Troubleshooting: Transaction Log Service Test Fails With "There Was No Endpoint Listening" Error

Follow
    Applies to:
  • SecureAuth Identity Platform
Deployment model:
  • Cloud
  • Hybrid
  • On Premises
  • Version Affected: All
     
     

    Overview

    The SecureAuth Transaction Log Service reports connectivity errors when it can't reach its cloud endpoint. This can show up in three different ways: a SOAP error while a user is completing the post-authentication portion of a workflow, the exception below when the Trx Log Service URL test is run from the System Info tab, or -- in extreme cases -- an HTTP 503 Service Unavailable error for all users if the application pool fails outright.

    Exception: There was no endpoint listening at http://cloud.secureauth.com/SATransaction/Transaction.svc that could accept the message. This is often caused by an incorrect address or SOAP action. See InnerException, if present, for more details. Inner exception: Unable to connect to the remote server.

     

    Cause

    Connectivity from the appliance to cloud.gosecureauth.com is blocked, either by a firewall on the customer's network or by Windows Firewall with Advanced Security running on the SecureAuth appliance itself.

     

    Resolution:

    1. Confirm outbound connectivity from the appliance to cloud.gosecureauth.com (209.134.48.130) on TCP/80 is allowed by the customer's corporate firewall(s). Although this traffic uses port 80, the appliance encrypts the data before sending it, so this is still a secure connection.
    2. Confirm Windows Firewall with Advanced Security on the appliance also allows that same outbound connectivity. Appliances provisioned before October 2013 may not have this rule configured; the SecureAuth 7.4.3 update package (or later) adds the IP address to the local Windows Advanced Firewall automatically, but it can still be worth confirming directly:
      1. Open Windows Firewall with Advanced Security and check the outbound rule covering this traffic.
      2. In the rule's Remote IP address section, confirm there is an entry for 209.134.48.130.
      3. If the entry is missing, add it: in the IP Address window, under This IP address or subnet, enter 209.134.48.130 and click OK.




     

    SecureAuth Knowledge Base Articles provide information based on specific use cases and may not apply to all appliances or configurations. Be advised that these instructions could cause harm to the environment if not followed correctly or if they do not apply to the current use case.

    Customers are responsible for their own due diligence prior to utilizing this information and agree that SecureAuth is not liable for any issues caused by misconfiguration directly or indirectly related to SecureAuth products.

    0 out of 0 found this helpful

    Comments

    0 comments

    Please sign in to leave a comment.