There are some instances where the connection from an Active Administrator console to an Active Administrator server may fail.
Potential issue one – DNS lookup:
When the Active Administrator console attempts to connect to the Active Administrator server, we use the FQDN of the server from the Active Administrator AFS service connection point in AD. If this FQDN cannot be resolved into an IP address using DNS on the Active Administrator console host machine, this connection will fail.
Potential issue two - Ports blocked by a Firewall:
If there is a firewall in place on the Active Administrator port used to communicate with the AFS service, port 15600, this will also cause the Active Administrator console to fail to connect to the AFS service on the Active Administrator service host machine. Additional ports that must be open for the console to work correctly are ports 8080 and 9443 for communication with the web console. Also, port 389 must be open to allow for Active Directory to communicate with domain controllers.