Available in Classic and VPC
You might run into the following problems when using SSL VPN. Find out causes and possible solutions.
If the problem is not resolved with the methods provided by this guide, submit inquiries including the following information to Contact us.
- SSL VPN access information
- SSL VPN username
- Access time
- Issue description (including screen capture)
Troubleshoot prior action issues
SSL VPN agent installation and execution errors occur.
Cause
Windows updates are not installed or a security program is preventing the installation and execution of the SSL VPN Agent.
Solution
- Update Windows to the latest version.
- Close all security programs.
- Disable the firewall.
Troubleshoot SSL VPN agent installation error issues
When you install SSL VPN agent, the following error message appears:
"BIG-IP Edge Client setup enned prematurely because of an error. Your system has not been modified. To install this program at a later time, please run the installation again."
Cause
Installation is restricted if the Root Certification Authority certificate does not exist or expired.
To view a certificate, follow these steps:
- Run certmgr.msc.
- Check the following 3 certificates and expiration dates in Certificates - Current user > Trusted root certification authorities > Certificates.
- Entrust Root Certification Authority
- Entrust Root Certification Authority - G2
- Entrust.net Certification Authority (2048)
Solution
The solutions are as follows:
- Connect to the Internet to view certificates.
- Download the following 3 certificates:
- Run the 3 downloaded certificates and save them in the trusted root certification authorities.
- Click [Install certificate].
- Select [Local computer] and click [Next].
- Select [Save all certificates to the following repository] and then select [Trusted root certification authorities] from Browse.
- Press the [Next] button to save the certificate.
Troubleshoot SSL VPN agent execution error issues
If you cannot execute or connect to the SSL VPN agent, check the causes and solutions.
Cause
It cannot be executed or connected because the service is not executed or the network adapter or system file is damaged.
Solution
The solutions are as follows:
- Check the service status.
- Run services.msc.
- Check the status of the following services and if they are not running, click the [Start] button:
- Remote Access Connection Manger
- Remote Access Auto Connection Manger
- Secure Socket Tunneling Protocol Service
- Telephony
- Reinstall the network adapter driver.
- Run devmgmt.msc.
- Remove up to 8 network adapters which start with WAN Miniport.
- Select WAN Miniport and click Action > Remove device.
- Click Action > Scan for hardware changes and reinstall the WAN Miniport network adapter.
- After the reinstallation is complete, check the 8 WAN Miniport network adapters.
- WAN Miniport (IKEv2)
- WAN Miniport (IP)
- WAN Miniport (IPv6)
- WAN Miniport (L2TP)
- WAN Miniport (Network Monitor)
- WAN Miniport (PPPOE)
- WAN Miniport (PPTP)
- WAN Miniport (SSTP)
- Inspect system files.
- Run cmd.exe with the administrator permissions.
- Enter the
sfc /scannowcommands at the command prompt, and then press Enter.
- Reboot after completing all actions.
If you're still having trouble finding what you need, click on the feedback icon and send us your thoughts and requests. We'll use your feedback to improve this guide.