<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cannot connect to highly available portal version 10.8.1 with error message: You are not authorized to use this resource. in ArcGIS Enterprise Portal Questions</title>
    <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/cannot-connect-to-highly-available-portal-version/m-p/1008836#M10285</link>
    <description>&lt;P&gt;We have found the solution. Eventually, it was the value of&amp;nbsp;&amp;nbsp;privatePortalURL.&lt;/P&gt;&lt;P&gt;There is a small note at the documentation of &lt;A href="https://enterprise.arcgis.com/en/portal/latest/administer/windows/configuring-a-highly-available-portal.htm" target="_self"&gt;configuring a highly available portal&lt;/A&gt;:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;If the&amp;nbsp;privatePortalURL&amp;nbsp;is different from the&amp;nbsp;WebContextURL, do not set the&amp;nbsp;X-Forwarded-Host&amp;nbsp;header for this URL.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I used the same value for the two parameters&amp;nbsp;privatePortalURL and&amp;nbsp;WebContextURL. We have also configure our portal for IWA.&lt;/P&gt;&lt;P&gt;The&amp;nbsp;privatePortalURL is not only&amp;nbsp;used for communication between the federated ArcGIS Server and the portal, but also between the portal machines that participate in the portal site.&lt;/P&gt;&lt;P&gt;When the primary machine restarted, then the internal communication was happening via the public load balancer and that was triggering a windows authentication.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;If IWA is configured, then the&amp;nbsp;privatePortalURL must have a different value than the&amp;nbsp;WebContextURL.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I have unset temporarily the&amp;nbsp;privatePortalURL and everything works fine. We have asked from our system administrator a load balancer address which goes through the 7443 port, bypassing the windows authentication.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Fri, 11 Dec 2020 10:20:55 GMT</pubDate>
    <dc:creator>MichailMarinakis1</dc:creator>
    <dc:date>2020-12-11T10:20:55Z</dc:date>
    <item>
      <title>Cannot connect to highly available portal version 10.8.1 with error message: You are not authorized to use this resource.</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/cannot-connect-to-highly-available-portal-version/m-p/1006572#M10264</link>
      <description>&lt;P&gt;Hi all,&amp;nbsp;&lt;/P&gt;&lt;P&gt;we have the following issue in our highly available (HA) portal, version 10.8.1.&amp;nbsp;&lt;/P&gt;&lt;P&gt;Our configuration is:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;2 portal machines, running on windows server 2019, on premise, with https only connection and domain certificates.&lt;/LI&gt;&lt;LI&gt;ArcGIS portal content is located to a shared folder, highly available, both machines have stable access to the folder (using a domain account for the service)&lt;/LI&gt;&lt;LI&gt;2 web adaptors pointing to each server&lt;/LI&gt;&lt;LI&gt;1 load balancer, pointing to the 2 web adaptors. The value of the load balancer is set to the&amp;nbsp;WebContextURL&lt;/LI&gt;&lt;LI&gt;No federation yet.&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Workflow to reproduce the issue:&lt;/P&gt;&lt;OL&gt;&lt;LI&gt;After initial installation, we checked the health status of every server, everything was fine.&lt;/LI&gt;&lt;LI&gt;We checked, from the portaladmin page, the SSL Certificates for each machine, they are properly set.&amp;nbsp;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;&amp;nbsp;The links to generate tokens for both machines work properly e.g.&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://machine.domain.com:7443/arcgis/sharing/rest/generateToken" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;https://standbymachine.domain.com:7443/arcgis/sharing/rest/generateToken&lt;/A&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;Index status is aligned properly with the store.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;STRONG&gt;We stop the windows portal service for the primary portal machine.&lt;/STRONG&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;HA function kicks in, switches the standby to primary. &lt;STRONG&gt;Everything OK.&amp;nbsp;&lt;/STRONG&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;&lt;SPAN&gt;We restart the stopped windows service, approximately some minutes after the stop.&lt;/SPAN&gt;&lt;/LI&gt;&lt;/OL&gt;&lt;P&gt;&lt;SPAN&gt;Expected Behavior:&lt;/SPAN&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;No issues...&amp;nbsp;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Actual Behavior:&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;In D:\arcgisportal for both servers, we have extra folders with name e.g.&amp;nbsp;db1606979894714&lt;/LI&gt;&lt;LI&gt;When we click on the ssl certificates for the standby machine, all the values are null&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-center" image-alt="Screenshot 2020-11-25 153921.png" style="width: 599px;"&gt;&lt;img src="https://community.esri.com/t5/image/serverpage/image-id/1416i7D2B1F9B3F86DB32/image-dimensions/599x241?v=v2" width="599" height="241" role="button" title="Screenshot 2020-11-25 153921.png" alt="Screenshot 2020-11-25 153921.png" /&gt;&lt;/span&gt;&lt;/P&gt;&lt;UL&gt;&lt;LI&gt;&lt;SPAN&gt;The links to generate tokens for the standby machine (sometimes for both machines!) is not accessible with error 404 e.g.&amp;nbsp;&lt;/SPAN&gt;&lt;A href="https://machine.domain.com:7443/arcgis/sharing/rest/generateToken" target="_blank" rel="noopener nofollow noopener noreferrer"&gt;https://standbymachine.domain.com:7443/arcgis/sharing/rest/generateToken&lt;/A&gt;&lt;SPAN&gt;. In general the arcgis/sharing/rest is not accessible.&lt;/SPAN&gt;&lt;/LI&gt;&lt;LI&gt;We cannot connect to the portaladmin, using the url ...:7443/arcgis/portaladmin with&amp;nbsp;error message: &lt;STRONG&gt;You are not authorized to use this resource.&amp;nbsp;&lt;/STRONG&gt;&lt;/LI&gt;&lt;/UL&gt;&lt;P&gt;Workaround:&lt;/P&gt;&lt;P&gt;Stop the windows service for the standby machine again.&lt;/P&gt;&lt;P&gt;Sometimes, when we wait a bit and stop the standby machine again, wait some more, and start it again, then everything is back to normal.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Similar issue has been reported &lt;A title="AWS 10.8.1 HA Portal not restarting" href="https://community.esri.com/t5/arcgis-enterprise-questions/aws-10-8-1-ha-portal-not-restarting/td-p/146314" target="_self"&gt;here&lt;/A&gt;.&lt;/P&gt;&lt;P&gt;Any feedback will be very useful. Thanks!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 03 Dec 2020 13:18:54 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/cannot-connect-to-highly-available-portal-version/m-p/1006572#M10264</guid>
      <dc:creator>MichailMarinakis1</dc:creator>
      <dc:date>2020-12-03T13:18:54Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot connect to highly available portal version 10.8.1 with error message: You are not authorized to use this resource.</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/cannot-connect-to-highly-available-portal-version/m-p/1008836#M10285</link>
      <description>&lt;P&gt;We have found the solution. Eventually, it was the value of&amp;nbsp;&amp;nbsp;privatePortalURL.&lt;/P&gt;&lt;P&gt;There is a small note at the documentation of &lt;A href="https://enterprise.arcgis.com/en/portal/latest/administer/windows/configuring-a-highly-available-portal.htm" target="_self"&gt;configuring a highly available portal&lt;/A&gt;:&lt;/P&gt;&lt;P&gt;&lt;EM&gt;If the&amp;nbsp;privatePortalURL&amp;nbsp;is different from the&amp;nbsp;WebContextURL, do not set the&amp;nbsp;X-Forwarded-Host&amp;nbsp;header for this URL.&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;I used the same value for the two parameters&amp;nbsp;privatePortalURL and&amp;nbsp;WebContextURL. We have also configure our portal for IWA.&lt;/P&gt;&lt;P&gt;The&amp;nbsp;privatePortalURL is not only&amp;nbsp;used for communication between the federated ArcGIS Server and the portal, but also between the portal machines that participate in the portal site.&lt;/P&gt;&lt;P&gt;When the primary machine restarted, then the internal communication was happening via the public load balancer and that was triggering a windows authentication.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;If IWA is configured, then the&amp;nbsp;privatePortalURL must have a different value than the&amp;nbsp;WebContextURL.&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;I have unset temporarily the&amp;nbsp;privatePortalURL and everything works fine. We have asked from our system administrator a load balancer address which goes through the 7443 port, bypassing the windows authentication.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 11 Dec 2020 10:20:55 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/cannot-connect-to-highly-available-portal-version/m-p/1008836#M10285</guid>
      <dc:creator>MichailMarinakis1</dc:creator>
      <dc:date>2020-12-11T10:20:55Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot connect to highly available portal version 10.8.1 with error message: You are not authorized to use this resource.</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/cannot-connect-to-highly-available-portal-version/m-p/1038942#M10705</link>
      <description>&lt;P&gt;Hello&amp;nbsp;&lt;a href="https://community.esri.com/t5/user/viewprofilepage/user-id/298169"&gt;@MichailMarinakis1&lt;/a&gt;,&lt;/P&gt;&lt;P&gt;Wahou, your configuration is almost identical as mine except that I am not using IWA but I do have Web Adaptor for reverse proxying. I already have a load balancer balancing on 7443 private portal URL which in my case is different that the public one.&lt;/P&gt;&lt;P&gt;But I still face the same issue. If one portal is deconnected and reconnected again, then the whole portal is messed up and you cannot access 'portaladmin', etc..&lt;/P&gt;&lt;P&gt;So I am wondering what could be the issue for me as Windows authentification is already out of the equation...&lt;/P&gt;</description>
      <pubDate>Wed, 24 Mar 2021 14:15:59 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/cannot-connect-to-highly-available-portal-version/m-p/1038942#M10705</guid>
      <dc:creator>NicolasGIS</dc:creator>
      <dc:date>2021-03-24T14:15:59Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot connect to highly available portal version 10.8.1 with error message: You are not authorized to use this resource.</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/cannot-connect-to-highly-available-portal-version/m-p/1038989#M10707</link>
      <description>&lt;P&gt;Hi Nicolas,&lt;/P&gt;&lt;P&gt;At the end it was a bug in the portal. We solve it by installing the latest patch here: &lt;A href="https://support.esri.com/en/download/7864" target="_self"&gt;https://support.esri.com/en/download/7864&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Further details about the topic can be found here: &lt;A href="https://community.esri.com/t5/arcgis-enterprise-questions/aws-10-8-1-ha-portal-not-restarting/m-p/1033401#M29605" target="_self"&gt;https://community.esri.com/t5/arcgis-enterprise-questions/aws-10-8-1-ha-portal-not-restarting/m-p/1033401#M29605&lt;/A&gt;&lt;/P&gt;&lt;P&gt;Hope this helps!&lt;/P&gt;</description>
      <pubDate>Sat, 20 Mar 2021 14:21:38 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/cannot-connect-to-highly-available-portal-version/m-p/1038989#M10707</guid>
      <dc:creator>MichailMarinakis1</dc:creator>
      <dc:date>2021-03-20T14:21:38Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot connect to highly available portal version 10.8.1 with error message: You are not authorized to use this resource.</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/cannot-connect-to-highly-available-portal-version/m-p/1039449#M10717</link>
      <description>&lt;P&gt;Such good news &lt;span class="lia-unicode-emoji" title=":slightly_smiling_face:"&gt;🙂&lt;/span&gt;&lt;/P&gt;&lt;P&gt;Thanks !&lt;/P&gt;</description>
      <pubDate>Mon, 22 Mar 2021 19:16:32 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/cannot-connect-to-highly-available-portal-version/m-p/1039449#M10717</guid>
      <dc:creator>NicolasGIS</dc:creator>
      <dc:date>2021-03-22T19:16:32Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot connect to highly available portal version 10.8.1 with error message: You are not authorized to use this resource.</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/cannot-connect-to-highly-available-portal-version/m-p/1070799#M11173</link>
      <description>&lt;P&gt;Following up on this, is it true that if IWA is configured, then the&amp;nbsp;privatePortalURL must have a different value than the&amp;nbsp;WebContextURL? Or was this just thought to be the issue when it was really the bug that the patch resolved?&lt;/P&gt;&lt;P&gt;I'm setting up a new 10.8.1 deployment where we are using IWA and currently have the privatePortalURL and WebContextURL set to the same value, the web adaptor registered with the portal. This hasn't caused any issues so far but I want to make sure I'm following best practices and not setting myself up for problems later.&lt;/P&gt;&lt;P&gt;I have installed the HA patch, do I need to set a different&amp;nbsp;privatePortalURL and WebContextURL if using IWA?&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 00:43:29 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/cannot-connect-to-highly-available-portal-version/m-p/1070799#M11173</guid>
      <dc:creator>BenjaminBlackshear</dc:creator>
      <dc:date>2021-06-22T00:43:29Z</dc:date>
    </item>
    <item>
      <title>Re: Cannot connect to highly available portal version 10.8.1 with error message: You are not authorized to use this resource.</title>
      <link>https://community.esri.com/t5/arcgis-enterprise-portal-questions/cannot-connect-to-highly-available-portal-version/m-p/1070905#M11175</link>
      <description>&lt;P&gt;Hi Benjamin,&amp;nbsp;&lt;/P&gt;&lt;P&gt;for us yes, it was necessary to use a different value. The privatePortalURL has to point to the 7443 port and &lt;STRONG&gt;not&lt;/STRONG&gt; to the port 443. Issues appeared when we federated an arcgis server. We didn't observe any issues without a federated arcgis server.&lt;/P&gt;&lt;P data-unlink="true"&gt;We needed to federate an arcgis server so we used for WebContextURL e.g. https://gis.portal.com/arcgis&amp;nbsp;that redirects to port 443 for each of the machines behind and for privatePortalURL we used e.g. https://gis.portal.com:7443/arcgis&amp;nbsp;that redirects to port 7443 for each of the machines behind.&amp;nbsp;&lt;/P&gt;&lt;P data-unlink="true"&gt;Hope this answer your question!&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 22 Jun 2021 11:39:11 GMT</pubDate>
      <guid>https://community.esri.com/t5/arcgis-enterprise-portal-questions/cannot-connect-to-highly-available-portal-version/m-p/1070905#M11175</guid>
      <dc:creator>MichailMarinakis1</dc:creator>
      <dc:date>2021-06-22T11:39:11Z</dc:date>
    </item>
  </channel>
</rss>

