Solved

Error 806 (ERROR_VPN_GRE_BLOCKED) when connecting to VPN from Vista client

Posted on 2007-11-17
6
13,548 Views
Last Modified: 2008-06-14
I have three clients on my location, two running XP and one running Vista. All of  them should periodically connect to central office via PPTP VPN. Until recently there were no problems, but now Vista is suddenly unable to connect any more.  
I am getting error 806: The VPN connection between your computer and the VPN server could not be completed. The most command cause for this failure is that at least one Internet device (for example a firewall or a router) between your computer and the VPN server is not configured to allow GRE protocol packets.
I have checked the router (Zyxel Zywall 35) it has both port 1723 and GRE protocol 47 configured OK. Otherwise I would have problems with XP clients, too. Or is GRE important only for Vista?
I havent changed anything - the connection was just lost one morning and I am trying to get it back since then without success. I have tried Microsoft KB 926170 and 929857 instructions, since the error first manifested as 721, but no solution so far.
All clients are on  domain, but the domain server is on the host that is available only throught VPN - I guess this might be the problem...
0
Comment
Question by:igams
  • 2
  • 2
6 Comments
 
LVL 3

Expert Comment

by:The_R0CK
ID: 20304173
Because the other XP clients are connecting, I think the problem must be with the client device running Vista. There is no specific difference between XP and Vista as GRE as used by both for PPTP. You do not need to be on a domain or have AD access to connect to a VPN. Therefore, I suggest reveiwing the client. Vista (in my opinion) is not yet very stable for VPN. I would suggest disabling Windows Firewall and retest, maybe System Restore to a previous point, else worst case would be O/S reinstall.
0
 
LVL 3

Expert Comment

by:The_R0CK
ID: 20449501
I did make an effort to answer it :P
0
 

Author Comment

by:igams
ID: 20481062
I am sorry, I was away and I did not get any e-mail messages about any events going on here...
My problem is stil left to solve, and I will dedicate more efforts to it now. I hope you are not mad at me...
I appreciate all help from The ROCK, I tried to disable the Firewall, no success. As far as System Restore is concerned, I tried it the first day the problem appear.
I really would not like to reinstall the sistem. I suspect that the problem is conneted to DNS. I remember I had problems immediately before VPN was lost with mapping the local server discs. All mapped discs were lost and I could not map them with the server name using Explorer. I solved the problem with hosts file: I explicitely entered the mapping of the server name to its IP and it helped. But, obviously, the problem was not solved at it roots... Should I better start solving the DNS problem first and VPN after that?
0
 

Accepted Solution

by:
igams earned 0 total points
ID: 21734463
Since the question has not been closed yet I can now report how I managed to solve the problem:

The source of all problems was the firewall after all. But not the firewall on the router or the firewall on Vista - it was the firewall on F-Secure anti-virus client. One day some new version arrived and was installed (automatically or manually - I can not remember). This new version obviously changed its default configuration and became much more restrictive as far as IP communications are concerned.
The result was that it blocked all VPN traffic and did not report about it (firing alerts) as it should.
0

Featured Post

How to run any project with ease

Manage projects of all sizes how you want. Great for personal to-do lists, project milestones, team priorities and launch plans.
- Combine task lists, docs, spreadsheets, and chat in one
- View and edit from mobile/offline
- Cut down on emails

Join & Write a Comment

Suggested Solutions

Like many others, when I created a Windows 2008 RRAS VPN server, I connected via PPTP, and still do, but there are problems that can arise from solely using PPTP.  One particular problem was that the CFO of the company used a Virgin Broadband Wirele…
Secure VPN Connection terminated locally by the Client.  Reason 442: Failed to enable Virtual Adapter. If you receive this error on Windows 8 or Windows 8.1 while trying to connect with the Cisco VPN Client then the solution is a simple registry f…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
The Task Scheduler is a powerful tool that is built into Windows. It allows you to schedule tasks (actions) on a recurring basis, such as hourly, daily, weekly, monthly, at log on, at startup, on idle, etc. This video Micro Tutorial is a brief intro…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now