[This post comes to us courtesy of Sabir Chandwale, Harshal Charde, Ajay Sarkaria and Rituraj Choudhary from Global Business Support]
In our previous post, we covered steps involved in configuring VPN on Windows Server Essentials. In this post, we will cover common problems that could result in failure of VPN functionality in your Windows Server Essentials environment.
In Windows Server 2012 R2 Essentials, VPN is deployed in a way that there is little requirement of manual configurations on the server or a client. Considering correct TCP Ports are open on the firewall and forwarded to the server, and VPN was enabled while running Anywhere Access wizard, VPN should work right out of the box. Also, on the VPN client, make sure the VPN dialer has proper protocols selected.
To be able to access the Remote Access management tools, you should first install Remote Access GUI and Command-Line Tools using the following command:
Add-WindowsFeature –Name RSAT-RemoteAccess-MGMT
Let us now discuss some common issues with VPN connection.
Error 850: The Extensible Authentication Protocol type required for authentication of the remote access connection is not installed on your computer.
If you have set up the VPN connection manually, you may encounter this error. This error indicates that none of the protocols are chosen in the VPN Connection Properties. The fix is to select Allow these protocols on the Security tab of the VPN connectoid. Microsoft CHAP Version 2 (MS-CHAP v2) would get selected automatically when you click this option. Hit OK to apply the changes.
You may also face internet or network resource access issues. It could be that you are using the default gateway of the remote network. On the Networking tab of the VPN connectoid, open the properties of Internet Protocol Version 4 (TCP/IPv4) and click Advanced.
Now, on the Advanced TCP/IP Settings window, clear the check for Use default gateway on remote network.
That should ensure that the network and internet connection are up and running.
Let’s look at another error.
Error 800: The remote connection was not made because the attempted VPN tunnels failed. The VPN server might be unreachable. If this connection is attempting to use an L2TP/IPsec tunnel, the security parameters required for IPsec negotiation might not be configured properly.
The reason for this connection failure could be either because 443 is not allowed on the firewall or there is a mismatch of certificate in RRAS and IIS (Default Web Site). To fix it, ensure that 443 is allowed and forwarded to the Windows Server 2012 R2 Essentials, and that correct SSL certificate is bound to the Default Web Site for port 443, and the same is associated with SSTP port.
You can easily figure out if SSL port 443 is blocked. If you are able to browse RWA from outside, it is open, otherwise it is not.
To verify certificates, open Internet Information Services (IIS) Manager on the Server Essentials, and click to open Bindings for the Default Web Site.
On the Site Bindings page, choose the binding for the port 443 with blank host name, and click Edit.
On the Edit Site Binding page, click View.
On the Certificate window, chose Details and make a note of the Thumbprint of the certificate.
Alternatively, you could use the following PowerShell command to display the thumbprint of the certificate active on the Default Web Site:
Get-WebBinding | Where-Object {$_.bindinginformation -eq "*:443:"} | fl certificateHash
Now, open Routing and Remote Access Management console. Right-click the server name, open its properties and click on the Security tab. Click View next to the Certificate. You should have the same certificate thumbprint here as well.
If this is a different certificate, change the certificate to match the one on the IIS. Alternatively, you may use this command to modify the thumbprint of this certificate for the Secure Socket Tunneling Protocol (SSTP) Service:
reg add HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SstpSvc\Parameters /v SHA1CertificateHash /t REG_BINARY /<thumbprint recorded from previous step> /f
Once you ensure that the certificate on the Default Web Site and SSTP are same, this issue should have been taken care of.
Let’s look at the next error.
Error 720: A connection to the remote computer could not be established. You might need to change the network settings for this connection.
If VPN client is unable to obtain an IP address from the VPN server, you may see this error.
In Server Essentials, usually the DHCP is hosted on a different device. To workaround this error, open Routing and Remote Access console and open the server Properties.
On the server properties, assign a valid static IPv4 address pool for the VPN clients, and exclude it from DHCP server scope.
On certain occasions we have seen that the on premise client would show connected to the hosted Windows Server 2012 R2 Essentials, however there may not be any connectivity the between the VPN client and the Server Essentials. In such scenarios, enable and analyze additional Routing and Remote Access information logs at the %windir%\tracing directory.
Additionally, you may want to check the events for RemoteAccess-MgmtClient and RemoteAccess-RemoteAccessServer on the Event Viewer.
These were some common VPN issues we see with Windows Server 2012 R2 Essentials, and they usually show up when VPN server settings or VPN client connectoid has been configured manually. If you enable VPN through the Anywhere Access wizard, you may not see these errors.
thanks, very good help!!
thank you
Pingback from Troubleshooting Common VPN issues on Windows Server 2012 R2 Essentials
Pingback from Understanding VPN configuration in Windows Server 2012 R2 Essentials – The Windows Server Essentials and Small Business Server Blog – Site Home – TechNet Blogs
It’s noteworthy that Windows Server 2012 R2 Essentials allows client machines to join their server without having to be inside the company network using a feature called Remote Domain Join.But it shows the best options in the article.http://www.careerchangetraining.com">CCTC
Any tips for getting a Mac running Mavericks to connect?
Really great that the VPN Issues have been tackled here. For sure VPN Users and VPN Seekers will learn a lot of new things from here. Another good source of non-biased VPN Reviews is
http://www.bestvpnservicemag.com/what-is-vpn/. Looking forward for your next posts SBS Bloggers! You really did a great job!
These are the top Microsoft Support solutions for the most common issues experienced when you use Windows
These are the top Microsoft Support solutions for the most common issues experienced when you use Windows
These are the top Microsoft Support solutions for the most common issues experienced when you use Windows
This Gentleman Sabir Chandwale, writes fantastic posts and has come to my rescue once when i called Microsoft. Sabir Chandwale i am for of gratitude for the help & support provided.
Thanks again. Microsoft Support is Awesome !!!!
Hi,
For me everything work fine but I only have one problem. When i’m connected to the VPN I can’t ping VPN Server(windows server 2012) but I can ping the clients machine from the server. How to solve that ?
Thanks for sharing this, man! It helped me a lot! I also found cool stuffs here:
http://bestvpnservicemag.com/
Just learned something about STTP that works on Windows though a little support is provided for non-Windows devices. This protocol can support multiple TCP ports at once. Got additional information at
https://www.bestvpnservicemag.com/sstp-vpn-protocol/
Just learned something about STTP that works on Windows though a little support is provided for non-Windows devices. This protocol can support multiple TCP ports at once. Got additional information at
https://www.bestvpnservicemag.com/sstp-vpn-protocol/
I can manage to connect only one user from the same public ip. If i try to connect a second user I get an error
I like good business….
http://goghost.net/">vpn windows
I like good business….
http://goghost.net/
i correct this problem
i correct this problem
These are the top Microsoft Support solutions for the most common issues experienced when you use Windows
I’ve always read write-ups like this, but I think yours was written very well with the key points laid out satisfactorily. As a tech noob I just recently opted to use a VPN for my online security. I’ve had FrootVPN
https://www.frootvpn.com/ since then and I can say I will stick to it for a long time now. It’s high speed and encrypted so I’m okay with it and for my budget. Anyways, thanks for the article!
With Gain Credit Loans, you can get instant loan/money for a wide range of your personal needs like renovation of your home, marriage in the family, a family holiday, your child’s education, buying a house, medical expenses or any other emergencies. With
minimum documentation, you can now avail a personal loan at attractive 3% interest rates. This is trust and honest loans which you will not regret, Contact us via Email: gaincreditloan01@gmail.com
Your Full Details:
Full Name. . .. . .. . .. . .. . .
Loan Amount Needed. . …
Loan Duration. . .. . .. . .. . .
Phone Number. . .. . .. . ..
Applied before. . .. . .. . ..
Country. . .. . .
Email Us: gaincreditloan01@gmail.com
http://www.happynewyear2016wishesimagessms.com/hindu-festival-2016/
http://www.happynewyear2016wishesimagessms.com/lohri-pics-lohri-sms-lohri-wallpapers/
http://www.happynewyear2016wishesimagessms.com/happy-lohri-images/
http://www.happynewyear2016wishesimagessms.com/happy-lohri-quotes/
http://www.happynewyear2016wishesimagessms.com/happy-lohri-wishes/
http://www.happynewyear2016wishesimagessms.com/happy-lohri-wallpaper/
http://www.happynewyear2016wishesimagessms.com/lohri-greetings/
http://www.happynewyear2016wishesimagessms.com/lohri-images/
http://www.happynewyear2016wishesimagessms.com/lohri-songs/
http://www.happynewyear2016wishesimagessms.com/lohri-wishes/
http://www.happynewyear2016wishesimagessms.com/lohri-festival/
http://www.happynewyear2016wishesimagessms.com/happy-lohri-bonfire-festival/
http://www.happynewyear2016wishesimagessms.com/lohri-bonfire-festival/
http://www.happynewyear2016wishesimagessms.com/lohri-the-bonfire-festival/
http://www.happynewyear2016wishesimagessms.com/up-helly-aa-event-in-scotland/
http://www.happynewyear2016wishesimagessms.com/dinagyang-festival/
http://www.happynewyear2016wishesimagessms.com/sundance-film-festival-2016/
http://www.happynewyear2016wishesimagessms.com/wwe-in-india-wwe-live-event-in-new-delhi/
http://www.happynewyear2016wishesimagessms.com/lohri-wishes-for-friends-family/
http://www.happynewyear2016wishesimagessms.com/cowboy-poetry/
http://www.happynewyear2016wishesimagessms.com/ati-atihan-festival-full-information/
http://www.happynewyear2016wishesimagessms.com/holy-ship-2016/
http://www.happynewyear2016wishesimagessms.com/things-to-do-in-banff-town-canada/
http://www.happynewyear2016wishesimagessms.com/rainbow-serpent-festival/
http://www.happynewyear2016wishesimagessms.com/sundance-film-festival-winners/
http://www.happynewyear2016wishesimagessms.com/junkanoo-parade/
http://www.happynewyear2016wishesimagessms.com/hogmanay-2016/
http://www.happynewyear2016wishesimagessms.com/ice-sculpture-snow-sculpture-festival/
http://www.happynewyear2016wishesimagessms.com/carnevale-di-venezia/
http://www.happynewyear2016wishesimagessms.com/bpm-festival-what-bpm-festival-is/
http://www.happynewyear2016wishesimagessms.com/thaipusam-thaipusam-is-a-hindu-festival/
http://www.happynewyear2016wishesimagessms.com/holy-ship-unveils-massive-lineups-for-2016-cruises/
http://www.happynewyear2016wishesimagessms.com/quebec-winter-carnival/
http://www.happynewyear2016wishesimagessms.com/jam-cruise/
http://www.happynewyear2016wishesimagessms.com/things-to-do-in-edinburgh/
http://www.happynewyear2016wishesimagessms.com/harbin-ice-festival/
http://www.happynewyear2016wishesimagessms.com/the-sundance-film-festival-a-program-of-the-sundance-institute/
http://www.republicdayimagesi.com/republic-day-songs/
http://www.republicdayimagesi.com/republic-day-status-republic-day-wallpaper/
http://www.republicdayimagesi.com/republic-day-information-republic-day-photos/
http://www.republicdayimagesi.com/republic-day-pictures-republic-day-pics/
http://www.republicdayimagesi.com/republic-day-messages-republic-day-sms/
http://www.republicdayimagesi.com/republic-day-in-hindi/
http://www.republicdayimagesi.com/essay-on-republic-day/
http://www.republicdayimagesi.com/what-is-republic-day/
http://www.republicdayimagesi.com/republic-day-wishes/
http://www.republicdayimagesi.com/speech-on-republic-day-in-hindi-speech-for-republic-day/
http://www.republicdayimagesi.com/republic-day-speech-in-hindi/
http://www.republicdayimagesi.com/republic-day-image/
http://www.republicdayimagesi.com/india-republic-day/
http://www.republicdayimagesi.com/republic-day-quotes/
http://www.republicdayimagesi.com/images-of-republic-day-pics-of-republic-day/
http://www.republicdayimagesi.com/speech-on-republic-day/
http://www.republicdayimagesi.com/republic-day-2016/
http://www.republicdayimagesi.com/republic-day-india/
http://www.republicdayimagesi.com/republic-day-speech/
http://www.republicdayimagesi.com/republic-day-images/
http://www.republicdayimagesi.com/happy-republic-day/
http://www.republicdayimagesi.com/republic-day/
http://www.republicdayi.com/republic-day-songs/
http://www.republicdayi.com/republic-day-status-republic-day-wallpaper/
http://www.republicdayi.com/republic-day-information-republic-day-photos/
http://www.republicdayi.com/republic-day-pictures-republic-day-pics/
http://www.republicdayi.com/republic-day-messages-republic-day-sms/
http://www.republicdayi.com/speech-on-republic-day-in-hindi-speech-for-republic-day/
http://www.republicdayi.com/republic-day-in-hindi/
http://www.republicdayi.com/essay-on-republic-day/
http://www.republicdayi.com/what-is-republic-day/
http://www.republicdayi.com/republic-day-wishes/
http://www.republicdayi.com/republic-day-speech-in-hindi/
http://www.republicdayi.com/republic-day-image/
http://www.republicdayi.com/india-republic-day/
http://www.republicdayi.com/republic-day-quotes/
http://www.republicdayi.com/images-of-republic-day/
http://www.republicdayi.com/speech-on-republic-day/
http://www.republicdayi.com/republic-day-2016/
http://www.republicdayi.com/republic-day-india/
http://www.republicdayi.com/republic-day-speech/
http://www.republicdayi.com/republic-day-images/
http://www.republicdayi.com/happy-republic-day/
http://www.republicdayi.com/republic-day/
http://www.happylohrii.com/lohri-pics-lohri-sms-lohri-wallpapers/
http://www.happylohrii.com/happy-lohri-images/
http://www.happylohrii.com/hindu-festival-2016/
http://www.happylohrii.com/happy-lohri-quotes/
http://www.happylohrii.com/happy-lohri-wishes/
http://www.happylohrii.com/happy-lohri-wallpaper/
http://www.happylohrii.com/lohri-greetings/
http://www.happylohrii.com/lohri-images/
http://www.happylohrii.com/lohri-songs/
http://www.happylohrii.com/lohri-wishes/
http://www.happylohrii.com/lohri-festival/
http://www.happylohrii.com/happy-lohri-bonfire-festival/
http://www.happylohrii.com/lohri-bonfire-festival/
We Offer Online Financial Loan To Individual Apply Now.
Getting legitimate loan has always been a huge problem to clients who are financially in needs. We have been accredited by the lender’s council to give out loans to local and international clients Contact us on Email : [ keirangavinfinance@gmail.com ]
Need personal Loan?
Business Cash Loan?
Unsecured Loan?
Fast and Simple Loan?
Quick Application Process?
Approvals within 30mins
Get unsecured working capital?
Name:
Gender:
Country:
Loan Amount:
Purpose of Loan:
Your Contact email:
Personal Mobile Phone:
if interested Contact us on Email: [ keirangavinfinance@gmail.com ]
We Offer Online Financial Loan To Individual Apply Now.
Getting legitimate loan has always been a huge problem to clients who are financially in needs. We have been accredited by the lender’s council to give out loans to local and international clients Contact us on Email : [ keirangavinfinance@gmail.com ]
Need personal Loan?
Business Cash Loan?
Unsecured Loan?
Fast and Simple Loan?
Quick Application Process?
Approvals within 30mins
Get unsecured working capital?
Name:
Gender:
Country:
Loan Amount:
Purpose of Loan:
Your Contact email:
Personal Mobile Phone:
if interested Contact us on Email: keirangavinfinance@gmail.com
We offer the following types of loans:
*Commercial Loans.
*Debt Consolidation
*Personal Loans.
*Business Loans.
*Investments Loans.
*Development Loans.
*Acquisition Loans.
*Construction loans.
*Business Loans And many More: Contact us on Email: [ cholrisfinance@gmail.com ]