Okta Access Gateway Worker Node Addition Fails with a Failure RC=56 Error
Last Updated:
Overview
An Okta Access Gateway (OAG) worker node addition fails when an environment uses a proxy and the bypass list lacks the required hostname. Administrators must modify the proxy settings on the worker node to bypass the required hostname. The issue occurs after the administrator pastes the key, and Okta generates the following error message:
Applies To
- Okta Identity Engine (OIE)
- Okta Classic Engine
- Okta Access Gateway (OAG) versions 2025.3 and later
- High Availability (HA)
Cause
Starting in Okta Access Gateway version 2025.3, the worker node looks for the specific hostname ha-admin.service.oag on the admin node to configure High Availability (HA). This issue occurs in environments that use a proxy and lack the ha-admin.service.oag host in the bypass list. Review the documentation for additional details.
Solution
How do administrators configure the proxy to bypass the required hostname?
Modify the proxy settings on the node designated as a worker to bypass the required hostname.
- Review the Set the proxy for Access Gateway documentation.
- Modify the proxy settings on the node to bypass the
ha-admin.service.oaghostname before adding it as a worker.
