republican-creole
Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Virtual Private Networking » Server 2k3 cannot connect to VPN via L2TP over IPsec
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
OpenVPN internet routing »
AuthorAll Replies


MattE
Obama '08
Premium
join:2003-07-20
Jamestown, NC
·North State Commun..
·Corporate Colocation


edit:
May 12th, @02:29PM

reply to johnpsph
Re: Server 2k3 cannot connect to VPN via L2TP over IPsec

Hrm, never seen that one before but this MS KB article says it's a domain issue: »support.microsoft.com/kb/310431

You may want to try username@domain in the username field, or use the username in the username field and put the NetBIOS domain name in the domain field.

I have a few clients where one or the other works.

johnpsph

join:2003-11-16
Saint Louis, MO
Well, I don't have a domain field in the Vista VPN Client, but I did try username@domain.com, but still had the same problem


MattE
Obama '08
Premium
join:2003-07-20
Jamestown, NC
·North State Commun..
·Corporate Colocation

said by johnpsph See Profile :

Well, I don't have a domain field in the Vista VPN Client, but I did try username@domain.com, but still had the same problem
You have to enable the domain field in the VPN properties.

johnpsph

join:2003-11-16
Saint Louis, MO
·Charter Pipeline


edit:
May 13th, @03:15AM

Oh ok. Well, I tried that too, but got the same 691 error.

I just realized that there is a fact I haven't mentioned about my setup. The machine in question just has one NIC, so I set up a custom RRAS for VPN, I was not able to go through the standard VPN bulleted option in the RRAS setup.


MattE
Obama '08
Premium
join:2003-07-20
Jamestown, NC
·North State Commun..
·Corporate Colocation

said by johnpsph See Profile :

Oh ok. Well, I tried that too, but got the same 691 error.

I just realized that there is a fact I haven't mentioned about my setup. The machine in question just has one NIC, so I set up a custom RRAS for VPN, I was not able to go through the standard VPN bulleted option in the RRAS setup.
Do you have L2TP ports listed under ports?

johnpsph

join:2003-11-16
Saint Louis, MO
Yes, looks like 1-99.


MattE
Obama '08
Premium
join:2003-07-20
Jamestown, NC
Hrm, I'd start looking at whether or not your routers pass IPSec through properly. Are there NAT routers at either end?

If so, check for an IPSec passthru setting in the router and make sure it's enabled (or disabled as some need to be).

johnpsph

join:2003-11-16
Saint Louis, MO
I set up IPsec passthrough on the router previously, but that doesn't seem to have been the issue. The 2k3 server is behind a NAT Router with firewall port 1723 forwarded to it. Are there any other ports I should forward?


MattE
Obama '08
Premium
join:2003-07-20
Jamestown, NC
·North State Commun..
·Corporate Colocation

said by johnpsph See Profile :

I set up IPsec passthrough on the router previously, but that doesn't seem to have been the issue. The 2k3 server is behind a NAT Router with firewall port 1723 forwarded to it. Are there any other ports I should forward?
For IPSec/L2TP you need to forward UDP 4500 for IPSec NAT-T, UDP 500 for ISAKMP, and the ESP protocol to the RRAS server. The ESP protocol portion may be where you're running into trouble.

You only need 1723 and the GRE protocol for PPTP.

johnpsph

join:2003-11-16
Saint Louis, MO

edit:
May 14th, @02:03PM

All right, I forwarded the ports in question, but i'm still getting the same error, even though I have the router set up for IPsec and L2TP over IPsec passthrough. I'd be happy to post up a few screenshots of the router's setup if that might help.

johnpsph

join:2003-11-16
Saint Louis, MO
Alternately, I have to run out, but I may try putting my server in the DMZ to see if that works.

johnpsph

join:2003-11-16
Saint Louis, MO
Well, I tried that, and it didn't work. I also tried turning the firewall on the router off altogether for a minute, but I'm still getting the 691 message....


MattE
Obama '08
Premium
join:2003-07-20
Jamestown, NC
Do you know for a fact that your router supports forwarding ESP? In needs to allow it WAN -> LAN, not just LAN -> WAN.
Forums » Up and Running » Virtual Private NetworkingOpenVPN internet routing »


Wednesday, 15-Oct 15:30:25 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 9 years online! © 1999-2008 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [131] All Hail the New RIAA Copyright Czar
· [77] More on Comcast's New 22Mbps Speed Tier
· [71] Comcast: Hey, At Least We're Not Hiking Broadband/VoIP Prices
· [54] New 'Economic Stimulus' Plan Includes Universal Broadband
· [38] 72% Of P2P Pirates Would Stop With ISP Warning
· [31] Google: We're Fresh Out Of Androids
· [30] AT&T To Sell U-Verse At Walmart, Circuit City
· [30] Crackberry Addicts Fear Microsoft Takeover
· [28] Unions Want Improper Cable Grounding Inspected, Too
· [27] Virgin: Our 50Mbps Tier Breaks Your Speed Tests
Most people now reading
· Extreme HD and Essentials [Verizon FIOS TV]
· [WotLK] What you guys think of the patch? [World of Warcraft]
· [Rant] Wealthy people [Rants, Raves, & Praise]
· Southern California New HD Watch [Verizon FIOS TV]
· Sarah Palin Ordered to Preserve Yahoo! Emails [Security]
· [ Classes] Holy Priest Level 70 WoW 3 Talent Build [World of Warcraft]
· [WotLK] Frost/Arcane Mage Build Thoughts [World of Warcraft]
· IMG 1.6 Build 06.89 Released [Verizon FIOS TV]
· Official Patch Notes - 3.0.2 [World of Warcraft]