| 4001 |
Incorrect credentials/Password. Try again. |
Incorrect credentials are supplied |
Enter the correct credentials |
| 4002 |
Not Permitted |
This is a catch all error. Occurs when ldapbind operation fails for reasons other than incorrect user credentials. |
Make sure bind operation is permitted |
| 4003 |
Cannot connect to server. Try connecting again in a few minutes. |
Server times out |
Increase the LDAP/Radius server timeout value on NetScaler (Authentication > LDAP/Radius > Server > Timeout value). Default timeout value is 3 secs. |
| 4004 |
System Error |
NetScaler/NetScaler Gateway internal error or a runtime error in the appliance library |
Check for the cause of the system error and reslove the same |
| 4005 |
Socket Error |
Socket error while talking to the authentication server |
Make sure that LDAP/RADIUS server or any other authentication servers can listen on the ports mentioned in the authentication action configured on NetScaler. For example, a common error scenario can be that an ldapprofile on NetScaler is configured to use port 636 /SSL, however the same port is not open on the AD. |
| 4006 |
Incorrect username |
Bad (format) username passed to nsaaad, like empty username |
Enter the correct username |
| 4007 |
Incorrect password |
Bad (format) password passed to nsaaad |
Enter the correct password |
| 4008 |
Passwords do not match |
Password mismatch |
Enter the correct password |
| 4009 |
User not found |
No such user |
Login using a valid user present in AD |
| 4010 |
You do not have permission to log on at this time |
Restricted log on hours |
Log on outside the restricted hours |
| 4011 |
Your AD account is disabled |
Account disabled |
Get your AD account enabled |
| 4012 |
Your password has expired |
Password expired |
Reset your password |
| 4013 |
You do not have permission to log on |
No dial-in permission (RADIUS specific). This usually happens if a user is not authorized to authenticate at a server. |
Network access permission setting needs to be changed |
| 4014 |
Could not change your password |
Error in changing password. This can happen due to many reasons. One such reason could be trying to change the password using the non-ssl port provided in ldapprofile on NetScaler. |
Ensure secure port and sec type is used for changing password |
| 4015 |
Your account is temporarily locked |
User AD account is locked |
Get your AD account unlocked |
| 4016 |
Could not update your password. The password must meet the length, complexity, and history requirements of the domain. |
User password requirements not met while changing the password |
Meet the needed requirements while changing the password |
| 4017 |
NAC process |
Microsoft Intune Specific. NetScaler Gateway is unable to verify device, either due to API failure or connectivity failure. |
Ensure Microsoft Intune managed devices are reachable to NetScaler Gateway |
| 4018 |
NAC Noncompliance |
Microsoft Intune returns a status saying that this device is not compliant device |
Ensure Microsoft Intune managed devices are compliant with NetScaler Gateway |
| 4019 |
NAC Unmanaged |
Microsoft Intune returns a status saying that this is not a managed device |
Ensure Microsoft Intune specific configurations are in place |
| 4020 |
Authentication not Supported |
This error is seen in case of misconfiguration. For example, auth type is not supported by NetScaler or if the Authentciationprofile config is incorrect on NetScaler appliance or if accounting action (radius) is attempted for authentication. |
Check the Authentication checkbox for the Authentication server on NetScaler if its unchecked. Use appropriate Authentication action on NetScaler. |
| 4021 |
User Account Expired |
The user account has expired |
Get your user account renewed |
| 4022 |
User account is locked by NetScaler |
The user account is locked by NetScaler |
Unlock the account using unlock aaa user <> command |
| 4023 |
Max OTP Device limit reached |
Device limit for receiving OTP reached |
Either try unregistering the non-required OTP devices or continue with the ones already registered |