L2TP VPN connection in windows 2012 R2


i'm trying configure l2tp vpn connection on testlab environment i'm not able to. able configure pptp , sstp.

here config:

rras server: gate.mydoamin.local

-nic 1

 ip 192.168.0.3/255.255.255.0

-nic 2

 ip 192.168.1.1/255.255.255.0

domain controller: dc.mydomain.local ip 192.168.1.2/255.255.255.0

client ip 192.168.0.10

client host file pointing vpn.mydomain.com 192.168.0.3

---------------------------------------------------------------------------

rras config

general tab: set nat+vpn

security: eap, ms-chap-v2, ikev2. nps installed other settings not here

ipv4: dhcp

--------------------

nps config:

first tab: allow access

second tab:

tunnel type: l2tp

nas port: virtual or wireless

eap allowed:

"microsoft smartcard or..."

"microsoft "peap..." both options (smart card , password)

third tab:

auth methods:

microsoft smart card (set certificate vpn.mydoamin.com)

microsoft peap:

smart card or other certificate (set vpn.mydomain.com)

password (eap-ms-chap-v2)

fourth tab:

radius standard:

ppp framed

network protection: allow full access

encription: 128 but

ip settings: dhcp

-------

server: firewall

opened ports:

udp 500

udp 4500

udp 1701

protocol: 50 allowed

----------------------------------------------

certificates:

server has 3 certificates in personal/computer folder:

-gate.mydomain.local

client auth, server auth standard ad certificate

-sstp-mydomain.com

server auth certificate used sstp connections

-vpn.mydoamin.com 

server auth, smart card access, ike ip security mediator issued deal l2tp , ike vpn

client has standard ad certificate client auth , server auth

------------------------------------------------------------------------------------

client config:

address: vpn.mydoamin.com

kind: l2tp or ikev2

security settings: tried possible configurations

check server certificate disabled

-----------------------------------------------------------------------------------

result: not work.

if set l2tp, keep getting error 789 on client, , on server in event viewer can see 1 error id 4652 , many error 4653 following

- <system>
  <provider name="microsoft-windows-security-auditing" guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
  <eventid>4652</eventid>
  <version>0</version>
  <level>0</level>
  <task>12547</task>
  <opcode>0</opcode>
  <keywords>0x8010000000000000</keywords>
  <timecreated systemtime="2015-08-03t16:48:22.613422500z" />
  <eventrecordid>40569519</eventrecordid>
  <correlation />
  <execution processid="616" threadid="4984" />
  <channel>security</channel>
  <computer>gate.mydomain.local</computer>
  <security />
  </system>
- <eventdata>
  <data name="localmmprincipalname">-</data>
  <data name="localmmcerthash">-</data>
  <data name="localmmissuingca">-</data>
  <data name="localmmrootca">-</data>
  <data name="remotemmprincipalname">client.mydomain.local</data>
  <data name="remotemmcerthash">f801bac7f68a62bb95b96d84b2373d586eda8a72</data>
  <data name="remotemmissuingca">mydoamin-dc-ca</data>
  <data name="remotemmrootca">dc=local, dc=mydomain, cn=mydomain-dc-ca</data>
  <data name="localaddress">192.168.0.3</data>
  <data name="localkeymodport">500</data>
  <data name="remoteaddress">192.168.0.10</data>
  <data name="remotekeymodport">500</data>
  <data name="keymodname">%%8222</data>
  <data name="failurepoint">%%8199</data>
  <data name="failurereason">ike: impossibile trovare un certificato di computer valido. contattare l'amministratore della rete addetto alla sicurezza per l'installazione di un certificato valido nel corretto archivio certificati.</data>
  <data name="mmauthmethod">%%8227</data>
  <data name="state">%%8203</data>
  <data name="role">%%8206</data>
  <data name="mmimpersonationstate">%%8217</data>
  <data name="mmfilterid">128310</data>
  <data name="initiatorcookie">d093a0cb7ec6075f</data>
  <data name="respondercookie">0b3a28cabe0780c2</data>
  </eventdata>
 </event>

- <system>
  <provider name="microsoft-windows-security-auditing" guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
  <eventid>4653</eventid>
  <version>0</version>
  <level>0</level>
  <task>12547</task>
  <opcode>0</opcode>
  <keywords>0x8010000000000000</keywords>
  <timecreated systemtime="2015-08-03t16:48:23.610141000z" />
  <eventrecordid>40569536</eventrecordid>
  <correlation />
  <execution processid="616" threadid="4984" />
  <channel>security</channel>
  <computer>gate.mydomain.local</computer>
  <security />
  </system>
- <eventdata>
  <data name="localmmprincipalname">-</data>
  <data name="remotemmprincipalname">-</data>
  <data name="localaddress">192.168.0.3</data>
  <data name="localkeymodport">500</data>
  <data name="remoteaddress">192.168.0.10</data>
  <data name="remotekeymodport">500</data>
  <data name="keymodname">%%8222</data>
  <data name="failurepoint">%%8199</data>
  <data name="failurereason">ricevuto cookie non valido.</data>
  <data name="mmauthmethod">%%8194</data>
  <data name="state">%%8201</data>
  <data name="role">%%8206</data>
  <data name="mmimpersonationstate">%%8217</data>
  <data name="mmfilterid">0</data>
  <data name="initiatorcookie">d093a0cb7ec6075f</data>
  <data name="respondercookie">0000000000000000</data>
  </eventdata>
  </event>

if try ikev2 instead, error  13806



i solved issue. write here solution in case other people have same problem.

refer kb2964556

https://support.microsoft.com/en-us/kb/2964556

the update described there not installed. wsus downloaded marked not necessary. manually installing update , rebooting solved issue



Windows Server  >  Network Infrastructure Servers



Comments

Popular posts from this blog

CRL Revocation always failed

Failed to query the results of bpa xpath

RDS 2012 r2 collections show black screen and then close