Forum Discussion

Rhys_Peters_770's avatar
Rhys_Peters_770
Historic F5 Account
Apr 10, 2014

APM Internal Error

I have a customer who has implemented an network access SSL VPN APM policy. They are running 11.4.1 HF2.

 

Since going live there are inconsistencies when logging in. The policy is making use of AD auth and an SMS OTP. A failed connection shows both of these auth mechanisms being successful, however, the webtop presents an internal error. For a failed connection the following debug entry is missing from the end of the logs:

 

Apr 9 15:00:44 N-MEL-LTM01 notice tmm3[12500]: 01490549:5: 452cb07e: Assigned PPP IPv4: 10.3.90.108 Tunnel Type: VPN_TUNNELTYPE_TLS NA Resource: /Common/na_vpn.symbion.com.au

 

There is no indication in the logs of what this internal error is. I have checked the lease pool and there are plenty of IP addresses available (there are 250 assigned to the pool).

 

A subsequent connection attempt is successful. Has anyone had a similar issue to this one in the past?

 

1 Reply

  • kunjan's avatar
    kunjan
    Icon for Nimbostratus rankNimbostratus

    You may be able to troubleshoot by:

     

    1) Enable debug on the client end

     

    http://support.f5.com/kb/en-us/solutions/public/12000/400/sol12444.html

     

    2) Enable debug on the server end

     

    tmsh modify sys db log.accesscontrol.level value debug check /var/log/apm

     

    3) Do a packet capture and decrypt

     

    http://support.f5.com/kb/en-us/solutions/public/10000/200/sol10209.html