Reason: Invalid response
Radius response: Authentication rejected
User-Name: testuser
|
Incorrect token response. |
- Verify the correct response is being entered.
- Check the response in the administration console.
- Check if PIN configured for user.
|
Reason: Account locked out due to invalid attempts
Radius response: Authentication Rejected
User-Name: testuser
|
User’s account is locked in Defender. |
Use the Defender Administration Console to reset violation count for the user. |
Reason: Invalid password
Radius response: Authentication Rejected
User-Name: testuser
|
Incorrect Active Directory password. |
Verify the correct password is being entered. |
authentication abandoned user testuser
|
Session timed out while waiting for user response. |
Verify connectivity between the client and the Defender Security Server on the configured RADIUS port. |
Reason: User not valid for this route
Radius response: Authentication Rejected
User-Name: testuser |
This message can be caused by one of the following:
- User is not a member of the Access Node.
- User does not have a token.
- User is not a Defender user.
- There is no license available for the user.
- Client IP not permitted by the Access Node.
|
- Verify the members of the Access Node.
- Verify the user has a Defender token assigned.
- Verify that suitable licenses exist.
- Verify the IP.
|
Domain Search from CN=testuser,CN=Users,DC=child,DC=democor p,DC=local took 57 seconds
L DAP fa i led (-1)find i ng user test u ser
|
Active Directory search has failed. This can happen if, for example, the child domain is unavailable. |
Verify that the Defender service account has sufficient permissions or is a member of the Domain Administrators group. |
LDAP failed (50) writing token data for CN=PDWIN1348400003,OU=Tokens,OU=Defender,DC=democorp,DC=local
Failed to write token data to LDAP
|
The Defender service account does not have sufficient permissions in Active Directory to update the user’s token information. |
Verify that the Defender service account has sufficient permissions or is a member of the Domain Administrators group. |