VMware Horizon Community
stevan44
Enthusiast
Enthusiast

Unable to access UAG login page (first time deployment)

I have deployed euc-unified-access-gateway-21.11.0.0-18970468_OVF10.ova in a test lab. I've answered the questions that are required during the OVF setup. It will load and run with the IP address I have assigned (192.168.44.44) single NIC configuration. I can ping this IP, but I can not connect to it using Https:\\192.168.44.44:9443. 

I ran a port checker and it does not see the 9443 port open. I'm not sure what the issues is and would greatly appreciate any help in finding a solution to this problem.

 

Labels (1)
0 Kudos
16 Replies
ch4mp10n
Contributor
Contributor

Can you login using Root, into the UAG can you also telnet onto to the IP over that port? is the firewall open between your subnet and that IP?

stevan44
Enthusiast
Enthusiast

Yes I can login to root. Firewall is open allowing 9443 and 443 to access UAG. Telnetting to the UAG using 9443 is not working. I ran a port scanner on the UAG server no ports are shown to be open. I would image that the ports are used by default within the OVA image and are appended to what ever the IP that you assign. 

 

0 Kudos
stevan44
Enthusiast
Enthusiast

Is there a way to login into with root and configure the ports?

0 Kudos
sjesse
Leadership
Leadership

Check the network connection settings, run the command as "cd /opt/vmware/share/vami" then the command "./vami_config_net"

stevan44
Enthusiast
Enthusiast

I've done as you asked, but its not showing anything that would show why UAG is not listening on TCP port 9443. In fact the network settings are correct, except for the DNS (this should not be the cause of the problem). This appears to be something with the UAG ova that is not working. I placed a laptop in the DMZ and tried to access the web admin page but it could not connect either, this eliminates firewall rules.

Is there a way to check UAG TCP/UDP ports settings as root?

 

stevan44_0-1642616023772.png

 

 

0 Kudos
stevan44
Enthusiast
Enthusiast

Is this issue posted in the right forum area? if so where are the Horizon/UAG experts?

Tags (1)
0 Kudos
sjesse
Leadership
Leadership

Most people volunteer their time, including me, so you may not get a response as quick as you would like. I just deployed euc-unified-access-gateway-21.11.1.0-19072784_OVF10 just a few days ago in my lab again and it worked fine. These appliances are setup to be deployed and thrown away if they don't work , so there is limited troubleshooting that widely available. Take a look in /opt/vmware/gateway/logs and look at the admin.log and see if there are any hints. Like I mentioned before most of the time its a some misconfiguration of the network settings, I suggest deleting it and trying to redeploy it a few times if you haven't, its possible the one you had just didn't deploy correctly.

0 Kudos
stevan44
Enthusiast
Enthusiast

It looks like the Web ui is not being enabled. I'm thinking it a a problem with the version of UAG that I'm using. I don't have the latest one that you used so I can't verify that assumption. 

0 Kudos
sjesse
Leadership
Leadership

Where did you get it? If you have a support agreement with vmware you should be able to download it, plus you could open a ticket there. If you use something like vmug advantage, I think the version I have came from there. I can't say without personally looking, but I'm not aware of a version where the admin ui doesn't start without some sort of misconfiguration, if so there should be other posts here maybe that could help.

0 Kudos
stevan44
Enthusiast
Enthusiast

It was from my old job, which I have since left. The version should not matter, Admin Ui does not seem to be enabled during the configuration. I have used the OVA configuration method and not the scripts but that should not matter. I know that the configuration is correct and I have deployed it multiple times with same results.

 

 

0 Kudos
stevan44
Enthusiast
Enthusiast

I found  found this link, if it does not work then you may have this issue. 

https:.minarik.io/can-you-deploy-uag-directly-on-esxi-host

 

0 Kudos
sjesse
Leadership
Leadership

If this is for your own needs, I'd look at vmug advantage, its $200 a year and you can download new ones. its possible the file you hagve is damaged, I install alot of these and follow these forums pretty reguraly and having seen many if all issues with a version that didn't have the admin ui not start if you deployed it via the ova properties correctly. Maybe you might get someone from vmware to confirm directly, as I do not work for them, so they may have internal documents they can check.

0 Kudos
stevan44
Enthusiast
Enthusiast

Yes, this is for my own needs for testing.  The vmug advantage for $200 is not a bad deal, but I can't justify it for this one issue only.

After all that I've have seen it was leading me to believe that the ova may have been corrupt. But after digging in to details of using euc-unified-access-gateway-21.11.0.0-18970468_OVF10.ova, I discovered it was to be used in vCenter. I was using ESXi to deploy it. So I installed vCenter.

 

Also I added info to the ova configuration script for:

tcp/9443/UAG IP address:9443

 

stevan44_0-1643039800935.png

After the UAG started up and the Admin UI came up.  I don't think you have to do this but I figured it can't hurt.

I hope this help others who may be having the same issue. You can make this as solved.

 

0 Kudos
bwnets
Contributor
Contributor

Stevan44,

Just so you know, I was running into the same issue - deploying in vCenter.  I could connect to the vm just fine on port 22, however port 9443 or 443 were not open - entered the line you suggested here and was able to get to the management interface!   Tried 3 different OVA versions  2109, 2111 and 2302  all with the same exact issue.

0 Kudos
znil
Contributor
Contributor

I answer here because google will show you this thread for that problem first:

As you can see in this thread: https://communities.vmware.com/t5/Horizon-Desktops-and-Apps/Unified-Access-Gateway-Admin-Portal-SOLV...

 

The reason is then the password is "wrong". Then will the creation of the admin account fail, if that fail it is the same as then you have no admin password set. Without admin Password no Admin GUI will be available.

The password should be at least 16 characters long.
In addition, at least one of the following special characters must also occur: !@$%^&+()
And the usual like upper case letters, lower case letters and numbers

 

0 Kudos
mhkhoshraftar
Contributor
Contributor

It's all about the password complexity. You must choose correct the password policy when you deploy your OVA.

Only a-z, 0-9, underscrore (_) and hyphen(-) are allowed. Minimum length is 16 and Maximum length is 32.

0 Kudos