Bobcares

Authenticate to WorkSpace using WorkSpaces client in amazon

by | Jan 29, 2022

Are you unable to authenticate to WorkSpace using WorkSpaces client in Amazon? We can help you.

Here, at Bobcares, we assist our customers with several AWS queries as part of our AWS Support Services.

Today, let us see steps followed by our Support Techs to resolve it.

 

Unable to authenticate to WorkSpace using WorkSpaces client in Amazon?

The Amazon WorkSpaces client depends on many special services and network settings.

When the client fails to load the WorkSpace, that failure is usually because one of these prerequisites is incorrectly configured or unavailable.

Today, let us see the common errors and solutions provided by our Support Techs.

After authenticating, the Amazon WorkSpaces client expands and displays a gray “Loading…” screen for a while before returning to the login screen. No other error message appears.

This error usually indicates that the Amazon WorkSpaces client can authenticate over port 443, but can’t establish a streaming connection over port 4172.

This can happen when network prerequisites aren’t met.

Issues on the client side often cause the network check in the bottom-right corner of the client to fail.

Click the icon (typically a red triangle with an exclamation point) to see which health checks are failing.

Note: The most common cause is a client-side firewall or proxy preventing access over port 4172 (TCP and UDP).

If this health check fails, check your local firewall settings.

Passing the network check often indicates a problem with network configuration on the WorkSpace.

 

“WorkSpace Status: Unhealthy. We were unable to connect you to your WorkSpace. Please try again in a few minutes.”

This error usually indicates that the SkyLightWorkSpacesConfigService service isn’t responding to health checks.

If you just reboot or start your WorkSpace, wait a few minutes, and then try again.

If the WorkSpace has been running for some time and you still see this error, verify that the SkyLightWorkSpacesConfigService service:

  • is running
  • is set to start automatically
  • can communicate over the management interface (eth0)
  • isn’t block by any third-party antivirus software

To verify that the SkyLightWorkSpacesConfigService service meets the preceding requirements, follow these steps:

1.Firstly, connect using RDP.

2.Then open Windows PowerShell, and then run the following command:

netstat -ano | findstr "8200"

This returns the following:

TCP Management_IP_Address_Of_WorkSpace:8200 0.0.0.0:0

If the command doesn’t return the preceding entry, verify that SkyLightWorkSpacesConfigService is running.

If it’s stops, start it. Within a minute, the service begins listening on TCP port 8200 for the private IP address of your WorkSpace.

 

“An error occurred while launching your WorkSpace. Please try again.”

This error often occurs when the WorkSpace can’t load the Windows desktop using PCoIP.

Check the following:

  • Interactive logon banner group policies currently aren’t support on Amazon WorkSpaces.

Try moving the WorkSpace to an organizational unit (OU) where the Interactive logon: Message text for users attempting to log on group policy isn’t applied.

  • If the PCoIP agent is uninstalled, reboot the WorkSpace through the Amazon WorkSpaces console to reinstall it automatically.
  • This message also appears if the PCoIP Standard Agent for Windows service isn’t running.

Follow these steps to verify that the service is running, set to start automatically, and can communicate over the management interface (eth0):

1. Firstly, connect using RDP.

2. Then, open Windows PowerShell and run the following command:

netstat -ano | findstr "8200"

This returns the following:

TCP Management_IP_Address_Of_WorkSpace:8200 0.0.0.0:0

If the command doesn’t return the preceding entry, verify that SkyLightWorkSpacesConfigService is running.

If it stops, start it.

Within a minute, the service begins listening on TCP port 8200 for the private IP address of your WorkSpace.

3. Finally, run the following command:

netstat -ano | findstr "4172"

This returns the following:

TCP Management_IP_Address_Of_WorkSpace:4172 0.0.0.0:0 LISTENING

If the command doesn’t return the preceding entry, verify that PCoIP Standard Agent for Windows is running.

You can also run the following command to see if all dependencies are running:

tasklist | findstr "pcoip"

Expected output:

pcoip_agent.exe

You might also receive this error on the Amazon WorkSpaces client after a long delay if the WorkSpaces security group is modified to restrict outbound traffic.

An outbound traffic restriction prevents Windows from communicating with your directory controllers for login.

Verify that your security groups allow your WorkSpaces to communicate with your directory controllers on all required ports over its primary network interface.

 

“This device is not authorized to access the WorkSpace. Please contact your administrator for assistance.”

This error indicates that IP access control groups are configured on your WorkSpace directory, but the client IP address isn’t on an allow list.

Check the settings on your directory.

Confirm that the public IP address the user is connecting from allows access to the WorkSpace.

Note: By default, Linux client access is disabled.

[Need help with the process? We’d be happy to assist]

Conclusion

In short, we saw how our Support Techs resolve Authentication error in Amazon.

 

PREVENT YOUR SERVER FROM CRASHING!

Never again lose customers to poor server speed! Let us help you.

Our server experts will monitor & maintain your server 24/7 so that it remains lightning fast and secure.

GET STARTED

0 Comments

Submit a Comment

Your email address will not be published. Required fields are marked *

Never again lose customers to poor
server speed! Let us help you.

Privacy Preference Center

Necessary

Necessary cookies help make a website usable by enabling basic functions like page navigation and access to secure areas of the website. The website cannot function properly without these cookies.

PHPSESSID - Preserves user session state across page requests.

gdpr[consent_types] - Used to store user consents.

gdpr[allowed_cookies] - Used to store user allowed cookies.

PHPSESSID, gdpr[consent_types], gdpr[allowed_cookies]
PHPSESSID
WHMCSpKDlPzh2chML

Statistics

Statistic cookies help website owners to understand how visitors interact with websites by collecting and reporting information anonymously.

_ga - Preserves user session state across page requests.

_gat - Used by Google Analytics to throttle request rate

_gid - Registers a unique ID that is used to generate statistical data on how you use the website.

smartlookCookie - Used to collect user device and location information of the site visitors to improve the websites User Experience.

_ga, _gat, _gid
_ga, _gat, _gid
smartlookCookie
_clck, _clsk, CLID, ANONCHK, MR, MUID, SM

Marketing

Marketing cookies are used to track visitors across websites. The intention is to display ads that are relevant and engaging for the individual user and thereby more valuable for publishers and third party advertisers.

IDE - Used by Google DoubleClick to register and report the website user's actions after viewing or clicking one of the advertiser's ads with the purpose of measuring the efficacy of an ad and to present targeted ads to the user.

test_cookie - Used to check if the user's browser supports cookies.

1P_JAR - Google cookie. These cookies are used to collect website statistics and track conversion rates.

NID - Registers a unique ID that identifies a returning user's device. The ID is used for serving ads that are most relevant to the user.

DV - Google ad personalisation

_reb2bgeo - The visitor's geographical location

_reb2bloaded - Whether or not the script loaded for the visitor

_reb2bref - The referring URL for the visit

_reb2bsessionID - The visitor's RB2B session ID

_reb2buid - The visitor's RB2B user ID

IDE, test_cookie, 1P_JAR, NID, DV, NID
IDE, test_cookie
1P_JAR, NID, DV
NID
hblid
_reb2bgeo, _reb2bloaded, _reb2bref, _reb2bsessionID, _reb2buid

Security

These are essential site cookies, used by the google reCAPTCHA. These cookies use an unique identifier to verify if a visitor is human or a bot.

SID, APISID, HSID, NID, PREF
SID, APISID, HSID, NID, PREF