Server 2008 R2 RRAS VPN Network Policy - User Groups *and* Machine Groups required


hello,

i setting server 2008 r2 vpn server in active directory domain , having trouble getting conditions on network access policy work.  basically, restrict access policy based on both user membership in ad security group *and* computer membership in different ad security group.  in other words, want specified users able connect specified computers.  ("specified computers" broad domain computers group, preferably not.)

my network access policy has following conditions:
nas port type: virtual (vpn)
tunnel type: layer 2 tunneling protocol (l2tp)
user groups: <domain user security group>
machine groups: <domain computer security group>

it doesn't work.  can connect if remove machine groups condition.  client test machine running windows 7 , has computer certificate works making l2tp/ipsec connection. if have machine groups condition in place, client connection fails error 629 "the connection closed remote computer", , server logs error says
"the connection prevented because of policy configured on ras/vpn server. specifically, authentication method used server verify username , password may not match authentication method configured in connection profile. please contact administrator of ras server , notify them of error."

if remove machine groups condition, l2tp connection succeeds immediately, not workable solution need able resrict access based on computer's identity well.

based on rras logs, looks connecting machine information may not getting passed correctly server.  need configure work?

thanks,
  -> thayer

look @ properties of your test computer account. under dial-in tab, set 'control access through nps network policy?"

in nps profile, set "ignore user account properties?"

ace

 


ace fekay
mvp, mct, mcitp ea, mcts windows 2008 & exchange 2007, mcse & mcsa 2003/2000, mcsa messaging 2003
microsoft certified trainer
microsoft mvp - directory services

this posting provided as-is no warranties or guarantees , confers no rights.



Windows Server  >  Network Infrastructure Servers



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

0x300000d errors in Microsoft Remote Desktop client