Solved

RRAS authentication on 2008 R2

Posted on 2011-09-29
3
1,531 Views
Last Modified: 2012-08-13
I'm having some trouble getting RRAS working on server 2008 R2 and was wondering if anyone had some insight.

RRAS installs correctly, I am able to connect but authentication fails with, and it just keeps asking for the password when trying to connect:
" The user <username removed> connected from <IP Removed> but failed an authentication attempt due to the following reason: The connection was prevented because of a policy configured on your RAS/VPN server. Specifically, the authentication method used by the server to verify your username and password may not match the authentication method configured in your connection profile. Please contact the Administrator of the RAS server and notify them of this error."

Configuration information:
RRAS is installed on a domain controller with local Authentication. VPN client is connecting using standard PPTP, and I verified that RRAS authentication is enabled for MS-CHAP v2 (default), and NPS has a VPN access policy which allows access to users of the VPN group. I've added the user to the VPN group, and on his dial in permissions specified allowed (I've tried switching this around to policy based or just plain allow).

I can see the user hitting the correct policy using the logs.
192.168.1.25,<username removed>,09/29/2011,05:44:18,RAS,AKRON,44,10,32,AKRON,4,192.168.1.25,6,2,7,1,5,256,61,5,64,1,65,1,31,71.75.105.228,66,71.75.105.228,4108,192.168.1.25,4128,AKRON,8132,2,4147,311,4148,MSRASV5.20,4160,MSRASV5.20,4159,MSRAS-0-DIETER-PC,8158,{F0286BA4-E35D-4C92-ACA4-329DC62AB380},4154,VPN Access,4155,1,4129,<username removed>,4130,<username removed>,25,311 1 fe80::b160:3e62:cb72:cb8 09/16/2011 20:19:00 61,4127,4,4136,1,4142,0
192.168.1.25,<username removed>,09/29/2011,05:44:18,RAS,AKRON,44,10,25,311 1 fe80::b160:3e62:cb72:cb8 09/16/2011 20:19:00 61,4127,4,4130,<username removed>,4129,<username removed>,4155,1,4154,VPN Access,4136,3,4142,16
59,4127,4,4130,<username removed>,4129,<username removed>,4155,1,4154,VPN Access,4136,3,4142,16

This happens with all accounts (not just 1), and I verified the account login and passwords are correct and the account is not locked out. Pretty much all settings are defaults on the server, unless otherwise specified above.

I verified this isn't an issue with firewall, as local connections to the VPN server has the same issue.

Thanks,
Dieter
0
Comment
Question by:25BY7
  • 2
3 Comments
 
LVL 51

Expert Comment

by:Netman66
Comment Utility
What are your clients running for an OS?

I've seen issues with FIPS encryption getting in the way, but I'm not certain in your case.

0
 

Accepted Solution

by:
25BY7 earned 0 total points
Comment Utility
This was related to GPOs which raised the LM authentication level on the authentication server. Those had to be lowered to allow authentication to complete successfully.

0
 

Author Closing Comment

by:25BY7
Comment Utility
Once the GPOs were updated, everything started working correctly.
0

Featured Post

Shouldn't all users have the same email signature?

You wouldn't let your users design their own business cards, would you? So, why do you let them design their own email signatures? Think of the damage they could be doing to your brand reputation! Choose the easy way to manage set up and add email signatures for all users.

Join & Write a Comment

Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will walk an individual through locating and launching the BEUtility application and how to execute it on the appropriate database. Log onto the server running the Backup Exec database. In a larger environment, this would generally be …
This tutorial will show how to configure a new Backup Exec 2012 server and move an existing database to that server with the use of the BEUtility. Install Backup Exec 2012 on the new server and apply all of the latest hotfixes and service packs. The…

743 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now