>       &lt;Name&gt;<br>       &lt;/Name&gt;<br>       &lt;ErrorCode&gt;16388&lt;/ErrorCode&gt;<br>     &lt;/EventInfo&gt;<br>   &lt;/UserData&gt;<br> &lt;/Event&gt;<br> <br> Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational<br> Source:        Microsoft-Windows-TerminalServices-Gateway<br> Date:          10/24/2008 8:26:47 AM<br> Event ID:      201<br> Task Category: (2)<br> Level:         Error<br> Keywords:      Audit Failure,(16777216)<br> User:          NETWORK SERVICE<br> Computer:      $TS_GATEWAY_NAME<br> Description:<br> The user &quot;$USER_NAME&quot;, on client computer &quot;$COMPUTER_IP&quot;, did not meet connection authorization policy requirements and was therefore not authorized to access the TS Gateway server. The following authentication method was attempted: &quot;NTLM&quot;. The following error occurred: &quot;23003&quot;.<br> Event Xml:<br> &lt;Event xmlns=&quot;http://schemas.microsoft.com/win/2004/08/events/event&quot;&gt;<br>   &lt;System&gt;<br>     &lt;Provider Name=&quot;Microsoft-Windows-TerminalServices-Gateway&quot; Guid=&quot;{4d5ae6a1-c7c8-4e6d-b840-4d8080b42e1b}&quot; /&gt;<br>     &lt;EventID&gt;201&lt;/EventID&gt;<br>     &lt;Version&gt;0&lt;/Version&gt;<br>     &lt;Level&gt;2&lt;/Level&gt;<br>     &lt;Task&gt;2&lt;/Task&gt;<br>     &lt;Opcode&gt;30&lt;/Opcode&gt;<br>     &lt;Keywords&gt;0x4010000001000000&lt;/Keywords&gt;<br>     &lt;TimeCreated SystemTime=&quot;2008-10-24T14:26:47.651Z&quot; /&gt;<br>     &lt;EventRecordID&gt;444&lt;/EventRecordID&gt;<br>     &lt;Correlation /&gt;<br>     &lt;Execution ProcessID=&quot;348&quot; ThreadID=&quot;3744&quot; /&gt;<br>     &lt;Channel&gt;Microsoft-Windows-TerminalServices-Gateway/Operational&lt;/Channel&gt;<br>     &lt;Computer&gt;$TS_GATEWAY_FQDN&lt;/Computer&gt;<br>     &lt;Security UserID=&quot;S-1-5-20&quot; /&gt;<br>   &lt;/System&gt;<br>   &lt;UserData&gt;<br>     &lt;EventInfo xmlns=&quot;aag&quot;&gt;<br>       &lt;Username&gt;$USER_NAME&lt;/Username&gt;<br>       &lt;IpAddress&gt;$CLIENT_IP_ADDRESS&lt;/IpAddress&gt;<br>       &lt;AuthType&gt;NTLM&lt;/AuthType&gt;<br>       &lt;Resource&gt;<br>       &lt;/Resource&gt;<br>       &lt;ErrorCode&gt;23003&lt;/ErrorCode&gt;<br>     &lt;/EventInfo&gt;<br>   &lt;/UserData&gt;<br> &lt;/Event&gt;<br> <br> <br> The TS Gateway is a Server 2008 machine, the Terminal Services server is a Server 2008 machines, the client is Windows XP SP3<br> <br> Here's the rub, the computer belongs to another domain.  The computer is owned by another department within our larger infrastructure, it is in the same forest.  I do not have any TS RAPs applied at this moment; and, it doesn't even look like it's getting far enough for the SoH to be analyzed.<br> <br> I cannot find absolutely anything online about the ' TS Gateway Network access Policy engine received failure from IAS and the error was &quot;16388&quot; ' error; besides <a href="http://technet.microsoft.com/en-us/library/cc775154.aspx">this technet discription of the error</a>.<br><br>So, I really don't know where to look for more information.<br>© 2009 Microsoft Corporation. All rights reserved.Fri, 16 Oct 2009 18:52:23 Z092a427c-3609-43bc-9a8b-23616970b45ehttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#092a427c-3609-43bc-9a8b-23616970b45ehttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#092a427c-3609-43bc-9a8b-23616970b45emoomanXhttp://social.technet.microsoft.com/Profile/en-US/?user=moomanXTS Gateway Network access Policy engine received failure from IAS and the error was "16388"Hello,<br> <br> I'm not sure if this is more appropriate here, or in the Network Access Protection forum...<br> <br> When I try to connect to my Terminal Services server through my TS Gateway I get the following two events logged on the TS Gateway:<br> <br> Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational<br> Source:        Microsoft-Windows-TerminalServices-Gateway<br> Date:          10/24/2008 8:26:47 AM<br> Event ID:      641<br> Task Category: (4)<br> Level:         Error<br> Keywords:      (33554432)<br> User:          NETWORK SERVICE<br> Computer:      $TS_GATEWAY_NAME<br> Description:<br> TS Gateway Network access Policy engine received failure from IAS and the error was &quot;16388&quot;<br> Event Xml:<br> &lt;Event xmlns=&quot;http://schemas.microsoft.com/win/2004/08/events/event&quot;&gt;<br>   &lt;System&gt;<br>     &lt;Provider Name=&quot;Microsoft-Windows-TerminalServices-Gateway&quot; Guid=&quot;{4d5ae6a1-c7c8-4e6d-b840-4d8080b42e1b}&quot; /&gt;<br>     &lt;EventID&gt;641&lt;/EventID&gt;<br>     &lt;Version&gt;0&lt;/Version&gt;<br>     &lt;Level&gt;2&lt;/Level&gt;<br>     &lt;Task&gt;4&lt;/Task&gt;<br>     &lt;Opcode&gt;22&lt;/Opcode&gt;<br>     &lt;Keywords&gt;0x4000000002000000&lt;/Keywords&gt;<br>     &lt;TimeCreated SystemTime=&quot;2008-10-24T14:26:47.651Z&quot; /&gt;<br>     &lt;EventRecordID&gt;443&lt;/EventRecordID&gt;<br>     &lt;Correlation /&gt;<br>     &lt;Execution ProcessID=&quot;348&quot; ThreadID=&quot;3744&quot; /&gt;<br>     &lt;Channel&gt;Microsoft-Windows-TerminalServices-Gateway/Operational&lt;/Channel&gt;<br>     &lt;Computer&gt;$TS_GATEWAY_FQDN&lt;/Computer&gt;<br>     &lt;Security UserID=&quot;S-1-5-20&quot; /&gt;<br>   &lt;/System&gt;<br>   &lt;UserData&gt;<br>     &lt;EventInfo xmlns=&quot;aag&quot;&gt;<br>       &lt;Name&gt;<br>       &lt;/Name&gt;<br>       &lt;ErrorCode&gt;16388&lt;/ErrorCode&gt;<br>     &lt;/EventInfo&gt;<br>   &lt;/UserData&gt;<br> &lt;/Event&gt;<br> <br> Log Name:      Microsoft-Windows-TerminalServices-Gateway/Operational<br> Source:        Microsoft-Windows-TerminalServices-Gateway<br> Date:          10/24/2008 8:26:47 AM<br> Event ID:      201<br> Task Category: (2)<br> Level:         Error<br> Keywords:      Audit Failure,(16777216)<br> User:          NETWORK SERVICE<br> Computer:      $TS_GATEWAY_NAME<br> Description:<br> The user &quot;$USER_NAME&quot;, on client computer &quot;$COMPUTER_IP&quot;, did not meet connection authorization policy requirements and was therefore not authorized to access the TS Gateway server. The following authentication method was attempted: &quot;NTLM&quot;. The following error occurred: &quot;23003&quot;.<br> Event Xml:<br> &lt;Event xmlns=&quot;http://schemas.microsoft.com/win/2004/08/events/event&quot;&gt;<br>   &lt;System&gt;<br>     &lt;Provider Name=&quot;Microsoft-Windows-TerminalServices-Gateway&quot; Guid=&quot;{4d5ae6a1-c7c8-4e6d-b840-4d8080b42e1b}&quot; /&gt;<br>     &lt;EventID&gt;201&lt;/EventID&gt;<br>     &lt;Version&gt;0&lt;/Version&gt;<br>     &lt;Level&gt;2&lt;/Level&gt;<br>     &lt;Task&gt;2&lt;/Task&gt;<br>     &lt;Opcode&gt;30&lt;/Opcode&gt;<br>     &lt;Keywords&gt;0x4010000001000000&lt;/Keywords&gt;<br>     &lt;TimeCreated SystemTime=&quot;2008-10-24T14:26:47.651Z&quot; /&gt;<br>     &lt;EventRecordID&gt;444&lt;/EventRecordID&gt;<br>     &lt;Correlation /&gt;<br>     &lt;Execution ProcessID=&quot;348&quot; ThreadID=&quot;3744&quot; /&gt;<br>     &lt;Channel&gt;Microsoft-Windows-TerminalServices-Gateway/Operational&lt;/Channel&gt;<br>     &lt;Computer&gt;$TS_GATEWAY_FQDN&lt;/Computer&gt;<br>     &lt;Security UserID=&quot;S-1-5-20&quot; /&gt;<br>   &lt;/System&gt;<br>   &lt;UserData&gt;<br>     &lt;EventInfo xmlns=&quot;aag&quot;&gt;<br>       &lt;Username&gt;$USER_NAME&lt;/Username&gt;<br>       &lt;IpAddress&gt;$CLIENT_IP_ADDRESS&lt;/IpAddress&gt;<br>       &lt;AuthType&gt;NTLM&lt;/AuthType&gt;<br>       &lt;Resource&gt;<br>       &lt;/Resource&gt;<br>       &lt;ErrorCode&gt;23003&lt;/ErrorCode&gt;<br>     &lt;/EventInfo&gt;<br>   &lt;/UserData&gt;<br> &lt;/Event&gt;<br> <br> <br> The TS Gateway is a Server 2008 machine, the Terminal Services server is a Server 2008 machines, the client is Windows XP SP3<br> <br> Here's the rub, the computer belongs to another domain.  The computer is owned by another department within our larger infrastructure, it is in the same forest.  I do not have any TS RAPs applied at this moment; and, it doesn't even look like it's getting far enough for the SoH to be analyzed.<br> <br> I cannot find absolutely anything online about the ' TS Gateway Network access Policy engine received failure from IAS and the error was &quot;16388&quot; ' error; besides <a href="http://technet.microsoft.com/en-us/library/cc775154.aspx">this technet discription of the error</a>.<br><br>So, I really don't know where to look for more information.<br>Fri, 24 Oct 2008 18:52:44 Z2008-10-24T18:53:28Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#887560fc-398e-4f0e-98bf-e4cb2b088c1dhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#887560fc-398e-4f0e-98bf-e4cb2b088c1dVikash Buchahttp://social.technet.microsoft.com/Profile/en-US/?user=Vikash%20BuchaTS Gateway Network access Policy engine received failure from IAS and the error was "16388" The feature team is looking into this issue. I will get back to you once we find anything<br><br>Thanks,<br>VikashMon, 27 Oct 2008 07:14:01 Z2008-10-27T07:14:01Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#b308f83d-5289-4181-adba-5953aba3ec57http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#b308f83d-5289-4181-adba-5953aba3ec57moomanXhttp://social.technet.microsoft.com/Profile/en-US/?user=moomanXTS Gateway Network access Policy engine received failure from IAS and the error was "16388"Eeerp!<br><br>My bad, I never ran tsgqecclientconfig.cmd on this client... Thus, it was Non-NAP Capable; I don't know how/if that error correlates, but there you go.<br><br>There's still this issue of being in a different domain.  For some reason the TS Gateway tries to contact the computer's domain; even though there is no computer-based authentication happening(?), it should just be authenticating the user that is part of my domain, right?<br><br>Anyway, can probably close this.<br> Mon, 27 Oct 2008 17:20:57 Z2008-10-27T17:20:57Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#d9f0d82e-a776-4d16-a1b6-6de10dee3a62http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#d9f0d82e-a776-4d16-a1b6-6de10dee3a62moomanXhttp://social.technet.microsoft.com/Profile/en-US/?user=moomanXTS Gateway Network access Policy engine received failure from IAS and the error was "16388"Alright, I was going to come in here and close ('Mark as Answer') this; but, this is odd...<br><br>I'm receiving those same two errors in the Terminal Services events whenever I attempt to log on.<br><br>The client Disconnects from Remote Desktop with the following message:<br>Terminal Services connection authorization policy (TS CAP) is preventing connection to the remote computer through TS Gateway, possibly due to one of the following reasons:  You do not have permission to connect to the TS Gateway server.  You used password authentication but the TS Gateway server is expecting smart card authentication (or vice versa).  Contact your administrator for further assistance.<br><br>On the NPS side I get the following three events when I attempt to log on:<br><br>Log Name:      System<br>Source:        NPS<br>Date:          10/27/2008 12:52:05 PM<br>Event ID:      4402<br>Task Category: None<br>Level:         Error<br>Keywords:      Classic<br>User:          N/A<br>Computer:      $TS_GATEWAY_FQDN<br>Description:<br>There is no domain controller available for domain $OTHER_DOMAIN_NAME.<br>Event Xml:<br>&lt;Event xmlns=&quot;http://schemas.microsoft.com/win/2004/08/events/event&quot;&gt;<br>  &lt;System&gt;<br>    &lt;Provider Name=&quot;NPS&quot; /&gt;<br>    &lt;EventID Qualifiers=&quot;49152&quot;&gt;4402&lt;/EventID&gt;<br>    &lt;Level&gt;2&lt;/Level&gt;<br>    &lt;Task&gt;0&lt;/Task&gt;<br>    &lt;Keywords&gt;0x80000000000000&lt;/Keywords&gt;<br>    &lt;TimeCreated SystemTime=&quot;2008-10-27T18:52:05.000Z&quot; /&gt;<br>    &lt;EventRecordID&gt;3702&lt;/EventRecordID&gt;<br>    &lt;Channel&gt;System&lt;/Channel&gt;<br>    &lt;Computer&gt;$TS_GATEWAY_FQDN&lt;/Computer&gt;<br>    &lt;Security /&gt;<br>  &lt;/System&gt;<br>  &lt;EventData&gt;<br>    &lt;Data&gt;HFS&lt;/Data&gt;<br>  &lt;/EventData&gt;<br>&lt;/Event&gt;<br><br>Log Name:      Security<br>Source:        Microsoft-Windows-Security-Auditing<br>Date:          10/27/2008 12:52:05 PM<br>Event ID:      6272<br>Task Category: Network Policy Server<br>Level:         Information<br>Keywords:      Audit Success<br>User:          N/A<br>Computer:      $TS_GATEWAY_FQDN<br>Description:<br><b>Network Policy Server granted access to a user.</b><br><br>User:<br>    Security ID:            NULL SID<br>    Account Name:            $DOMAIN\ACCOUNT_NAME<br>    Account Domain:            $DOMAIN<br>    Fully Qualified Account Name:    $DOMAIN\ACCOUNT_NAME<br><br>Client Machine:<br>    Security ID:            NULL SID<br>    Account Name:            $COMPUTER_FQDN(different domain than one I am attempting to connect to)<br>    Fully Qualified Account Name:    $COMPUTER_FQDN<br>    OS-Version:            5.1.2600 3.0 x86 Domain Controller <br>    Called Station Identifier:        UserAuthType:PW<br>    Calling Station Identifier:        -<br><br>NAS:<br>    NAS IPv4 Address:        -<br>    NAS IPv6 Address:        -<br>    NAS Identifier:            -<br>    NAS Port-Type:            Virtual <br>    NAS Port:            -<br><br>RADIUS Client:<br>    Client Friendly Name:        -<br>    Client IP Address:            -<br><br>Authentication Details:<br>    Proxy Policy Name:        NAP TS Gateway<br>    Network Policy Name:        NAP TS Gateway Compliant<br>    Authentication Provider:        Windows <br>    Authentication Server:        $TS_GATEWAY_FQDN<br>    Authentication Type:        Unauthenticated <br>    EAP Type:            -<br>    Account Session Identifier:        -<br><br>Quarantine Information:<br>    Result:                Full Access <br>    Session Identifier:            {A1FC7E35-8827-4BC4-86D2-920E2A4FFCBC} - 2008-10-27 18:51:34.656Z<br><br>Event Xml:<br>&lt;Event xmlns=&quot;http://schemas.microsoft.com/win/2004/08/events/event&quot;&gt;<br>  &lt;System&gt;<br>    &lt;Provider Name=&quot;Microsoft-Windows-Security-Auditing&quot; Guid=&quot;{54849625-5478-4994-a5ba-3e3b0328c30d}&quot; /&gt;<br>    &lt;EventID&gt;6272&lt;/EventID&gt;<br>    &lt;Version&gt;0&lt;/Version&gt;<br>    &lt;Level&gt;0&lt;/Level&gt;<br>    &lt;Task&gt;12552&lt;/Task&gt;<br>    &lt;Opcode&gt;0&lt;/Opcode&gt;<br>    &lt;Keywords&gt;0x8020000000000000&lt;/Keywords&gt;<br>    &lt;TimeCreated SystemTime=&quot;2008-10-27T18:52:05.181Z&quot; /&gt;<br>    &lt;EventRecordID&gt;6347&lt;/EventRecordID&gt;<br>    &lt;Correlation /&gt;<br>    &lt;Execution ProcessID=&quot;636&quot; ThreadID=&quot;760&quot; /&gt;<br>    &lt;Channel&gt;Security&lt;/Channel&gt;<br>    &lt;Computer&gt;$TS_GATEWAY_FQDN&lt;/Computer&gt;<br>    &lt;Security /&gt;<br>  &lt;/System&gt;<br>  &lt;EventData&gt;<br>    &lt;Data Name=&quot;SubjectUserSid&quot;&gt;S-1-0-0&lt;/Data&gt;<br>    &lt;Data Name=&quot;SubjectUserName&quot;&gt;$DOMAIN\ACCOUNT_NAME(my domain)&lt;/Data&gt;<br>    &lt;Data Name=&quot;SubjectDomainName&quot;&gt;$DOMAIN_NAME&lt;/Data&gt;<br>    &lt;Data Name=&quot;FullyQualifiedSubjectUserName&quot;&gt;$ACCOUNT_NAME&lt;/Data&gt;<br>    &lt;Data Name=&quot;SubjectMachineSID&quot;&gt;S-1-0-0&lt;/Data&gt;<br>    &lt;Data Name=&quot;SubjectMachineName&quot;&gt;$CLIENT_COMPUTER_FQDN&lt;/Data&gt;<br>    &lt;Data Name=&quot;FullyQualifiedSubjectMachineName&quot;&gt;$CLIENT_COMPUTER_FQDN&lt;/Data&gt;<br>    &lt;Data Name=&quot;MachineInventory&quot;&gt;5.1.2600 3.0 x86 Domain Controller &lt;/Data&gt;<br>    &lt;Data Name=&quot;CalledStationID&quot;&gt;UserAuthType:PW&lt;/Data&gt;<br>    &lt;Data Name=&quot;CallingStationID&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;NASIPv4Address&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;NASIPv6Address&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;NASIdentifier&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;NASPortType&quot;&gt;Virtual &lt;/Data&gt;<br>    &lt;Data Name=&quot;NASPort&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;ClientName&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;ClientIPAddress&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;ProxyPolicyName&quot;&gt;NAP TS Gateway&lt;/Data&gt;<br>    &lt;Data Name=&quot;NetworkPolicyName&quot;&gt;NAP TS Gateway Compliant&lt;/Data&gt;<br>    &lt;Data Name=&quot;AuthenticationProvider&quot;&gt;Windows &lt;/Data&gt;<br>    &lt;Data Name=&quot;AuthenticationServer&quot;&gt;$TS_GATEWAY_FQDN&lt;/Data&gt;<br>    &lt;Data Name=&quot;AuthenticationType&quot;&gt;Unauthenticated &lt;/Data&gt;<br>    &lt;Data Name=&quot;EAPType&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;AccountSessionIdentifier&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;QuarantineState&quot;&gt;Full Access &lt;/Data&gt;<br>    &lt;Data Name=&quot;QuarantineSessionIdentifier&quot;&gt;{A1FC7E35-8827-4BC4-86D2-920E2A4FFCBC} - 2008-10-27 18:51:34.656Z&lt;/Data&gt;<br>  &lt;/EventData&gt;<br>&lt;/Event&gt;<br><br>Log Name:      Security<br>Source:        Microsoft-Windows-Security-Auditing<br>Date:          10/27/2008 12:52:05 PM<br>Event ID:      6278<br>Task Category: Network Policy Server<br>Level:         Information<br>Keywords:      Audit Success<br>User:          N/A<br>Computer:      $TS_GATEWAY_FQDN<br>Description:<br>Network Policy Server granted full access to a user because the host met the defined health policy.<br><br>User:<br>    Security ID:            NULL SID<br>    Account Name:            $ACCOUNT_NAME<br>    Account Domain:            $DOMAIN_NAME<br>    Fully Qualified Account Name:    $DOMAIN\ACCOUNT_NAME<br><br>Client Machine:<br>    Security ID:            NULL SID<br>    Account Name:            $CLIENT_COMPUTER_FQDN<br>    Fully Qualified Account Name:    $CLIENT_COMPUTER_NAME<br>    OS-Version:            5.1.2600 3.0 x86 Domain Controller <br>    Called Station Identifier:        UserAuthType:PW<br>    Calling Station Identifier:        -<br><br>NAS:<br>    NAS IPv4 Address:        -<br>    NAS IPv6 Address:        -<br>    NAS Identifier:            -<br>    NAS Port-Type:            Virtual <br>    NAS Port:            -<br><br>RADIUS Client:<br>    Client Friendly Name:        -<br>    Client IP Address:            -<br><br>Authentication Details:<br>    Proxy Policy Name:        NAP TS Gateway<br>    Network Policy Name:        NAP TS Gateway Compliant<br>    Authentication Provider:        Windows <br>    Authentication Server:        $TS_GATEWAY_FQDN<br>    Authentication Type:        Unauthenticated <br>    EAP Type:            -<br>    Account Session Identifier:        -<br><br>Quarantine Information:<br>    Result:                Full Access <br>    Extended-Result:            -<br>    Session Identifier:            {A1FC7E35-8827-4BC4-86D2-920E2A4FFCBC} - 2008-10-27 18:51:34.656Z<br>    Help URL:            -<br>    System Health Validator Result(s):    <br>Windows Security Health Validator..<br>    Compliant <br>    No Data <br>    None <br>    (0x0 - )<br>    (0x0 - )<br>    (0x0 - )<br>    (0x0 - )<br>    (0x0 - )<br>    (0x0 - )<br><br>Event Xml:<br>&lt;Event xmlns=&quot;http://schemas.microsoft.com/win/2004/08/events/event&quot;&gt;<br>  &lt;System&gt;<br>    &lt;Provider Name=&quot;Microsoft-Windows-Security-Auditing&quot; Guid=&quot;{54849625-5478-4994-a5ba-3e3b0328c30d}&quot; /&gt;<br>    &lt;EventID&gt;6278&lt;/EventID&gt;<br>    &lt;Version&gt;0&lt;/Version&gt;<br>    &lt;Level&gt;0&lt;/Level&gt;<br>    &lt;Task&gt;12552&lt;/Task&gt;<br>    &lt;Opcode&gt;0&lt;/Opcode&gt;<br>    &lt;Keywords&gt;0x8020000000000000&lt;/Keywords&gt;<br>    &lt;TimeCreated SystemTime=&quot;2008-10-27T18:52:05.181Z&quot; /&gt;<br>    &lt;EventRecordID&gt;6348&lt;/EventRecordID&gt;<br>    &lt;Correlation /&gt;<br>    &lt;Execution ProcessID=&quot;636&quot; ThreadID=&quot;760&quot; /&gt;<br>    &lt;Channel&gt;Security&lt;/Channel&gt;<br>    &lt;Computer&gt;$TS_GATEWAY_FQDN&lt;/Computer&gt;<br>    &lt;Security /&gt;<br>  &lt;/System&gt;<br>  &lt;EventData&gt;<br>    &lt;Data Name=&quot;SubjectUserSid&quot;&gt;S-1-0-0&lt;/Data&gt;<br>    &lt;Data Name=&quot;SubjectUserName&quot;&gt;$DOMAIN\ACCOUNT_NAME&lt;/Data&gt;<br>    &lt;Data Name=&quot;SubjectDomainName&quot;&gt;$DOMAIN&lt;/Data&gt;<br>    &lt;Data Name=&quot;FullyQualifiedSubjectUserName&quot;&gt;$DOMAIN\ACCOUNT_NAME&lt;/Data&gt;<br>    &lt;Data Name=&quot;SubjectMachineSID&quot;&gt;S-1-0-0&lt;/Data&gt;<br>    &lt;Data Name=&quot;SubjectMachineName&quot;&gt;$CLIENT_COMPUTER_FQDN&lt;/Data&gt;<br>    &lt;Data Name=&quot;FullyQualifiedSubjectMachineName&quot;&gt;$CLIENT_COMPUTER&lt;/Data&gt;<br>    &lt;Data Name=&quot;MachineInventory&quot;&gt;5.1.2600 3.0 x86 Domain Controller &lt;/Data&gt;<br>    &lt;Data Name=&quot;CalledStationID&quot;&gt;UserAuthType:PW&lt;/Data&gt;<br>    &lt;Data Name=&quot;CallingStationID&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;NASIPv4Address&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;NASIPv6Address&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;NASIdentifier&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;NASPortType&quot;&gt;Virtual &lt;/Data&gt;<br>    &lt;Data Name=&quot;NASPort&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;ClientName&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;ClientIPAddress&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;ProxyPolicyName&quot;&gt;NAP TS Gateway&lt;/Data&gt;<br>    &lt;Data Name=&quot;NetworkPolicyName&quot;&gt;NAP TS Gateway Compliant&lt;/Data&gt;<br>    &lt;Data Name=&quot;AuthenticationProvider&quot;&gt;Windows &lt;/Data&gt;<br>    &lt;Data Name=&quot;AuthenticationServer&quot;&gt;$TS_GATEWAY_FQDN&lt;/Data&gt;<br>    &lt;Data Name=&quot;AuthenticationType&quot;&gt;Unauthenticated &lt;/Data&gt;<br>    &lt;Data Name=&quot;EAPType&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;AccountSessionIdentifier&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;QuarantineState&quot;&gt;Full Access &lt;/Data&gt;<br>    &lt;Data Name=&quot;ExtendedQuarantineState&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;QuarantineSessionID&quot;&gt;{A1FC7E35-8827-4BC4-86D2-920E2A4FFCBC} - 2008-10-27 18:51:34.656Z&lt;/Data&gt;<br>    &lt;Data Name=&quot;QuarantineHelpURL&quot;&gt;-&lt;/Data&gt;<br>    &lt;Data Name=&quot;QuarantineSystemHealthResult&quot;&gt;<br>Windows Security Health Validator..<br>    Compliant <br>    No Data <br>    None <br>    (0x0 - )<br>    (0x0 - )<br>    (0x0 - )<br>    (0x0 - )<br>    (0x0 - )<br>    (0x0 - )&lt;/Data&gt;<br>  &lt;/EventData&gt;<br>&lt;/Event&gt;<br><br><br>So, it looks like the client computer is passing the TS CAP; but, the client side still thinks it failed?<br> Mon, 27 Oct 2008 19:03:45 Z2008-10-27T19:03:45Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#8a7e59f4-2160-42c1-896d-695014da087chttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#8a7e59f4-2160-42c1-896d-695014da087cmoomanXhttp://social.technet.microsoft.com/Profile/en-US/?user=moomanXTS Gateway Network access Policy engine received failure from IAS and the error was "16388"Okay...<br><br>If I allow my TS Gateway to access (through our firewall) the Domain Controllers in the computer owner's domain it successfully logs on.<br><br>According to our firewall logs it looks like some Kerberos authentication was happening between the TS Gateway and the outside Domain Controller.  I can live with this for this client; but, it begs the question...<br><br>Can I get by without this computer domain check?  What if I am trying to connect from a computer that is NAP Capable; but I do not know where it's 'home domain' is?<br> Mon, 27 Oct 2008 20:07:30 Z2008-10-27T20:07:30Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#370b5506-3a69-4732-99f4-23c7b1fbeae7http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#370b5506-3a69-4732-99f4-23c7b1fbeae7Rob McShinskyhttp://social.technet.microsoft.com/Profile/en-US/?user=Rob%20McShinskyTS Gateway Network access Policy engine received failure from IAS and the error was "16388" Did you ever find a solution to this.  We are experiencing this same problem trying to connect with another organization through a TS Gateway.  The same workstation when taken off the domain works just fine.  When it is on the domain it does not work.<br><br>Thanks<br><br>RobFri, 20 Mar 2009 17:02:00 Z2009-03-20T17:02:00Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#46e274a9-7445-40f4-b792-744afd1619cbhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#46e274a9-7445-40f4-b792-744afd1619cbVikash Buchahttp://social.technet.microsoft.com/Profile/en-US/?user=Vikash%20BuchaTS Gateway Network access Policy engine received failure from IAS and the error was "16388" What error do you get on the client when you say that the connection does not work?<br><br>Thanks<br>VikashSat, 21 Mar 2009 03:52:10 Z2009-03-21T03:52:10Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#abbe5ced-fb7d-470b-9e0b-3881ffbdbd75http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#abbe5ced-fb7d-470b-9e0b-3881ffbdbd75Rob McShinskyhttp://social.technet.microsoft.com/Profile/en-US/?user=Rob%20McShinskyTS Gateway Network access Policy engine received failure from IAS and the error was "16388" The error we received is below: <p>[Window Title]<br>RemoteApp Disconnected</p> <p>[Content]<br>Terminal Services connection authorization policy (TS CAP) is preventing connection to the remote computer through TS Gateway, possibly due to one of the following reasons:</p> <p>*    You do not have permission to connect to the TS Gateway server.<br>*    You used password authentication but the TS Gateway server is expecting smart card authentication (or vice versa).</p> <p>Contact your administrator for further assistance.<br><br><br>The authentication (username and password from an account on  their domain) is correct.  For testing we are also logging in with a local machine account and not a domain account.  The strange thing is that with the same computers taken off our domain, the connection through the gateway always works and we are able to get to the affiliates apps.  The same computer rejoined to the domain again fails everytime. <br><br>I was thinking this was due to some policy we have in our domain that may be blocking the connection for some reason so I created an OU that blocks all policies on the domain and put all the computer accounts that we were testing as well as a few domain user accounts.  We verified that no policies were being brought down to the system with a gpresult command.  We receive the same error with all policies blocked but just on the domain.  <br><br><br></p>Thu, 26 Mar 2009 02:24:38 Z2009-03-26T02:24:38Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#1f3e7d1c-a708-4614-a205-c59aa8f51bdfhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#1f3e7d1c-a708-4614-a205-c59aa8f51bdfRajesh Gantahttp://social.technet.microsoft.com/Profile/en-US/?user=Rajesh%20%20GantaTS Gateway Network access Policy engine received failure from IAS and the error was "16388" Hello Rob,<br><br>I am assuming that the computers that you are moving in and out of domain are client computers.  And when the clients are domain joined you get a CAP error and when they are non domain joined connections go through. Please correct me if i am wrong. <br><br>Please answer the following questions.<br><br>1. Is TS Gateway configured for a NAP scenario ? Is TS Gateway QEC is enabled on your client ( netsh nap client show state and see whether gateway QEC is enabled ).  Please list the CAP settings on the TS Gateway.<br><br>2.  when you try to login from domain joined client machine , is it asking for gateway credentials ? Or picking up logged on credentials. This is one GP setting. Ultimately what i am asking here is &quot;Is the same user name is used to connect to Gateway in both the cases ( when client is domain joined and not joined to domain ) ?&quot;<br><br><br>There can be a machine level gorup policy setting which is causing this, so by logging in with local user account you can not rule out that domain GP is not a problem.<br><br>Thanks &amp; Regards,<br><span class=RadEWrongWord>Rajesh</span>.<br><br><br><br><br> Thu, 26 Mar 2009 11:23:57 Z2009-03-26T11:23:57Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#0c186675-f8ec-4c71-bffb-e10f74378cf8http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#0c186675-f8ec-4c71-bffb-e10f74378cf8bodhijoehttp://social.technet.microsoft.com/Profile/en-US/?user=bodhijoeTS Gateway Network access Policy engine received failure from IAS and the error was "16388"I found this thread because I am having the same exact problem and can recreate it as necessary for testing. Remote Desktop Client PC's (Windows XP SP3 or Vista SP1) in a domain environment trying to connect through a TS Gateway to a computer in an entirely different domain/forest and remote network.<br/> <br/> If the client PC is a member computer of the domain (even if a user logs on locally), we get the above-mentioned error:<br/> <br/> <em>Terminal Services connection authorization policy (TS CAP) is preventing connection to the remote computer through TS Gateway, possibly due to one of the following reasons:<br/> * You do not have permission to connect to the TS Gateway server.<br/> * You used password authentication but the TS Gateway server is expecting smart card authentication (or vice versa).<br/> Contact your administrator for further assistance.</em> <br/> <br/> If I remove the client PC from its domain, I can successfully connect to the remote TS Gateway (in an entirely different domain/forest), but if I add the PC back to its local domain, I get the error again.<br/> <br/> Looking at the TS Gateway logs, on success (when client computer is not a member of its domain), I see:<br/> <br/> <em>The user &quot;domain\user&quot;, on client computer &quot;xxx.xxx.xxx.xxx&quot;, met connection authorization policy requirements and was therefore authorized to access the TS Gateway server. The following authentication method was used: &quot;NTLM&quot;.</em> <br/> <br/> On failure (when client computer is a member of its domain), I see two entries in the log:<br/> <br/> <em>1. TS Gateway Network access Policy engine received failure from IAS and the error was &quot;16388&quot;<br/> 2. The user &quot;</em> <em>domain\user&quot;, on client computer &quot;</em> <em>xxx.xxx.xxx.xxx&quot;, did not meet connection authorization policy requirements and was therefore not authorized to access the TS Gateway server. The following authentication method was attempted: &quot;NTLM&quot;. The following error occurred: &quot;23003&quot;.</em> <br/> <br/> Note that I am not changing any settings on the TS Gateway. I am only adding/removing the client from its domain for testing. In the logs &quot;domain\user&quot; are the correct credentials for the TS Gateway's domain, I am not incorrectly passing the client's domain and login credentials to the TS Gateway. As for the TS CAP settings on the Gateway server, I am allowing passwords and I am allowing all &quot;Domain Users&quot; to connect (Domain Users referring to users in the TS Gateway's domain, not the client's domain.)  Client group membership is blank (I want any computer to be able to connect) and I have &quot;Enable device redirection for all client devices.&quot;<br/> <br/> To answer Rajesh's questions, 1. We are not using NAP and the &quot;Network Access Protection Agent&quot; on the client is set on manual and is not running. (Turning it on doesn't help.) And when I connect to the Gateway, I am explicitly entering the correct credentials of the remote domain (not the credentials of the local client's domain).<br/> <br/> Is this a bug in the TS client/gateway handshake? Any possible machine-level GPO settings on the client that could cause it fail the TS_CAP policy that gets &quot;fixed&quot; when it's removed from its domain? Any suggestions are welcome -- I have a good setup for testing and finding a resolution sounds like it will help others as well. Thanks, Joe<br/> <br/> <br/> <br/>Wed, 08 Apr 2009 15:42:41 Z2009-04-08T15:42:41Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#36d707dc-efd2-429b-a56a-3970be9c7a00http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#36d707dc-efd2-429b-a56a-3970be9c7a00bodhijoehttp://social.technet.microsoft.com/Profile/en-US/?user=bodhijoeTS Gateway Network access Policy engine received failure from IAS and the error was "16388"P.S. I think the key to this issue is what moomanX wrote above:<br/> <br/> <em>There's still this issue of being in a different domain.  For some reason the TS Gateway tries to contact the computer's domain; even though there is no computer-based authentication happening(?), it should just be authenticating the user that is part of my domain, right?</em> <br/> <br/> Why is the TS Gateway in the destination domain trying to talk to the domain controllers of the client domain? Is NAP mistakenly trying to talk to the client's domain to verify the identity or integrity of the client computer? If the domains are unrelated (two different companies in two different locations), firewall rules or other protective measures would prevent this communication. Why is this verification not necessary if the client PC is in a workgroup instead? Hoping that somebody has some ideas.... -JoeFri, 10 Apr 2009 15:11:34 Z2009-04-10T15:11:34Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#aac49e6b-2011-4b40-a21a-f217098249f5http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#aac49e6b-2011-4b40-a21a-f217098249f5Rob McShinskyhttp://social.technet.microsoft.com/Profile/en-US/?user=Rob%20McShinskyTS Gateway Network access Policy engine received failure from IAS and the error was "16388"I am still seeing this error as well and have an open case with Microsoft.  The variable of the domain still exists even when I bring a domain machine home using my home network.  Taking that machine off the domain while at home and puting it in workgroup gives successful results on connecting through the TS Gateway.    The strange thing is, there are other users  that are part of other domains that can connect correctly to this affiliate TS Web Gateway.  Currently we are the only one.  I can even connect from workstations added to my home domain.  I will reference this thread to Microsoft, maybe we can get some more info.  <br/><br/>-RobWed, 15 Apr 2009 14:28:57 Z2009-04-15T14:28:57Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#e45d110a-ec56-4031-a07f-dcda785dd911http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#e45d110a-ec56-4031-a07f-dcda785dd911Vikash Buchahttp://social.technet.microsoft.com/Profile/en-US/?user=Vikash%20BuchaTS Gateway Network access Policy engine received failure from IAS and the error was "16388"Are you still facing this issue? If yes, i would like to help you investigate it further. Can you please provide me your email id so that i can contact you directly?<br/><br/>Thanks<br/>VikashWed, 22 Apr 2009 05:38:28 Z2009-04-22T05:38:28Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#580fc196-15b3-4ca1-900b-ee03516fa0bfhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#580fc196-15b3-4ca1-900b-ee03516fa0bflinnpminhttp://social.technet.microsoft.com/Profile/en-US/?user=linnpminTS Gateway Network access Policy engine received failure from IAS and the error was "16388"<p class=MsoNormal style="margin-bottom:.0001pt;line-height:normal;background:white"><span style="font-size:8.0pt;font-family:'Verdana','sans-serif';color:black">I seemed to be having the exact same problem. I am running Small Business Server 2008 which is migrated from SBS2003.</span></p> <p class=MsoNormal style="margin-bottom:.0001pt;line-height:normal;background:white"><span style="font-size:8.0pt;font-family:'Verdana','sans-serif';color:black">I got this error on the client machine running Windows Vista x64 Enterprise on a different domain. TS Gateway Server and the client computer are on different domain. I am using RWW to connect to a computer on the SBS domain.</span></p> <p class=MsoNormal style="margin-bottom:.0001pt;line-height:normal;background:white"><span style="font-size:8.0pt;font-family:'Verdana','sans-serif';color:black">NAP is running on the client computer with QEC enabled. Stopping or restarting NAP does not help. I ran tsgqecclientconfig.cmd to add the TS gateway server FQDN to the client machine.</span></p> <p class=MsoNormal style="margin-bottom:.0001pt;line-height:normal;background:white"><em>VBScript: remote Desktop Disconnected</em></p> <p class=MsoNormal style="margin-bottom:.0001pt;line-height:normal;background:white"><em>An internal error has occurred (error 50331676). For more information, please contact your network administer or Microsoft Product Support.</em></p> <p class=MsoNormal style="margin-bottom:.0001pt;line-height:normal;background:white">TS gateway server also logged the exact log as moomanX in the TerminalServices-Gateway:Operational.</p> <p class=MsoNormal style="margin-bottom:.0001pt;line-height:normal;background:white"><span style="font-size:8.0pt;font-family:'Verdana','sans-serif';color:black">Has anyone found the solution to this problem? I tried the hotfix KB954034. As everyone else in the forum, I didn't have this problem from a non-domain client. </span></p> <p class=MsoNormal style="margin-bottom:.0001pt;line-height:normal;background:white"> </p> <p class=MsoNormal style="margin-bottom:.0001pt;line-height:normal;background:white"><span style="font-size:8.0pt;font-family:'Verdana','sans-serif';color:black">Any idea? Thanks.</span></p> <p class=MsoNormal style="margin-bottom:.0001pt;line-height:normal;background:white">~Linn</p> <p class=MsoNormal> </p>Wed, 03 Jun 2009 17:00:26 Z2009-06-03T17:00:26Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#0496a981-c0cd-489b-9913-50e6acf07cb1http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#0496a981-c0cd-489b-9913-50e6acf07cb1Rajesh Gantahttp://social.technet.microsoft.com/Profile/en-US/?user=Rajesh%20%20GantaTS Gateway Network access Policy engine received failure from IAS and the error was "16388"Hi,<br/><br/>How are you connecting through gateway ?  using mstsc ? Please tell the details like how this VBScript error is generated. on your client can you please execute the command &quot;netsh napclient show state&quot; and see whether TSGQEC is properly intialized.  And tell the exact error message that is returned from mstsc client.<br/><br/><br/> <p class=MsoNormal style="line-height:normal;margin-bottom:0pt;background:white"><em>Regards,<br/>Rajesh.<br/></em></p><hr class="sig">Regards, Rajesh.Fri, 05 Jun 2009 13:04:42 Z2009-06-05T13:04:42Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#97e7ccd7-f309-4231-a5d4-fc5205905ee0http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#97e7ccd7-f309-4231-a5d4-fc5205905ee0linnpminhttp://social.technet.microsoft.com/Profile/en-US/?user=linnpminTS Gateway Network access Policy engine received failure from IAS and the error was "16388"<p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Hi Rajesh,<br/><br/>Thanks for replying. I was connecting through the SBS2008 Remote Web Workplace portal. Once I logged into RWW, I saw there options. One is to check my emails, another is “Connect to a computer”, and last one is for the company internal website. <br/><br/>From any computer (either on domain or not), I have no problem using email and internal website. But as I said before and other mentioned, I got the VBScript Error from a computer with a different domain than my SBS2008. Once I clicked on connect to a computer link, <br/><br/>1. It asked me to choose a computer<br/>2. And then I clicked &quot;Connect&quot; button<br/>3. And then it asked me for my user name and password. <br/>(I have tried domain\username and username.)<br/>4. Then a window with this message popped up.</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">(If it is a new computer that I have never used RWW, it asked me to install an ActiveX component.)<br/>~~</span></p> <table class=MsoNormalTable style="" border=0 cellspacing=0 cellpadding=0> <tbody> <tr style=""> <td style="background-color:transparent;border:#bbbbbb 1pt dashed;padding:0in" valign=top> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Please wait while a connection to your computer is established. This may take several seconds …</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">~~</span></p> </td> </tr> </tbody> </table> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">5. It stayed at this window for while. But after 30 seconds or so, I got the VBScrtip error.</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">And I think TSGQEC is initialized. When I ran netsh nap client show state, it generated this:</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">--------------------------------------------------------------------------------------</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Client state:</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">----------------------------------------------------</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Name<span style="">                   </span>= Network Access Protection Client</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Description<span style="">            </span>= Microsoft Network Access Protection Client</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Protocol version<span style="">       </span>= 1.0</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Status<span style="">                 </span>= Enabled</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Restriction state<span style="">      </span>= Not restricted</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Troubleshooting URL<span style="">    </span>=</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Restriction start time =</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Extended state<span style="">         </span>=</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Enforcement client state:</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">----------------------------------------------------</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Id<span style="">                     </span>= 79617</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Name<span style="">                   </span>= DHCP Quarantine Enforcement Client</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Description<span style="">            </span>= Provides DHCP based enforcement for NAP</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Version<span style="">              </span><span style="">  </span>= 1.0</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Vendor name<span style="">            </span>= Microsoft Corporation</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Registration date<span style="">      </span>=</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Initialized<span style="">            </span>= No</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Id<span style="">                     </span>= 79618</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Name<span style="">                   </span>= Remote Access Quarantine Enforcement Client</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Description<span style="">            </span>= Provides the quarantine enforcement for RAS Client</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Version<span style="">                </span>= 1.0</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Vendor name<span style="">            </span>= Microsoft Corporation</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Registration date<span style="">      </span>=</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Initialized<span style="">            </span>= No</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Id<span style="">                     </span>= 79619</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Name<span style="">                   </span>= IPSec Relying Party</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Description<span style="">          </span><span style="">  </span>= Provides IPSec based enforcement for Network Access Pro</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">tection</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Version<span style="">                </span>= 1.0</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Vendor name<span style="">            </span>= Microsoft Corporation</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Registration date<span style="">      </span>=</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Initialized<span style="">            </span>= No</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Id<span style="">                     </span>= 79621</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Name<span style="">                   </span>= TS Gateway Quarantine Enforcement Client</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Description<span style="">            </span>= Provides TS Gateway enforcement for NAP</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Version<span style="">                </span>= 1.0</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Vendor name<span style="">            </span>= Microsoft Corporation</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Registration date<span style="">      </span>=</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Initialized<span style="">            </span>= Yes</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Id<span style="">                     </span>= 79623</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Name<span style="">                   </span>= EAP Quarantine Enforcement Client</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Description<span style="">            </span>= Provides EAP based enforcement for NAP</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Version<span style="">                </span>= 1.0</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Vendor name<span style="">            </span>= Microsoft Corporation</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Registration date<span style="">   </span><span style="">   </span>=</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Initialized<span style="">            </span>= No</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">System health agent (SHA) state:</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">----------------------------------------------------</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Id<span style="">                     </span>= 79744</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Name<span style="">                   </span>= Windows Security Health Agent</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Description<span style="">            </span>= The Windows Security Health Agent checks the compliance</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana"><span style=""> </span>of a computer with an administrator-defined policy.</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Version<span style="">                </span>= 1.0</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Vendor name<span style="">            </span>= Microsoft Corporation</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Registration date<span style="">      </span>=</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Initialized<span style="">            </span>= Yes</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Failure category<span style="">       </span>= None</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Remediation state<span style="">      </span>= Success</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Remediation percentage = 0</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Fixup Message<span style="">          </span>= (3237937214) - The Windows Security Health Agent has fi</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">nished updating its security state.</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Compliance results<span style="">     </span>=</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Remediation results<span style="">    </span>=</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana"> </span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana">Ok.</span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="font-size:10pt;color:black;font-family:Verdana"> _____________________________________________________________________________________________<br/><br/>Thanks.<br/>~Linn</span></p>Fri, 05 Jun 2009 15:37:07 Z2009-06-05T15:37:07Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#b9bc2893-bb85-4ba2-982c-96c8a69dcfffhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#b9bc2893-bb85-4ba2-982c-96c8a69dcfffDr. Zaiushttp://social.technet.microsoft.com/Profile/en-US/?user=Dr.%20ZaiusTS Gateway Network access Policy engine received failure from IAS and the error was "16388"<blockquote> The feature team is looking into this issue. I will get back to you once we find anything<br/><br/>Thanks,<br/>Vikash</blockquote> <br/>Hello,<br/><br/>This is happening to us as well.  Our clients are NAP capable and work 95% of the time.  But over the past month we have recieved the above error on our 2 terminal servers that belong to one session broker.<br/><br/><span lang=EN> <p>TS Gateway Network access Policy engine received failure from IAS and the error was &quot;16388&quot;<br/></p> <div class=e> <div class=c style="margin-left:1em;text-indent:-2em"><a class=b href="http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e/#"><strong><span style="color:#ff0000;font-family:Courier New">-</span></strong></a> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">Event</span></span><span class=ns><span style="color:#ff0000"> xmlns</span></span><span class=m><span style="color:#0000ff">=&quot;</span></span><strong class=ns><span style="color:#ff0000">http://schemas.microsoft.com/win/2004/08/events/event</span></strong><span style="color:#0000ff"><span class=m>&quot;</span><span class=m>&gt;</span></span></div> <div style=""> <div class=e> <div class=c style="margin-left:1em;text-indent:-2em"><a class=b href="http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e/#"><strong><span style="color:#ff0000;font-family:Courier New">-</span></strong></a> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">System</span></span><span class=m><span style="color:#0000ff">&gt;</span></span></div> <div> <div class=e> <div style="margin-left:1em;text-indent:-2em"><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">Provider</span></span> <span class=t><span style="color:#990000">Name</span></span><span class=m><span style="color:#0000ff">=&quot;</span></span><strong>Microsoft-Windows-TerminalServices-Gateway</strong><span class=m><span style="color:#0000ff">&quot;</span></span><span class=t><span style="color:#990000"> Guid</span></span><span class=m><span style="color:#0000ff">=&quot;</span></span><strong>{4d5ae6a1-c7c8-4e6d-b840-4d8080b42e1b}</strong><span style="color:#0000ff"><span class=m>&quot;</span><span class=m> /&gt;</span></span></div> </div> <div class=e> <div style="margin-left:1em;text-indent:-2em"><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">EventID</span></span><span class=m><span style="color:#0000ff">&gt;</span></span><span class=tx><strong>641</strong></span><span class=m><span style="color:#0000ff">&lt;/</span></span><span class=t><span style="color:#990000">EventID</span></span><span class=m><span style="color:#0000ff">&gt;</span></span></div> </div> <div class=e> <div style="margin-left:1em;text-indent:-2em"><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">Version</span></span><span class=m><span style="color:#0000ff">&gt;</span></span><span class=tx><strong>0</strong></span><span class=m><span style="color:#0000ff">&lt;/</span></span><span class=t><span style="color:#990000">Version</span></span><span class=m><span style="color:#0000ff">&gt;</span></span></div> </div> <div class=e> <div style="margin-left:1em;text-indent:-2em"><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">Level</span></span><span class=m><span style="color:#0000ff">&gt;</span></span><span class=tx><strong>2</strong></span><span class=m><span style="color:#0000ff">&lt;/</span></span><span class=t><span style="color:#990000">Level</span></span><span class=m><span style="color:#0000ff">&gt;</span></span></div> </div> <div class=e> <div style="margin-left:1em;text-indent:-2em"><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">Task</span></span><span class=m><span style="color:#0000ff">&gt;</span></span><span class=tx><strong>4</strong></span><span class=m><span style="color:#0000ff">&lt;/</span></span><span class=t><span style="color:#990000">Task</span></span><span class=m><span style="color:#0000ff">&gt;</span></span></div> </div> <div class=e> <div style="margin-left:1em;text-indent:-2em"><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">Opcode</span></span><span class=m><span style="color:#0000ff">&gt;</span></span><span class=tx><strong>22</strong></span><span class=m><span style="color:#0000ff">&lt;/</span></span><span class=t><span style="color:#990000">Opcode</span></span><span class=m><span style="color:#0000ff">&gt;</span></span></div> </div> <div class=e> <div style="margin-left:1em;text-indent:-2em"><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">Keywords</span></span><span class=m><span style="color:#0000ff">&gt;</span></span><span class=tx><strong>0x4000000002000000</strong></span><span class=m><span style="color:#0000ff">&lt;/</span></span><span class=t><span style="color:#990000">Keywords</span></span><span class=m><span style="color:#0000ff">&gt;</span></span></div> </div> <div class=e> <div style="margin-left:1em;text-indent:-2em"><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">TimeCreated</span></span> <span class=t><span style="color:#990000">SystemTime</span></span><span class=m><span style="color:#0000ff">=&quot;</span></span><strong>2009-06-16T12:30:47.759Z</strong><span style="color:#0000ff"><span class=m>&quot;</span><span class=m> /&gt;</span></span></div> </div> <div class=e> <div style="margin-left:1em;text-indent:-2em"><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">EventRecordID</span></span><span class=m><span style="color:#0000ff">&gt;</span></span><span class=tx><strong>5966</strong></span><span class=m><span style="color:#0000ff">&lt;/</span></span><span class=t><span style="color:#990000">EventRecordID</span></span><span class=m><span style="color:#0000ff">&gt;</span></span></div> </div> <div class=e> <div style="margin-left:1em;text-indent:-2em"><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">Correlation</span></span> <span class=m><span style="color:#0000ff">/&gt;</span></span></div> </div> <div class=e> <div style="margin-left:1em;text-indent:-2em"><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">Execution</span></span> <span class=t><span style="color:#990000">ProcessID</span></span><span class=m><span style="color:#0000ff">=&quot;</span></span><strong>2324</strong><span class=m><span style="color:#0000ff">&quot;</span></span><span class=t><span style="color:#990000"> ThreadID</span></span><span class=m><span style="color:#0000ff">=&quot;</span></span><strong>6964</strong><span style="color:#0000ff"><span class=m>&quot;</span><span class=m> /&gt;</span></span></div> </div> <div class=e> <div style="margin-left:1em;text-indent:-2em"><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">Channel</span></span><span class=m><span style="color:#0000ff">&gt;</span></span><span class=tx><strong>Microsoft-Windows-TerminalServices-Gateway/Operational</strong></span><span class=m><span style="color:#0000ff">&lt;/</span></span><span class=t><span style="color:#990000">Channel</span></span><span class=m><span style="color:#0000ff">&gt;</span></span></div> </div> <div class=e> <div style="margin-left:1em;text-indent:-2em"><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">Computer</span></span><span class=m><span style="color:#0000ff">&gt;</span></span><span class=tx><strong>OurServerName</strong></span><span class=m><span style="color:#0000ff">&lt;/</span></span><span class=t><span style="color:#990000">Computer</span></span><span class=m><span style="color:#0000ff">&gt;</span></span></div> </div> <div class=e> <div style="margin-left:1em;text-indent:-2em"><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">Security</span></span> <span class=t><span style="color:#990000">UserID</span></span><span class=m><span style="color:#0000ff">=&quot;</span></span><strong>S-1-5-20</strong><span style="color:#0000ff"><span class=m>&quot;</span><span class=m> /&gt;</span></span></div> </div> <div><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;/</span></span><span class=t><span style="color:#990000">System</span></span><span class=m><span style="color:#0000ff">&gt;</span></span></div> </div> </div> <div class=e> <div class=c style="margin-left:1em;text-indent:-2em"><a class=b href="http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e/#"><strong><span style="color:#ff0000;font-family:Courier New">-</span></strong></a> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">UserData</span></span><span class=m><span style="color:#0000ff">&gt;</span></span></div> <div> <div class=e> <div class=c style="margin-left:1em;text-indent:-2em"><a class=b href="http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e/#"><strong><span style="color:#ff0000;font-family:Courier New">-</span></strong></a> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">EventInfo</span></span><span class=ns><span style="color:#ff0000"> xmlns</span></span><span class=m><span style="color:#0000ff">=&quot;</span></span><strong class=ns><span style="color:#ff0000">aag</span></strong><span style="color:#0000ff"><span class=m>&quot;</span><span class=m>&gt;</span></span></div> <div> <div class=e> <div style="margin-left:1em;text-indent:-2em"><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">Name</span></span> <span class=m><span style="color:#0000ff">/&gt;</span></span></div> </div> <div class=e> <div style="margin-left:1em;text-indent:-2em"><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;</span></span><span class=t><span style="color:#990000">ErrorCode</span></span><span class=m><span style="color:#0000ff">&gt;</span></span><span class=tx><strong>16388</strong></span><span class=m><span style="color:#0000ff">&lt;/</span></span><span class=t><span style="color:#990000">ErrorCode</span></span><span class=m><span style="color:#0000ff">&gt;</span></span></div> </div> <div><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;/</span></span><span class=t><span style="color:#990000">EventInfo</span></span><span class=m><span style="color:#0000ff">&gt;</span></span></div> </div> </div> <div><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;/</span></span><span class=t><span style="color:#990000">UserData</span></span><span class=m><span style="color:#0000ff">&gt;</span></span></div> </div> </div> <div><span class=b><strong><span style="color:#ff0000;font-family:Courier New"> </span></strong></span> <span class=m><span style="color:#0000ff">&lt;/</span></span><span class=t><span style="color:#990000">Event</span></span><span class=m><span style="color:#0000ff">&gt;</span></span></div> </div> </div> <p><br/><br/>The connection seems to reset itself after the above error anywhere from 40 seconds to 5 minutes. Can not find any information as to what could be causing this.  Any help would be greatly appreciated.<br/>Thanks!</p> </span>Wed, 17 Jun 2009 14:38:00 Z2009-06-17T14:38:00Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#faf1d95d-4d70-4725-a60b-5133511a5254http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#faf1d95d-4d70-4725-a60b-5133511a5254Rajesh Gantahttp://social.technet.microsoft.com/Profile/en-US/?user=Rajesh%20%20GantaTS Gateway Network access Policy engine received failure from IAS and the error was "16388"Hi,<br/><br/>The error  &quot;TS Gateway Network access Policy engine received failure from IAS and the error was &quot;16388&quot;&quot;   happens when the communication between NPS and TS Gateway times out.  <br/><br/> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="color:#1f497d"><span style="font-size:small"><span style="font-family:Calibri">Can you please provide  the NPS  logs?  Here is the command to start the logging <br/></span></span></span><span style="color:#1f497d"><span style="font-size:small"><span style="font-family:Calibri"><br/>netsh ras set tracing * enable</span></span></span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="color:#1f497d"><span style="font-family:Calibri;font-size:small"> </span></span></p> <p class=MsoNormal style="margin:0in 0in 0pt"><span style="color:#1f497d"><span style="font-size:small"><span style="font-family:Calibri">Send us the all the log files in %windir%\tracing directory.  Also </span></span></span><span style="color:#1f497d"><span style="font-size:small"><span style="font-family:Calibri">Please also send us the event logs<br/></span></span></span></p> <br/>Thanks.<br/><br/><hr class="sig">Regards, Rajesh.Sat, 20 Jun 2009 07:03:19 Z2009-06-20T07:03:19Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#b9a5c27c-3b92-40d5-9ea3-73274a745894http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#b9a5c27c-3b92-40d5-9ea3-73274a745894Dr. Zaiushttp://social.technet.microsoft.com/Profile/en-US/?user=Dr.%20ZaiusTS Gateway Network access Policy engine received failure from IAS and the error was "16388"Thank you for the response.  I will enable tracing now and post\send logs as soon as we receive another 641.Tue, 23 Jun 2009 18:15:36 Z2009-06-23T18:15:36Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#79a620d0-4d4f-4f79-b480-381e3d569842http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#79a620d0-4d4f-4f79-b480-381e3d569842Dr. Zaiushttp://social.technet.microsoft.com/Profile/en-US/?user=Dr.%20ZaiusTS Gateway Network access Policy engine received failure from IAS and the error was "16388"Hello,<br/><br/>This has just happened now.  I have the trace logs and the event logs, where can I send them too?<br/><br/>Thanks.Thu, 25 Jun 2009 20:23:16 Z2009-06-25T20:23:16Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#f59676d9-1d5e-4501-a892-a0899e8ebb5ahttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#f59676d9-1d5e-4501-a892-a0899e8ebb5aKristin L. Griffinhttp://social.technet.microsoft.com/Profile/en-US/?user=Kristin%20L.%20GriffinTS Gateway Network access Policy engine received failure from IAS and the error was "16388"I dont want to interced on Rajesh, but if you don't mind, I would like to see them too: kristin.l.griffin@gmail.com.<br/> <br/> Thanks! <hr class=sig> <br/> Kristin L. Griffin <br/> <br/> The Microsoft Windows Server 2008 Terminal Services Resource Kit is available at: http://www.amazon.com/Windows-Server%C2%AE-Terminal-Services-Resource/dp/0735625859/ref=sr_1_1?ie=UTF8&amp;s=books&amp;qid=1245947488&amp;sr=8-1Thu, 25 Jun 2009 20:24:27 Z2009-06-25T20:24:36Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#c7bc01bf-8ea3-43ba-9a07-88f325f582f5http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#c7bc01bf-8ea3-43ba-9a07-88f325f582f5Dr. Zaiushttp://social.technet.microsoft.com/Profile/en-US/?user=Dr.%20ZaiusTS Gateway Network access Policy engine received failure from IAS and the error was "16388"I have placed both the log files as well as the tsgateway eventlogs on our webserver at <a href="http://files.progressive-solutions.com/TSGateWay/">http://files.progressive-solutions.com/TSGateWay/</a> I will keep this up for a couple of days.  Thank you again for any assistance you can provide!Thu, 25 Jun 2009 21:27:09 Z2009-06-25T21:27:09Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#c21ceda9-1c78-4234-bb59-07b163b43f6bhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#c21ceda9-1c78-4234-bb59-07b163b43f6bDr. Zaiushttp://social.technet.microsoft.com/Profile/en-US/?user=Dr.%20ZaiusTS Gateway Network access Policy engine received failure from IAS and the error was "16388"Hello,<br/><br/>Has anyone had a chance to look at the logs for this issue?  Or is there any other information that I can provide?<br/><br/>Thanks,<br/>The Dr.Tue, 30 Jun 2009 22:32:56 Z2009-06-30T22:32:56Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#fff88685-362d-4acb-9083-b6716571f5d9http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#fff88685-362d-4acb-9083-b6716571f5d9Rajesh Gantahttp://social.technet.microsoft.com/Profile/en-US/?user=Rajesh%20%20GantaTS Gateway Network access Policy engine received failure from IAS and the error was "16388"Hi Zaius,<br/><br/>We are following up with NPS team and working on it.<br/><br/>NPS team says this error happens when NPS can not validate the client machine by contacting AD.  In your case NPS failed to validate  client computer name: <span style="font-family:'Calibri','sans-serif';color:#1f497d;font-size:11pt">TPUGHPC.CoxIndustries.local<span style="font-family:Verdana;color:#000000;font-size:x-small">  <br/><br/>Is the client machine domain and TS Gateway server domain are trusted ?  <br/><br/>Do you have any client machine group specified in CAP ?<br/><br/>Also are you getting the failure from same client ( <span style="font-family:'Calibri','sans-serif';color:#1f497d;font-size:11pt">TPUGHPC.CoxIndustries.local<span style="font-family:Verdana;color:#000000;font-size:x-small">  )</span></span> always ?<br/><br/><br/>Thanks.</span></span> <hr class=sig> Regards, Rajesh.Wed, 01 Jul 2009 11:03:40 Z2009-07-02T05:51:38Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#3ce55540-0f91-493a-a1b6-ada1fdbc2814http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#3ce55540-0f91-493a-a1b6-ada1fdbc2814linnpminhttp://social.technet.microsoft.com/Profile/en-US/?user=linnpminTS Gateway Network access Policy engine received failure from IAS and the error was "16388"Hello, <div><br/></div> <div> <p class=MsoNormal><span><span style="font-size:8.5pt;line-height:115%;font-family:'Verdana','sans-serif';color:black">I am still waiting for the answer as well.</span></span></p> <p class=MsoNormal><span style="line-height:12px">Has anyone found a workaround? </span></p> <p class=MsoNormal><span style="line-height:12px">Thanks.</span></p> <p class=MsoNormal><span style="line-height:12px">~Linn</span></p> </div> <div><br/></div>Thu, 02 Jul 2009 18:50:30 Z2009-07-02T18:50:30Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#7e4d2f40-0ea8-420b-ba16-2bb9256fdf24http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#7e4d2f40-0ea8-420b-ba16-2bb9256fdf24Vikash Buchahttp://social.technet.microsoft.com/Profile/en-US/?user=Vikash%20BuchaTS Gateway Network access Policy engine received failure from IAS and the error was "16388"<p>@Dr. Zaius, Can you please confirm that the logs that you have shared are for the failure connection case only? I am asking this because the NPS logs seem to indicate that NPS returned success. Else can you please share the logs for the connection failure case one more time?<br/><br/>@Linnpmin, can you also please share logs for the failure case that you are seeing?<br/><span style="font-size:x-small;color:#1f497d;font-family:Calibri">Here is the command to start the logging <br/></span><span style="color:#1f497d"><span style="font-size:small"><span style="font-family:Calibri"><span style="font-size:x-small">1. netsh ras set tracing * enable<br/>2. Repro the issue<br/>3. </span></span></span></span><span style="color:#1f497d"><span style="font-size:small"><span style="font-family:Calibri"><span style="font-size:x-small">Send us the all the log files in %windir%\tracing directory.  Also </span></span></span></span><span style="color:#1f497d"><span style="font-size:small"><span style="font-family:Calibri"><span style="font-size:x-small">Please also send us the event logs</span><br/><br/>Thanks<br/>Vikash</span></span></span></p>Fri, 03 Jul 2009 08:41:11 Z2009-07-03T08:41:11Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#558f7a1d-0103-49c7-806a-b8607f604bc9http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#558f7a1d-0103-49c7-806a-b8607f604bc9Vikash Buchahttp://social.technet.microsoft.com/Profile/en-US/?user=Vikash%20BuchaTS Gateway Network access Policy engine received failure from IAS and the error was "16388"Can anyone facing this issue share the logs again please?<br/><br/>Thanks<br/>VikashMon, 13 Jul 2009 06:32:48 Z2009-07-13T06:32:48Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#3fc75f5b-9c19-4950-b3a8-6e9927dd3cb8http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#3fc75f5b-9c19-4950-b3a8-6e9927dd3cb8linnpminhttp://social.technet.microsoft.com/Profile/en-US/?user=linnpminTS Gateway Network access Policy engine received failure from IAS and the error was "16388"Hi,<br/><br/>I have posted the logs here: <span class=Apple-style-span style="word-spacing:0px;font:16px 'Times New Roman';text-transform:none;color:#000000;text-indent:0px;white-space:normal;letter-spacing:normal;border-collapse:separate"><span class=Apple-style-span style="font-size:11px;color:#464646;font-family:Verdana;text-align:left"><a style="color:#114170" href="http://cid-ba1f0c40eb76ee9c.skydrive.live.com/browse.aspx/Public?authkey=cx0Syf4DUYU$">http://cid-ba1f0c40eb76ee9c.skydrive.live.com/browse.aspx/Public?authkey=cx0Syf4DUYU%24</a>.<br/><br/>~Linn</span></span>Mon, 13 Jul 2009 17:43:01 Z2009-07-13T17:43:01Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#78cb2cd7-d615-4801-8667-4efb1d0ad715http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#78cb2cd7-d615-4801-8667-4efb1d0ad715Dr. Zaiushttp://social.technet.microsoft.com/Profile/en-US/?user=Dr.%20ZaiusTS Gateway Network access Policy engine received failure from IAS and the error was "16388"<p>I am sorry, I was unavailable last week.  The logs that I posted did include the error event, but also successful events.  I will clear out the logs and repost as soon as the event occurs.  Here are some answers to a couple of the questions:<br/><br/><strong><span style="font-size:xx-small">Also are you getting the failure from same client ( </span><span style="font-size:11pt;color:#1f497d;font-family:'Calibri','sans-serif'">TPUGHPC.CoxIndustries.local<span style="font-size:x-small;color:#000000;font-family:Verdana"><span style="font-size:xx-small">  )</span></span></span></strong><span style="font-size:xx-small"><strong> always ?</strong>  --  Not sure on this, will need to check when event occurs again.<br/><br/><br/><strong>Do you have any client machine group specified in CAP ?</strong>   --  There are no client machine groups specified in the CAP.<br/><br/><br/><strong>Is the client machine domain and TS Gateway server domain are trusted ?</strong>   --  The clients are connecting to a Hosted provider and Domains are NOT trusted.<br/><br/>FYI ~ I have left the logs up at the site noted above and will repost to there if\when event occurs again.<br/><br/>Thanks~!<br/><br/></span></p>Mon, 13 Jul 2009 19:14:35 Z2009-07-13T21:00:14Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#2678ea2f-37bd-42c2-9718-bec5d87a3711http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#2678ea2f-37bd-42c2-9718-bec5d87a3711Paulm187http://social.technet.microsoft.com/Profile/en-US/?user=Paulm187TS Gateway Network access Policy engine received failure from IAS and the error was "16388"Did anyone find a answer. I have the NPS  &quot;<span style="font-size:xx-small">There is no domain controller available for domain&quot; issue while trying to connect via RD Gateway in Windows 2008 R2. I can however connect via TS Gateway in Windows 2008 SP2 without any problems. All my clients and servers are in a single Windows 2003 domain.</span>Tue, 18 Aug 2009 17:18:48 Z2009-08-18T17:18:48Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#9855114d-d528-41bb-b5e2-eb96ff1aa9f2http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#9855114d-d528-41bb-b5e2-eb96ff1aa9f2Vikash Buchahttp://social.technet.microsoft.com/Profile/en-US/?user=Vikash%20BuchaTS Gateway Network access Policy engine received failure from IAS and the error was "16388"Can you please share the logs as has been asked in this post above? This will help us to investigate it further. <br/>When you say you are using WS 2008 R2, which release are you using? Is it Beta or RC build?<br/><br/>Thanks<br/>VikashWed, 19 Aug 2009 04:21:21 Z2009-08-19T04:21:21Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#7510804a-594f-4f9c-990f-d939ed37ee81http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#7510804a-594f-4f9c-990f-d939ed37ee81Dr. Zaiushttp://social.technet.microsoft.com/Profile/en-US/?user=Dr.%20ZaiusTS Gateway Network access Policy engine received failure from IAS and the error was "16388"Just an FYI here....we haven't had the issue since we upgraded to SP2.&nbsp; At this time we don't have plans to move R2 into production as SP2 is working very solidly.<br /><br />Thanks,<br />Dr. ZThu, 15 Oct 2009 23:53:55 Z2009-10-15T23:53:55Zhttp://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#9d69683b-49f0-40d4-a7d7-5bcce155ffd3http://social.technet.microsoft.com/Forums/en-US/winserverTS/thread/092a427c-3609-43bc-9a8b-23616970b45e#9d69683b-49f0-40d4-a7d7-5bcce155ffd3jarettweberhttp://social.technet.microsoft.com/Profile/en-US/?user=jarettweberTS Gateway Network access Policy engine received failure from IAS and the error was "16388"<p>Just to add a little to this thread...<br /><br />-We can successfully connect to the TSGateway server with a NON domain connected machine.<br />-We can NOT connect to the TSGateway server with a machine that is connected to ANY domain, including our own.<br /><br />I did some research into the tracing logs (IASSAM.log in particular)&nbsp;and found that the TSGateway server is trying to communicate with the domain machines domain controller to "crack" it's FQDN into a NetBIOS name.&nbsp; Obviously no one wants a DC to be internet facing, thus our session fails.&nbsp; It throws some sort of COM exception which I have not got my finger on yet.&nbsp; Take a look at a snippet from my log...<br /><br /><span style="color: #1f497d;"><span style="font-size: small;"><span style="font-family: Calibri;">Successful login:</span></span></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #1f497d;"><span style="font-family: Calibri; font-size: small;">&nbsp;</span></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #1f497d;"><span style="font-size: small;"><span style="font-family: Calibri;">[3392] 10-16 13:01:20:500: NT-SAM Names handler received request with user identity XXX\xxxx.</span></span></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #1f497d;"><span style="font-size: small;"><span style="font-family: Calibri;">[3392] 10-16 13:01:20:500: Username is already an NT4 account name.</span></span></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #1f497d;"><span style="font-size: small;"><span style="font-family: Calibri;">[3392] 10-16 13:01:20:500: SAM-Account-Name is "XXX\xxxx".</span></span></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #1f497d;"><span style="font-size: small;"><span style="font-family: Calibri;">[3392] 10-16 13:01:20:500: Get machine name xp-demo2 from non SOH</span></span></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #1f497d;"><span style="font-size: small;"><span style="font-family: Calibri;">[3392] 10-16 13:01:20:500: Skipping cracking since machine name is in NetBIOS format: xp-demo2</span></span></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #1f497d;"><span style="font-family: Calibri; font-size: small;">&nbsp;</span></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #1f497d;"><span style="font-size: small;"><span style="font-family: Calibri;">Unsuccessful login:</span></span></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #1f497d;"><span style="font-family: Calibri; font-size: small;">&nbsp;</span></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #1f497d;"><span style="font-size: small;"><span style="font-family: Calibri;">[3084] 10-16 13:10:48:993: NT-SAM Names handler received request with user identity XXX\xxxx.</span></span></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #1f497d;"><span style="font-size: small;"><span style="font-family: Calibri;">[3084] 10-16 13:10:48:993: Username is already an NT4 account name.</span></span></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #1f497d;"><span style="font-size: small;"><span style="font-family: Calibri;">[3084] 10-16 13:10:48:993: SAM-Account-Name is "XXX\xxxx".</span></span></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #1f497d;"><span style="font-size: small;"><span style="font-family: Calibri;">[3084] 10-16 13:10:48:993: Get machine name xp-demo.AnyDomain.com from non SOH</span></span></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #1f497d;"><span style="font-size: small;"><span style="font-family: Calibri;">[3084] 10-16 13:11:31:086: Failed to crack machine name failed: The RPC server is unavailable.</span></span></span></p> <p class="MsoNormal" style="margin: 0in 0in 0pt;"><span style="color: #1f497d;"><span style="font-size: small;"><span style="font-family: Calibri;">[3084] 10-16 13:11:31:086: Caught COM exception: The system cannot open the file.<br /><br /></span></span></span></p> <p><br />The 2 XP machines are clones.&nbsp; XP Pro on SP3.&nbsp; Obviously different names and one is connected to a domain, one is not<br /><br />I've tried everything you guys have mentioned in this thread, so thanks for the ideas.&nbsp; I've sent my findings to MS, but have not heard back.&nbsp; I'll post any sort of fix I recieve.<br /><br />Thanks,<br /><br />Jarett</p>Fri, 16 Oct 2009 18:52:23 Z2009-10-16T18:53:45Z