?
Solved

Error trying to VPN using WAN Miniport L2TP

Posted on 2010-11-26
12
Medium Priority
?
5,811 Views
Last Modified: 2012-05-10
Unable to connect using Windows 7 VPN to Windows Server 2003.  I get several messages.  First message is "Verifying Password...", second message "connecting to ip using WAN Miniport (SSTP)', third message connecting to ip using WAN Miniport PPTP,  then last message "Connecting to  IP using "WAN Miniport (L2TP)...Error 800...".  This used to work up until that last few days.  No changes have been made to the network or configuration settings on either side (Client or Server including the PIX Firewall).  any ideas?
0
Comment
Question by:drest
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 6
  • 5
12 Comments
 
LVL 11

Expert Comment

by:DIPRAJ
ID: 34220733
0
 
LVL 71

Expert Comment

by:Qlemo
ID: 34221525
diprajbasu,
Please don't post just links, and in particular if they only lead to a list of threads not directly related.

drest,
Do you know which one of those protocols have been used actually to connect when it succeeded? It's important since the diagnostics differ for PPTP and L2TP (we can forget about SSTP - not supported with W2003).
0
 

Author Comment

by:drest
ID: 34222360
Genius, i do not know which used to work.  It has been working for over months.  

The only change that was made recently on the network was a local switch went bad (1 of the 2) and had to connect about half the  local workstations to an old backup switch.  The switches are unmanaged.  The Pix and the server are unaffected as the are/were connected to the 1 working existing switch.  No other changes have been made to the network.
0
Technology Partners: We Want Your Opinion!

We value your feedback.

Take our survey and automatically be enter to win anyone of the following:
Yeti Cooler, Amazon eGift Card, and Movie eGift Card!

 
LVL 71

Expert Comment

by:Qlemo
ID: 34222437
I agree the switches are not part of the issue. However, there has to be a change somewhere. Look into your server's event log - maybe it's the server's fault. But it could also be a lost or changed setting on the Cisco (about forwarding the necessary ports).
0
 

Author Comment

by:drest
ID: 34223245
Spent the last few hours toubleshooting this.  Got it to work, but don't know exactly why.  Inserted a couple of switches to help me troubleshoot. Bypassing the modem, the pix firewall, and tried several scenerios.  One time i was connected to the VPN and simply reconnected the Modem (DSL) and it immediately brought down the VPN connection.  Logged onto the Modem and saw nothing that would interfere with the VPN (no firewall, everything port forwarded).  Then reconnected bypassing everything but the modem, the pix, and the server...and whalla, i was able to connect.  reconnected everything the way it was originally and the VPN now works.  I do not have any clue as to why it is working!   Maybe the sequence of when the devices are brought up/attached?  Unexplainable!  
0
 
LVL 71

Expert Comment

by:Qlemo
ID: 34223312
There seem to be too much factors in the equation to really determine what is happening.
Now that the VPN is working, you should take note of whether it is PPTP or L2TP. If you cannot determine it otherwise, just issue a    netstat -an | findstr "1701 1723 500 4500"    to list the ports used.
0
 

Author Comment

by:drest
ID: 34223348
It is PPTP.
0
 
LVL 71

Expert Comment

by:Qlemo
ID: 34223369
Oy - many, many things can go wrong then. GRE, which is used for encapsulation, is a flaky protocol when crossing NAT devices.
I would wait for at least one day to see whether the effect is retained. If the connection breaks again, I'm afraid nothing else then logging the traffic on at least three locations (client, your router, and server) helps. That is the only way you can make sure you know enough about what is happening (or not).
0
 

Author Comment

by:drest
ID: 34226273
it broke again!
0
 
LVL 71

Accepted Solution

by:
Qlemo earned 2000 total points
ID: 34226306
We had that with our smart firewall device (Juniper SSG) applying a PPTP application layer gateway, which allows for using more than one PPTP connection in- or outbound with the same public IPs in a double-NAT scenario (ouch). Depending on the GRE session number, or anything exchanged different each time on connection initiation, the connection works or does not. It is random. Yours might be a similar issue.
The official answer for using PPTP behind NAT devices is to use an own public IP per remote target. In your case, if you have an IP address block assigned by your ISP, you can use a different IP for PPTP, and forward that to the W2003 server. That might help, but we cannot know, since we both have no hint yet what really breaks the connection.
0
 

Author Closing Comment

by:drest
ID: 34337050
Thank you for your comments.  it turned out to be the switch.  Since it was the only change, i relaced with a new switch and things began to work again.
0
 
LVL 71

Expert Comment

by:Qlemo
ID: 34337096
If the switch is a routing one (L3 Switch), that can explain the failure. If not, I was totally off, and should not get points.
0

Featured Post

Free Tool: Site Down Detector

Helpful to verify reports of your own downtime, or to double check a downed website you are trying to access.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

The password reset disk is often mentioned as the best solution to deal with the lost Windows password problem. In Windows 2008, 7, Vista and XP, a password reset disk can be easily created. But besides Windows 7/Vista/XP, Windows Server 2008 and ot…
If you’re involved with your company’s wide area network (WAN), you’ve probably heard about SD-WANs. They’re the “boy wonder” of networking, ostensibly allowing companies to replace expensive MPLS lines with low-cost Internet access. But, are they …
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

718 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question