I’d recommend checking the ActionServiceWorker log on both application servers for token refresh errors. If you find any re-register the services on that server. If that doesn’t help I’d recommend opening a support ticket in our portal at netwrix.com so our team can take a look. What version of NPS are you running currently?
The errors you are seeing indicate that the host does not have an Internet connection and the CRL check for the certificate is causing the handshake to timeout. There is a KB article that can help with this.
We have resolved the issue. We powered down both machines, rebooted only the primary one, re-registered the service as localhost, and waited for the services to come back up. We then performed the same procedure on the secondary machine.