troubleshooting Question

Help troubleshooting Network Policy Server on 2019 (again)

Avatar of Armitage318
Armitage318 asked on
Windows Server 2019NetworkingActive DirectoryTroubleshooting
5 Comments1 Solution23 ViewsLast Modified:
Hi, I am trying to fix Active Directory authentication for my VPN users.
I have two DC (windows 2019 and 2008). The 2008 DC is working fine.
I strictly followed firewall's documentation on how to set NPS on Windows.
Both settings are identical on both NPS.

Anyway, it seems that connection request policy is not matched on windows 2019.
Condition is built with:
Users group: "MYCOMPANY\VPN"
Authentication type: PAP (as stated in FW's documentation)

Open in new window

If I try to capture network traffic dump with Wireshark, I notice a strange error related to LDAP (I am translating from italian original message):

CN: object not authorized replica password read only controller

Open in new window

besides of this, it seems that the two DCs are fine: if I create a test user on DC 2008, it is visible even in windows 2019 and viceversa. So I don't figure the reason of "read only controller" issue.
Any suggestion on how to better troubleshoot this?
Thank you!
ASKER CERTIFIED SOLUTION
Armitage318

Our community of experts have been thoroughly vetted for their expertise and industry experience.

Log in to continue reading
Become an EE member today7-DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform for $9.99/mo
View membership options
Unlock 1 Answer and 5 Comments.
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.
See how we're fighting big data
The Value of Experts Exchange in My Daily IT Life

Experts Exchange (EE) has become my company's go-to resource to get answers. I've used EE to make decisions, solve problems and even save customers. OutagesIO has been a challenging project and... Keep reading >>

Mike

Owner of Outages.IO
Phoenix, Arizona, United States
Member Since 2016
Join a full scale community that combines the best parts of other tools into one platform.
Unlock 1 Answer and 5 Comments.
View membership options
“All of life is about relationships, and EE has made a virtual community a real community. It lifts everyone's boat.”
William Peck

Member since 2004