Windows 2008 R2 VPN not authenticating any users
i've created own lab setup step step guide windows 2008 r2 nap , vpn.
in neither case authentication work vpn client (windows 7)
topology:
dc1 (domain controller, dns server, gpos)
- nap gpo
- shv gpo
- eap enforcement gpo
nps1 (network policy server, radius server)
- nap configured per step step guide
vpn1 (rras server, radius client)
- vpn1 configured per step step guide.
client1 (vpn client windows 7)
- connected local server using username/password/domain (using local server name)
- connected vpn server using domain credentials
vpn1 , client 1 on fake internet segment.
no matter can not server authenticate me , establish vpn tunnel.
i keep getting "re-enter user name , password" message. have confirmed username , password correct. i've changed username/password still nothing.
possible causes:
1 of prime causes above error is: when *only* allowed authentication protocol configured on vpn server (or radius server) ms-chap , vpn client vista or above os platform (like windows7). note: due security reasons ms-chap removed vista , above os platform , hence connection fails.
error 812 comes when authentication protocol set via nps (network policy , access services).
possible solution:
1. configure more secured authentication protocol ms-chapv2 or eap based authentication on server – matches settings on client side.
2. re-import nps policies , stop/start nps.
3. add domain name such domain\username.
best regards
jeremy wu
Windows Server > Network Access Protection
Comments
Post a Comment