Service Desk is configured to use EIAM authentication and all users can't log in. End users will receive time out error when try to log in.
Messages like these are logged in Service Desk stdlog
04/08 11:03:33.29 <server name> bopauth_nxd 4740 ERROR bopauthobj.c 836 Could not create auth thread.
04/08 11:03:36.01 <server name> bopauth_nxd 4740 ERROR bopauthobj.c 836 Could not create auth thread.
04/08 11:03:40.28 <server name> bopauth_nxd 4740 ERROR bopauthobj.c 836 Could not create auth thread.
04/08 11:03:43.49 <server name> bopauth_nxd 4740 ERROR eiamAuth.c 477 Error authenticating user: '<userid>' - EE_AUTHFAILED Authentication FailedISP_ERROR_NOGATEWAY igateway not running - took '2629794' miliseconds.
pdm_status shows all Service Desk processes are up and running.
Remote EIAM app is up and running as testing users can log in EIAM UI with the same user name and password on the EIAM server. However, when try to bring up the EIAM UI from Service Desk server page not found error occurs.
Network monitor shows the EIAM port(default is 5250) is open as the network engineer can see Service Desk sends request bytes to EIAM server via the EIAM port. However, 0 bytes is sent from EIAM server to Service Desk server. So it seems there is no network firewall issue.
Release : 17.x and up, EIAM on windows server
Component : CA Embedded Entitlements Manager
EIAM server has the firewall turned on that blocks the EIAM port.
There are a couple of reasons the server firewall is on---it could be system administrators perform some security check and action, it could be some server security patch installation automatically blocks the "unsecure" ports, it could be some rollback of server due to some system issue and so on.
Disable the firewall on EIAM server for the EIAM port(default is 5250).
We have said that the "default" port for EIAM is 5250. You can confirm that 5250 is the listening port for EIAM by opening Resource Manager and going to the Network tab. Expanding the "Listening Ports" section of the page, and look for the image named "igateway". This display will let you know which port is being used.
However, it is unlikely to be any port other than 5250. This article explains the reason: changing port 5250 on EEM