NPS and CA Static port issue

Kave
Getting noticed

NPS and CA Static port issue

I have  a CA and NPS server in same VLAN and Same subnet, I can ping them but unfortunately When i set Static Port for CA i got RPC error, Port 135 is listening and ok but static port 10000 that i set it for CA can not start listening, i set it Allow  in In and Out band firewall as well, I do not know what is going on there. I have a MX withx2 VLAN one of them is management VLAN 1 and the another is set for 172.16x.x/24 subnet, The MX is connected to the nexus Via MX LAN portand nexus act as L2 and all VM is connected to the nexus.

kav noroozi
5 Replies 5
alemabrahao
Kind of a big deal
Kind of a big deal

This seems to be a server issue.

 

Check if the server's firewall is blocking anything.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
Brash
Kind of a big deal
Kind of a big deal

From what you've described, it definitely sounds like a server side firewall or port binding issue.

Kave
Getting noticed

I dont think so, I wrote a firewall role for that port

kav noroozi
alemabrahao
Kind of a big deal
Kind of a big deal

Have you tested the port locally on the server? A simple test is to isolate a host and the server from the firewall.

But honestly, I still believe it's a server issue.

I am not a Cisco Meraki employee. My suggestions are based on documentation of Meraki best practices and day-to-day experience.

Please, if this post was useful, leave your kudos and mark it as solved.
PhilipDAth
Kind of a big deal
Kind of a big deal

By CA, do you mean Certificate Authority?

Are you saying you have changed the IIS port to 10,000 for web-delivered certificates?

What are you expecting to talk to the CA server?

What is reporting the error?

Get notified when there are additional replies to this discussion.
Welcome to the Meraki Community!
To start contributing, simply sign in with your Cisco ID. If you don't yet have a Cisco ID, you can sign up.
Labels