Troubleshooting

In PCS Appliance:

Navigate to System > Log/Monitoring > Events/User Access/Admin Access Log to view any migration related logs

Troubleshooting Tips / Workarounds

Deprecated Auth Server (For example, SiteMinder) seen after the migration from PSA to ISA Appliance.

Workaround:

Remove the deprecated Auth Server and migrate the realms to the supported Authentication Server in ISA Appliance.

Appendix: Sample Screens of Connect Secure

Deprecated Features in Connect Secure

PSA Appliance

ISA appliance

Web Profiles

The screen shows the web application resource profiles on a PSA Appliance. The resource profiles marked with a red crossmark are deprecated on the ISA Appliance.

The screen shows the web application resource profiles on ISA Appliance.

Resource Profiles

The screen shows the resource profiles on PSA Appliance. The Telnet SSH resource profile marked in red is deprecated in ISA Appliance.

The screen shows the Resource profiles on ISA Appliance.

Resource Profiles- File Types

The screen shows the resource profiles on PSA Appliance. The Unix Resource Profile -file type marked in red is deprecated in ISA Appliance

.

The screen shows the ResourceProfile - File type on ISA Appliance.

Resource Profiles- HTML 5

The screen shows the resource profiles on PSA Appliance. The Basic HTML5 Resource Profile marked in red is deprecated in ISA Appliance.

The screen shows the ResourceProfile - HTML5 on ISA Appliance.

Resource Profile - Terminal Services

The screen shows the resource profiles on PSA Appliance. The Java Support marked in red is deprecated in ISA Appliance.

The screen shows the ResourceProfile - Terminal Service on ISA Appliance.

Config List

The screen shows the VPN tunneling configuration options on PSA Appliance. The options highlighted in red are deprecated on ISA Appliance.

The screen shows the option newly added in the PSA Appliance.

User Role Options

The screen shows the settings on PSA Appliance. The options highlighted in red are deprecated on ISA Appliance.

The screen shows the settings on the ISA Appliance.

HC Policy OS

The screen shows the Host Checker (HC) options on PSA Appliance. The Solaris option highlighted in red is deprecated in ISA Appliance.

The screen shows the HC options on ISA Appliance.

HC - Cache Cleaner

The screen shows the Host Checker on PSA Appliance. The Cache Cleaner marked in red is deprecated in ISA Appliance.

The screen shows the HC options on ISA Appliance.

HC - Statement of Health

The screen shows the Host Checker on PSA Appliance. The Statement of health marked in red is deprecated in ISA Appliance.

The screen shows the HC options on ISA Appliance.

Wizard

The screen shows the Host Checker on PSA Appliance. The User Access Policy marked in red is deprecated in ISA Appliance.

The screen shows the wizard on ISA Appliance.

Auth Servers

The screen shows the auth servers on a PSA Appliance. The auth servers marked with red crossmark are deprecated on ISA Appliance.

The screen shows the auth servers on ISA Appliance. The deprecated auth servers, which are migrated from PSA Appliance are shown in red with an asterrick. These servers have to be deleted manually as the enduser logins to these servers will be disabled.

LDAP Auth Server Type

The screen shows the LDAP auth server with different connection types on PSA Appliance. The connection type highlighted in Red are deprecated in ISA Appliance.

The screen shows the LDAP auth server on ISA Appliance.

MDM Server

The screen shows the MDM server with different connection types on PSA Appliance. The connection type highlighted in Red are deprecated in ISA Appliance

The screen shows the MDM server on ISA Appliance.

Hostcheck PASS messages

Info AUT31504 2021-10-17 21:21:17 - NODE_3_3 - [x.x.x.x] username(All Core Features Realm)[Files Role, HTML5 Role, STA Role, Terminal Services Role, VDI Role, Web Role, WSAM Role, All Core Features Role] - Login succeeded for username/All Core Features Realm (session:sid27ff58ec684a85a48b43280bad41f5200490e365dedf089c) from x.x.x.x .

Info AUT22923 2021-10-17 21:21:13 - NODE_3_3 - [x.x.x.x] username(All Core Features Realm)[] - Host Checker policy 'Pulse Secure Endpoint Compliance' passed on host x.x.x.x for user 'username'.

Info AUT24326 2021-10-17 21:20:23 - NODE_3_3 - [x.x.x.x] username(All Core Features Realm)[] - Secondary authentication successful for username/Google TOTP Auth Server from x.x.x.x

Info AUT31666 2021-10-17 21:19:11 - NODE_3_3 - [x.x.x.x] username(All Core Features Realm)[] - Anomaly (new_location) found for username. Prompting for secondary authentication

Info AUT24326 2021-10-17 21:19:11 - NODE_3_3 - [x.x.x.x] username(All Core Features Realm)[] - Primary authentication successful for username/PSBNG-LDAP from x.x.x.x

Info AUT30544 2021-10-17 21:47:36 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - User chose to proceed on the sign-in notification page "Post-sign-In Notification"

Info AUT31984 2021-10-17 21:47:24 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Host Checker Compliance Result - ['Fully Compliant'] on host ['x.x.x.x'] from address [''] for user ['username'], passed_hc_policies:['Pulse Secure Endpoint Compliance'], failed_hc_policies:[''], failed_reasons: [''].

Info AUT22923 2021-10-17 21:47:24 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Host Checker policy 'Pulse Secure Endpoint Compliance' passed on host x.x.x.x for user 'username'.

Info AUT24326 2021-10-17 21:46:47 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Secondary authentication successful for username/Google TOTP Auth Server from x.x.x.x

Info AUT31666 2021-10-17 21:46:40 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Anomaly (new_location) found for username. Prompting for secondary authentication

Info AUT24326 2021-10-17 21:46:40 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Primary authentication successful for username/PSBNG-LDAP from x.x.x.x

HostCheck FAIL messages

Info AUT22925 2021-10-17 21:33:00 - NODE_3_3 - [x.x.x.x] username(All Core Features Realm)[] - Host Checker policy 'Pulse Secure Endpoint Compliance' failed on host x.x.x.x . Reason: 'Rule-Compliance-WIN-AS:Windows Defender 6.1.7600.16385 does not comply with policy. Compliance requires real time protection enabled.; Rule-Compliance-WIN-FW:Windows Firewall 6.1.7600.16385 does not comply with policy. Compliance requires firewall to be turned on.; Rule-Compliance-WIN-AV:Windows Defender 6.1.7600.16385 does not comply with policy. Compliance requires real time protection enabled and latest virus definitions and successful complete system scan.'.

Info AUT24326 2021-10-17 21:32:23 - NODE_3_3 - [x.x.x.x] username(All Core Features Realm)[] - Secondary authentication successful for username/Google TOTP Auth Server from x.x.x.x

Info AUT31760 2021-10-17 21:32:10 - NODE_3_3 - [x.x.x.x] username(All Core Features Realm)[] - Detected first time login for user 'username'. Prompting for secondary authentication.

Info AUT24326 2021-10-17 21:32:10 - NODE_3_3 - [x.x.x.x] username(All Core Features Realm)[] - Primary authentication successful for username/PSBNG-LDAP from x.x.x.x

Info AUT31984 2021-10-17 22:46:03 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Host Checker Compliance Result - ['Fully Non Compliant'] on host ['x.x.x.x'] from address [''] for user ['username'], passed_hc_policies:[''], failed_hc_policies:['Pulse Secure Endpoint Compliance'], failed_reasons: ['Rule-Compliance-WIN-AS:Anti-Spyware software listed in security requirements is not installed.; Rule-Compliance-WIN-AV:Anti-Virus software listed in security requirements is not installed.'].

Info AUT22925 2021-10-17 22:46:03 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Host Checker policy 'Pulse Secure Endpoint Compliance' failed on host x.x.x.x . Reason: 'Rule-Compliance-WIN-AS:Anti-Spyware software listed in security requirements is not installed.; Rule-Compliance-WIN-AV:Anti-Virus software listed in security requirements is not installed.'.

Info AUT24326 2021-10-17 22:45:21 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Secondary authentication successful for username/Google TOTP Auth Server from x.x.x.x

Info AUT31666 2021-10-17 22:45:02 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Anomaly (new_location) found for username. Prompting for secondary authentication

Info AUT24326 2021-10-17 22:45:02 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Primary authentication successful for username/PSBNG-LDAP from x.x.x.x

Appendix: Sample Screens of Policy Secure

Deprecated Features in Policy Secure

PSA Appliance

ISA Appliance

HC Policy OS

The screen shows the Host Checker (HC) options on PSA Appliance. The Solaris option highlighted in red is deprecated in ISA Appliance.

The screen shows the HC options on ISA Appliance.

HC - Cache Cleaner

The screen shows the Host Checker on PSA Appliance. The Cache Cleaner marked in red is deprecated in ISA Appliance.

The screen shows the HC options on ISA Appliance.

HC - Statement of Health

The screen shows the Host Checker on PSA Appliance. The Statement of health marked in red is deprecated in ISA Appliance.

The screen shows the HC options on ISA Appliance.

Wizard

The screen shows the Host Checker on PSA Appliance. The User Access Policy marked in red is deprecated in ISA Appliance.

The screen shows the wizard on ISA Appliance.

Auth Servers

The screen shows the auth servers on a PSA Appliance. The auth servers marked with red crossmark are deprecated on ISA Appliance.

The screen shows the auth servers on ISA Appliance. The deprecated auth servers, which are migrated from PSA Appliance are shown in red with an asterrick. These servers have to be deleted manually as the enduser logins to these servers will be disabled.

LDAP Auth Server Type

The screen shows the LDAP auth server with different connection types on PSA Appliance. The connection type highlighted in Red are deprecated in ISA Appliance.

The screen shows the LDAP auth server on ISA Appliance.

MDM Server

The screen shows the MDM server with different connection types on PSA Appliance. The connection type highlighted in Red are deprecated in ISA Appliance

 

The screen shows the MDM server on ISA Appliance.

Hostcheck PASS messages

Info AUT31504 2021-10-17 21:21:17 - NODE_3_3 - [x.x.x.x] username(All Core Features Realm)[Files Role, HTML5 Role, STA Role, Terminal Services Role, VDI Role, Web Role, WSAM Role, All Core Features Role] - Login succeeded for username/All Core Features Realm (session:sid27ff58ec684a85a48b43280bad41f5200490e365dedf089c) from x.x.x.x .

Info AUT22923 2021-10-17 21:21:13 - NODE_3_3 - [x.x.x.x] username(All Core Features Realm)[] - Host Checker policy 'Pulse Secure Endpoint Compliance' passed on host x.x.x.x for user 'username'.

Info AUT24326 2021-10-17 21:20:23 - NODE_3_3 - [x.x.x.x] username(All Core Features Realm)[] - Secondary authentication successful for username/Google TOTP Auth Server from x.x.x.x

Info AUT31666 2021-10-17 21:19:11 - NODE_3_3 - [x.x.x.x] username(All Core Features Realm)[] - Anomaly (new_location) found for username. Prompting for secondary authentication

Info AUT24326 2021-10-17 21:19:11 - NODE_3_3 - [x.x.x.x] username(All Core Features Realm)[] - Primary authentication successful for username/PSBNG-LDAP from x.x.x.x

Info AUT30544 2021-10-17 21:47:36 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - User chose to proceed on the sign-in notification page "Post-sign-In Notification"

Info AUT31984 2021-10-17 21:47:24 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Host Checker Compliance Result - ['Fully Compliant'] on host ['x.x.x.x'] from address [''] for user ['username'], passed_hc_policies:['Pulse Secure Endpoint Compliance'], failed_hc_policies:[''], failed_reasons: [''].

Info AUT22923 2021-10-17 21:47:24 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Host Checker policy 'Pulse Secure Endpoint Compliance' passed on host x.x.x.x for user 'username'.

Info AUT24326 2021-10-17 21:46:47 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Secondary authentication successful for username/Google TOTP Auth Server from x.x.x.x

Info AUT31666 2021-10-17 21:46:40 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Anomaly (new_location) found for username. Prompting for secondary authentication

Info AUT24326 2021-10-17 21:46:40 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Primary authentication successful for username/PSBNG-LDAP from x.x.x.x

HostCheck FAIL messages

Info AUT22925 2021-10-17 21:33:00 - NODE_3_3 - [x.x.x.x] username(All Core Features Realm)[] - Host Checker policy 'Pulse Secure Endpoint Compliance' failed on host x.x.x.x . Reason: 'Rule-Compliance-WIN-AS:Windows Defender 6.1.7600.16385 does not comply with policy. Compliance requires real time protection enabled.; Rule-Compliance-WIN-FW:Windows Firewall 6.1.7600.16385 does not comply with policy. Compliance requires firewall to be turned on.; Rule-Compliance-WIN-AV:Windows Defender 6.1.7600.16385 does not comply with policy. Compliance requires real time protection enabled and latest virus definitions and successful complete system scan.'.

Info AUT24326 2021-10-17 21:32:23 - NODE_3_3 - [x.x.x.x] username(All Core Features Realm)[] - Secondary authentication successful for username/Google TOTP Auth Server from x.x.x.x

Info AUT31760 2021-10-17 21:32:10 - NODE_3_3 - [x.x.x.x] username(All Core Features Realm)[] - Detected first time login for user 'username'. Prompting for secondary authentication.

Info AUT24326 2021-10-17 21:32:10 - NODE_3_3 - [x.x.x.x] username(All Core Features Realm)[] - Primary authentication successful for username/PSBNG-LDAP from x.x.x.x

Info AUT31984 2021-10-17 22:46:03 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Host Checker Compliance Result - ['Fully Non Compliant'] on host ['x.x.x.x'] from address [''] for user ['username'], passed_hc_policies:[''], failed_hc_policies:['Pulse Secure Endpoint Compliance'], failed_reasons: ['Rule-Compliance-WIN-AS:Anti-Spyware software listed in security requirements is not installed.; Rule-Compliance-WIN-AV:Anti-Virus software listed in security requirements is not installed.'].

Info AUT22925 2021-10-17 22:46:03 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Host Checker policy 'Pulse Secure Endpoint Compliance' failed on host x.x.x.x . Reason: 'Rule-Compliance-WIN-AS:Anti-Spyware software listed in security requirements is not installed.; Rule-Compliance-WIN-AV:Anti-Virus software listed in security requirements is not installed.'.

Info AUT24326 2021-10-17 22:45:21 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Secondary authentication successful for username/Google TOTP Auth Server from x.x.x.x

Info AUT31666 2021-10-17 22:45:02 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Anomaly (new_location) found for username. Prompting for secondary authentication

Info AUT24326 2021-10-17 22:45:02 - DFS_NODE_3_92 - [x.x.x.x] Default Network::username(All Core Features Realm)[][] - Primary authentication successful for username/PSBNG-LDAP from x.x.x.x