Server 2008 R2 RRAS VPN Network Policy - User Groups *and* Machine Groups required
hello,
i setting server 2008 r2 vpn server in active directory domain , having trouble getting conditions on network access policy work. basically, restrict access policy based on both user membership in ad security group *and* computer membership in different ad security group. in other words, want specified users able connect specified computers. ("specified computers" broad domain computers group, preferably not.)
my network access policy has following conditions:
nas port type: virtual (vpn)
tunnel type: layer 2 tunneling protocol (l2tp)
user groups: <domain user security group>
machine groups: <domain computer security group>
it doesn't work. can connect if remove machine groups condition. client test machine running windows 7 , has computer certificate works making l2tp/ipsec connection. if have machine groups condition in place, client connection fails error 629 "the connection closed remote computer", , server logs error says
"the connection prevented because of policy configured on ras/vpn server. specifically, authentication method used server verify username , password may not match authentication method configured in connection profile. please contact administrator of ras server , notify them of error."
if remove machine groups condition, l2tp connection succeeds immediately, not workable solution need able resrict access based on computer's identity well.
based on rras logs, looks connecting machine information may not getting passed correctly server. need configure work?
thanks,
-> thayer
look @ properties of your test computer account. under dial-in tab, set 'control access through nps network policy?"
in nps profile, set "ignore user account properties?"
ace
ace fekay
mvp, mct, mcitp ea, mcts windows 2008 & exchange 2007, mcse & mcsa 2003/2000, mcsa messaging 2003
microsoft certified trainer
microsoft mvp - directory services
this posting provided as-is no warranties or guarantees , confers no rights.
Windows Server > Network Infrastructure Servers
Comments
Post a Comment