Remote VPNuser unable to connect to Server 2003/ Firebox setup

Posted on 2009-05-01
Medium Priority
Last Modified: 2012-05-06
I have a remote user who is trying to VPN in to the network.
He keeps getting VPN error 619 and 691.

Since I did not set this up I have been troubleshooting this msot of the morning.
I have him added to the firebox the same as other users.
The PPTP group in AD on Server 2003 has some VPN users who were setup before I took over as having dial in enabled or not enabled so its nto consistent. I am thinking a user VPN's into the network via firebox then lands ona  server and then RDP'sinto there respective desktop.

I am now thinking the user may have the issue on his here end.

Any ideas?
Question by:manelson05
  • 2
  • 2
LVL 32

Expert Comment

ID: 24307815
Few questions:
1. Is FB acting as VPN server or the 2003 server.
2. If firebox, then are you using AD authentication or local authentication.
3. If you try to connect from another service provider as the user with trouble what are the results.
4. Are other users able to connect fine.
5. If you are using AD authentication, then pre ensure that the user is part of the group which is allowed in the policy.

Thank you.

Author Comment

ID: 24460063
THE FB seems to broker a connection to RAS on Server 2003.
A users logs into FB with PPTP (barf) with seperate set of credentials.
From tehre they have access to network resources, laptop users have the apps local so its merely a data conenction such as DNS to bind local ODBC to the LAN's ODBC agent

I changed my Firewall setting at home and can get in but I have one user who still can not connect.
LVL 32

Accepted Solution

dpk_wal earned 2000 total points
ID: 24460414
FB broker connection to RAS; then there is not much we can check at the firewall level. If one user can connect so should be others; as far as single user is concerned it can be few factors:
1. Users ISP blocks outbound VPN connection.
    -If possible use same credentials and login from the location where you can establish VPN connection [using the same machine]. If you are able to connect, then it is ISP; if you even cannot from the other location using the same machine then it has to do with machine settings.
2. There is a personal firewall on the machine and this firewall is blocking the outbound VPN connection.
    -Disable firewall and try connecting again.
3. On the server the user does not have proper privileges and hence unable to connect.
    -From the same machine and ISP try connecting with some other user [which is otherwise working fine].

Thank you.

Author Closing Comment

ID: 31576935
This is the conclusion I drew on my own network at home, I had to allow pptp/vpn connections on the dsl router, since its a second firewall, things worked great. Now its a matter of the home user doing hte same, since I dont support home computers, they will have to resolve locally or call someone for an on call support request.

Featured Post


Modern healthcare requires a modern cloud. View this brief video to understand how the Concerto Cloud for Healthcare can help your organization.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Many of us need to configure DHCP server(s) in their environment. We can do that simply via DHCP console on server or using MMC snap-in on each computer with Administrative Tools installed in a network. But what if we have to configure many DHCP ser…
I've always wanted to allow a user to have a printer no matter where they login. The steps below will show you how to achieve just that. In this Article I'll show how to deploy printers automatically with group policy and then using security fil…
As many of you are aware about Scanpst.exe utility which is owned by Microsoft itself to repair inaccessible or damaged PST files, but the question is do you really think Scanpst.exe is capable to repair all sorts of PST related corruption issues?
Planning to migrate your EDB file(s) to a new or an existing Outlook PST file? This video will guide you how to convert EDB file(s) to PST. Besides this, it also describes, how one can easily search any item(s) from multiple folders or mailboxes…

621 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question