SCCM v2010 unable to retrieve AD site membership over VPN - boundaries are created

Constantine J. Koulis 26 Reputation points
2020-12-17T15:39:29.803+00:00

hello,

we have SCCM v2010 and I am trying to provide updates at the clients which are connected through VPN but it doenst seem to work.

I have the boundaries defined and specifically the IP range of the VPN which is 192.168.150.5 - 192.168.150.254.

when I look at my computer (connected through VPN) at the locationservices.log I see the below:


Updating portal certificates LocationServices 12/17/2020 9:13:55 AM 3892 (0x0F34)*
There are no certificates available to install LocationServices 12/17/2020 9:13:55 AM 3892 (0x0F34)
1 assigned MP errors in the last 10 minutes, threshold is 5. LocationServices 12/17/2020 9:15:44 AM 16572 (0x40BC)
Unable to retrieve AD site membership LocationServices 12/17/2020 9:28:56 AM 5092 (0x13E4)
Unable to retrieve AD site membership LocationServices 12/17/2020 9:28:56 AM 5092 (0x13E4)
Reset assigned MP error count LocationServices 12/17/2020 9:28:56 AM 6408 (0x1908)
Received reply of type PortalCertificateReply LocationServices 12/17/2020 9:28:56 AM 9964 (0x26EC)
The reply from location manager contains 0 certificates LocationServices 12/17/2020 9:28:56 AM 9964 (0x26EC)
Updating portal certificates LocationServices 12/17/2020 9:28:56 AM 9964 (0x26EC)
There are no certificates available to install LocationServices 12/17/2020 9:28:56 AM 9964 (0x26EC)*


Worth to say that when on corporate network then it works like a charm.

any ideas of what I need to check/ do?

thank you

Microsoft Security | Intune | Configuration Manager | Other
0 comments No comments
{count} votes

Accepted answer
  1. Youssef Saad 3,416 Reputation points
    2020-12-17T19:57:51.6+00:00

    Hi,

    Are you using PKI certificate to communicate with the MP?

    Make sure that all necessary ports are allowed on your network firewall between your VPN Clients <> Domain controller / Site server / DP / SUP etc.

    Regards,


    Youssef Saad | New blog: https://youssef-saad.blogspot.com
    Please remember to ** “Accept answer” ** for useful answers, thank you!

    0 comments No comments

5 additional answers

Sort by: Most helpful
  1. AllenLiu-MSFT 49,316 Reputation points Microsoft External Staff
    2020-12-18T06:50:45.323+00:00

    @Constantine J. Koulis
    Thank you for posting in Microsoft Q&A forum.
    Did you add your VPN boundary to your boundary group that has a DP assigned?
    Also, more detailed log could be more useful.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.