Solved

Windows VPN Server, IKE VPN Error

Posted on 2016-08-09
5
34 Views
Last Modified: 2016-09-08
I've setup a Windows 2012R2 VPN server with IKEv2 and SSTP.

Public Certificate has been installed and users can connection just fine using SSTP.

Also, from an internal 2012R2 server I'm able to connect to the VPN server using IKEv2 using the public hostname.

However, from external users when they try and connect using IKEv2 I get an error, see attached images.

The firewall in use is a Sonicwall NSA.

The ports being NAT'd are:

    IP Protocol Type=UDP, UDP Port Number=500   <- Used by IKEv2 (IPSec control path)
    IP Protocol Type=UDP, UDP Port Number=4500 <- Used by IKEv2 (IPSec control path)
    IP Protocol Type=UDP, UDP Port Number=1701  <- Used by L2TP control/data path
    IP Protocol Type=50 <- Used by data path (ESP)

In the Sonicwall I've also checked the box for: "Preserve IKE Port for Pass Through Connections" and also disabled the WAN VPN Group so its not using IKE.

See attached security configuration for clients. This works for an internal client but not an external one.
Win-10-Connection-Error.PNG
Win-7-Connection-Error.PNG
IKEv2-settings.PNG
0
Comment
Question by:RFVDB
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
5 Comments
 
LVL 5

Assisted Solution

by:Manuel Flores
Manuel Flores earned 500 total points
ID: 41749390
Could you try to configure in NAT-T (transversal mode)?
0
 
LVL 41

Expert Comment

by:Adam Brown
ID: 41749490
IKEv2 requires that the computer or user connecting to the VPN have a valid certificate to provide the underlying PKI encryption. Basically, if you don't have certificates installed on the client machines that they can use to authenticate themselves, IKEv2 won't work. It requires an Internal CA or Client certificates from a Third Party CA (super expensive).
0
 

Accepted Solution

by:
RFVDB earned 0 total points
ID: 41782539
Looks like the issue is with the Windows Client when the Firewall is behind a NAT for IKEv2. I just tried this Microsoft KB handling on a Windows 7 PC and it allowed the IKEv2 connection just fine.

https://support.microsoft.com/en-us/kb/926179

I didn't have to import any certificate of any kind as I'm using a public certificate on the server.

I'm trying this on Win 10 and I'll let you know on the results.
0
 

Author Comment

by:RFVDB
ID: 41783383
Just tried that article that supposed only works for Windows Vista and Server 2008 and it works on Windows 10. I was able to now connect using IKEv2.
0
 

Author Closing Comment

by:RFVDB
ID: 41789218
I figured out the finite solution in the end and thus selected my answer as the best solution.
0

Featured Post

Everything You Need to Know about Petya 2.0

Get an overview of the what, when and how of Petya 2.0  from our threat analyst Marc Labilerte, as well as a look at how WatchGuard Total Security Suite protected our customers from the recent attack!

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

You might have come across a situation when you have Exchange 2013 server in two different sites (Production and DR). After adding the Database copy in ECP console it displays Database copy status unknown for the DR exchange server. Issue is strange…
Envision that you are chipping away at another e-business site with a team of pundit developers and designers. Everything seems, by all accounts, to be going easily.
In this Micro Tutorial viewers will learn how to restore their server from Bare Metal Backup image created with Windows Server Backup feature. As an example Windows 2012R2 is used.
After creating this article (http://www.experts-exchange.com/articles/23699/Setup-Mikrotik-routers-with-OSPF.html), I decided to make a video (no audio) to show you how to configure the routers and run some trace routes and pings between the 7 sites…

717 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question