Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people, just like you, are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
Solved

401 error

Posted on 2013-06-28
11
749 Views
Last Modified: 2013-07-06
Users connecting to the office LAN by VPN are getting a 401 error when they try to log in to CRM 2011. Local users login successfully.  This problem has only been occurring for a week having been working fine until then. I am not aware that anything has changed. Previously remote users would open the CRM url and domain login credentials were requested. Local users log in to CRM automatically as the current windows user.

The error in the IIS log is 401 5

IIS is version 7 on Server 2008

Suggestions please?....

Thanks,
Jo
0
Comment
Question by:jostick
  • 5
  • 2
  • 2
  • +1
11 Comments
 
LVL 5

Expert Comment

by:truinx
ID: 39283974
In a given change, there is equivalent change. The question is what changed?

Try to ask the security guy?

Do you have any logs that can help EE people assist you?
At first glance, you seem to have an auto-rejection connection problem.
0
 

Author Comment

by:jostick
ID: 39283985
from IIS:

GET /default.aspx +OnBeginRequest:06/28/2013-10:17:00.572+LogEntries:0+SqlCalls:0+SqlCallsMs:0+GC:2+OnEndRequest:10:17:00.572 80 - 192.168.64.71 Mozilla/5.0+(compatible;+MSIE+10.0;+Windows+NT+6.1;+Trident/6.0) 401 5 0 78

The problem is not browser dependant. It is just on remote PCs that require user to login to website. This is also for users that are logged into their remote PC using cached domain credentials that would work locally.
0
 
LVL 5

Expert Comment

by:truinx
ID: 39283999
What happens if the user use IE?
0
Windows Server 2016: All you need to know

Learn about Hyper-V features that increase functionality and usability of Microsoft Windows Server 2016. Also, throughout this eBook, you’ll find some basic PowerShell examples that will help you leverage the scripts in your environments!

 
LVL 11

Expert Comment

by:b_levitt
ID: 39284095
I would guess this is an IE zoning problem.  When on the internal network, the site is correctly being detected in the local intranet zone, but while connecting via vpn it's being detected as an Internet site.  IIRC, IE only pushes domain credentials if a site is in the intranet zone.  You can start by manually adding the site to the intranet zone and see if that fixes that one computer.  If this is the issue, then you can start looking at it globally.  When we have problems like this, it's typically a proxy configuration issue.  Either a proxy was not configured or the domain was not included in the proxy bypass list (which automatically adds the site to the local intranet zone: http://msdn.microsoft.com/en-us/library/bb250483%28v=vs.85%29.aspx.

There are other issues, such as lack of connectivity to the domain controller, but the zoning and the proxy config is where I'd start.  Do internal and VPN users access the site in the same manner (same URL?).
0
 
LVL 11

Expert Comment

by:Sanjay Santoki
ID: 39286511
Hello,

As far as CRM is working fine locally there should not be any major issue. Make sure that the DNS record is pointing appropriate IP address while accessing website through VPN.

Also, try accessing using with alternate web browser.

Regards,
Sanjay Santoki
0
 

Author Comment

by:jostick
ID: 39289312
Sorry, misinformation. Problem occurs on some PCs only and is with IE not Firefox. Possibly it is IE9 problem. Site is local intranet zone
0
 

Author Comment

by:jostick
ID: 39289316
Login to other local web servers (e.g. SharePoint) is OK.
0
 
LVL 11

Expert Comment

by:Sanjay Santoki
ID: 39289717
Hello,

It could be browser specific issue. You can compare browser setting between the computers where it is working.

Regards,
Sanjay Santoki
0
 

Accepted Solution

by:
jostick earned 0 total points
ID: 39289805
The problem is to do with Kerberos and IE. I have resolved it by deselecting IE option to use windows autentication
0
 
LVL 11

Expert Comment

by:b_levitt
ID: 39290016
If kerberos is the problem, you could configure the server to use NTLM instead.  I see this all the time when sites are upgraded from windows 2003 to windows 2008, but I'm surprised it suddenly happened here.
0
 

Author Closing Comment

by:jostick
ID: 39303671
provides a workaround but does not resolve root cause
0

Featured Post

Comprehensive Backup Solutions for Microsoft

Acronis protects the complete Microsoft technology stack: Windows Server, Windows PC, laptop and Surface data; Microsoft business applications; Microsoft Hyper-V; Azure VMs; Microsoft Windows Server 2016; Microsoft Exchange 2016 and SQL Server 2016.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

First of all, clustering IIS is something you should rarely consider doing. In almost all cases, Microsoft Network Load Balancing (NLB) (http://technet.microsoft.com/en-us/library/cc758834(WS.10).aspx) is a much better solution when you need to p…
Automatically creating a Trello card using data from a Microsoft Dynamics CRM record turned out to be an easy project that yielded great results.  Here's how I did this for an internal team at General Code.
Although Jacob Bernoulli (1654-1705) has been credited as the creator of "Binomial Distribution Table", Gottfried Leibniz (1646-1716) did his dissertation on the subject in 1666; Leibniz you may recall is the co-inventor of "Calculus" and beat Isaac…
Nobody understands Phishing better than an anti-spam company. That’s why we are providing Phishing Awareness Training to our customers. According to a report by Verizon, only 3% of targeted users report malicious emails to management. With compan…

809 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question