Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

RRAS authentication on 2008 R2

Posted on 2011-09-29
3
1,548 Views
Last Modified: 2012-08-13
I'm having some trouble getting RRAS working on server 2008 R2 and was wondering if anyone had some insight.

RRAS installs correctly, I am able to connect but authentication fails with, and it just keeps asking for the password when trying to connect:
" The user <username removed> connected from <IP Removed> but failed an authentication attempt due to the following reason: The connection was prevented because of a policy configured on your RAS/VPN server. Specifically, the authentication method used by the server to verify your username and password may not match the authentication method configured in your connection profile. Please contact the Administrator of the RAS server and notify them of this error."

Configuration information:
RRAS is installed on a domain controller with local Authentication. VPN client is connecting using standard PPTP, and I verified that RRAS authentication is enabled for MS-CHAP v2 (default), and NPS has a VPN access policy which allows access to users of the VPN group. I've added the user to the VPN group, and on his dial in permissions specified allowed (I've tried switching this around to policy based or just plain allow).

I can see the user hitting the correct policy using the logs.
192.168.1.25,<username removed>,09/29/2011,05:44:18,RAS,AKRON,44,10,32,AKRON,4,192.168.1.25,6,2,7,1,5,256,61,5,64,1,65,1,31,71.75.105.228,66,71.75.105.228,4108,192.168.1.25,4128,AKRON,8132,2,4147,311,4148,MSRASV5.20,4160,MSRASV5.20,4159,MSRAS-0-DIETER-PC,8158,{F0286BA4-E35D-4C92-ACA4-329DC62AB380},4154,VPN Access,4155,1,4129,<username removed>,4130,<username removed>,25,311 1 fe80::b160:3e62:cb72:cb8 09/16/2011 20:19:00 61,4127,4,4136,1,4142,0
192.168.1.25,<username removed>,09/29/2011,05:44:18,RAS,AKRON,44,10,25,311 1 fe80::b160:3e62:cb72:cb8 09/16/2011 20:19:00 61,4127,4,4130,<username removed>,4129,<username removed>,4155,1,4154,VPN Access,4136,3,4142,16
59,4127,4,4130,<username removed>,4129,<username removed>,4155,1,4154,VPN Access,4136,3,4142,16

This happens with all accounts (not just 1), and I verified the account login and passwords are correct and the account is not locked out. Pretty much all settings are defaults on the server, unless otherwise specified above.

I verified this isn't an issue with firewall, as local connections to the VPN server has the same issue.

Thanks,
Dieter
0
Comment
Question by:25BY7
  • 2
3 Comments
 
LVL 51

Expert Comment

by:Netman66
ID: 36928541
What are your clients running for an OS?

I've seen issues with FIPS encryption getting in the way, but I'm not certain in your case.

0
 

Accepted Solution

by:
25BY7 earned 0 total points
ID: 37008140
This was related to GPOs which raised the LM authentication level on the authentication server. Those had to be lowered to allow authentication to complete successfully.

0
 

Author Closing Comment

by:25BY7
ID: 37035286
Once the GPOs were updated, everything started working correctly.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

This script can help you clean up your user profile database by comparing profiles to Active Directory users in a particular OU, and removing the profiles that don't match.
This article outlines the process to identify and resolve account lockout in an Active Directory environment.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

840 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question