DirectAccess stuck Connecting after VPN disconnect?

We use OpenVPN for our VPN clients coupled with DirectAccess for transparent domain access on Windows 8.1. If I boot a client it connects to DA and everything works as it should. When I connect to OpenVPN on the same client, DA immediately changes to a "Connecting ..." state and stays there, even after I disconnect from the VPN.

If I run a netsh interface httpstunnel show interface it shows a 0x274c failed to connect to the IP-HTTPS server. Waiting to reconnect. 

The DirectAccess Client Troubleshooter fails at the IP Connectivity, Infrastructure Tunnel, and User Tunnel Tests.

However, I can access the directaccess server just fine on port 443, even via a web browser.

I've tried restarting the IPHelper service and the IKE service, but DA eventually reverts to the same 0x274c error. The only way to clear it is to reboot the client.

The log from the DA Troubleshooter shows that NLS thinks it's "internal" I believe, as the IsExternal and GetNLS return the internal FQDN of the DA server and try to connect to that, then throw an error 503. Almost everything after that in the log also fails, of course.

I'm at a loss as to how to solve this.

April 24th, 2015 12:13am

I found the following KB article, which has helped a little but still hasn't resolved the inability for my client to re-connect after disconnecting from the VPN.

https://technet.microsoft.com/en-us/library/ee809093.aspx?f=255&MSPPError=-2147217396

If I set those two registry entries, a netsh interface httpstunnel show interface now properly reports that I have "other corporate connectivity available" when I connect to the VPN. A netsh dnsclient show state also properly detects whether I am inside or outside the corporate network.

However, I still cannot achieve a DirectAccess client re-connection after disconnecting from the VPN. The httpstunnel still reports a 0x274c, failed to connect to the IPHTTPS server. Waiting to reconnect.

I don't see anyting in the Event Viewer on either the client or the server, so I'm not sure  where to look next to continue troubleshooting.

Note - the client seems to have full connectivity to the DA server. I can run a Test-NetConnection -Port 443 -ComputerName da.myserver.com and it is successful. I can ping the hostname da.myserver.com and all 4 replies are successful.

I noticed that if I run an ipconfig on the client, the Tunnel adapter iphttpsinterface states "Media disconnected."

Can anyone assist?



  • Edited by Matt336 9 hours 35 minutes ago
Free Windows Admin Tool Kit Click here and download it now
April 26th, 2015 5:26pm

I found the following KB article, which has helped a little but still hasn't resolved the inability for my client to re-connect after disconnecting from the VPN.

https://technet.microsoft.com/en-us/library/ee809093.aspx?f=255&MSPPError=-2147217396

If I set those two registry entries, a netsh interface httpstunnel show interface now properly reports that I have "other corporate connectivity available" when I connect to the VPN. A netsh dnsclient show state also properly detects whether I am inside or outside the corporate network.

However, I still cannot achieve a DirectAccess client re-connection after disconnecting from the VPN. The httpstunnel still reports a 0x274c, failed to connect to the IPHTTPS server. Waiting to reconnect.

I don't see anyting in the Event Viewer on either the client or the server, so I'm not sure  where to look next to continue troubleshooting.

Note - the client seems to have full connectivity to the DA server. I can run a Test-NetConnection -Port 443 -ComputerName da.myserver.com and it is successful. I can ping the hostname da.myserver.com and all 4 replies are successful.

I noticed that if I run an ipconfig on the client, the Tunnel adapter iphttpsinterface states "Media disconnected."

Can anyone assist?



  • Edited by Matt336 Sunday, April 26, 2015 9:45 PM
April 26th, 2015 9:24pm

I found the following KB article, which has helped a little but still hasn't resolved the inability for my client to re-connect after disconnecting from the VPN.

https://technet.microsoft.com/en-us/library/ee809093.aspx?f=255&MSPPError=-2147217396

If I set those two registry entries, a netsh interface httpstunnel show interface now properly reports that I have "other corporate connectivity available" when I connect to the VPN. A netsh dnsclient show state also properly detects whether I am inside or outside the corporate network.

However, I still cannot achieve a DirectAccess client re-connection after disconnecting from the VPN. The httpstunnel still reports a 0x274c, failed to connect to the IPHTTPS server. Waiting to reconnect.

I don't see anyting in the Event Viewer on either the client or the server, so I'm not sure  where to look next to continue troubleshooting.

Note - the client seems to have full connectivity to the DA server. I can run a Test-NetConnection -Port 443 -ComputerName da.myserver.com and it is successful. I can ping the hostname da.myserver.com and all 4 replies are successful.

I noticed that if I run an ipconfig on the client, the Tunnel adapter iphttpsinterface states "Media disconnected."

Can anyone assist?



  • Edited by Matt336 Sunday, April 26, 2015 9:45 PM
Free Windows Admin Tool Kit Click here and download it now
April 26th, 2015 9:24pm

I found the following KB article, which has helped a little but still hasn't resolved the inability for my client to re-connect after disconnecting from the VPN.

https://technet.microsoft.com/en-us/library/ee809093.aspx?f=255&MSPPError=-2147217396

If I set those two registry entries, a netsh interface httpstunnel show interface now properly reports that I have "other corporate connectivity available" when I connect to the VPN. A netsh dnsclient show state also properly detects whether I am inside or outside the corporate network.

However, I still cannot achieve a DirectAccess client re-connection after disconnecting from the VPN. The httpstunnel still reports a 0x274c, failed to connect to the IPHTTPS server. Waiting to reconnect.

I don't see anyting in the Event Viewer on either the client or the server, so I'm not sure  where to look next to continue troubleshooting.

Note - the client seems to have full connectivity to the DA server. I can run a Test-NetConnection -Port 443 -ComputerName da.myserver.com and it is successful. I can ping the hostname da.myserver.com and all 4 replies are successful.

I noticed that if I run an ipconfig on the client, the Tunnel adapter iphttpsinterface states "Media disconnected."

Can anyone assist?



  • Edited by Matt336 Sunday, April 26, 2015 9:45 PM
April 26th, 2015 9:24pm

I found the following KB article, which has helped a little but still hasn't resolved the inability for my client to re-connect after disconnecting from the VPN.

https://technet.microsoft.com/en-us/library/ee809093.aspx?f=255&MSPPError=-2147217396

If I set those two registry entries, a netsh interface httpstunnel show interface now properly reports that I have "other corporate connectivity available" when I connect to the VPN. A netsh dnsclient show state also properly detects whether I am inside or outside the corporate network.

However, I still cannot achieve a DirectAccess client re-connection after disconnecting from the VPN. The httpstunnel still reports a 0x274c, failed to connect to the IPHTTPS server. Waiting to reconnect.

I don't see anyting in the Event Viewer on either the client or the server, so I'm not sure  where to look next to continue troubleshooting.

Note - the client seems to have full connectivity to the DA server. I can run a Test-NetConnection -Port 443 -ComputerName da.myserver.com and it is successful. I can ping the hostname da.myserver.com and all 4 replies are successful.

I noticed that if I run an ipconfig on the client, the Tunnel adapter iphttpsinterface states "Media disconnected."

Can anyone assist?



  • Edited by Matt336 Sunday, April 26, 2015 9:45 PM
Free Windows Admin Tool Kit Click here and download it now
April 26th, 2015 9:24pm

I found the following KB article, which has helped a little but still hasn't resolved the inability for my client to re-connect after disconnecting from the VPN.

https://technet.microsoft.com/en-us/library/ee809093.aspx?f=255&MSPPError=-2147217396

If I set those two registry entries, a netsh interface httpstunnel show interface now properly reports that I have "other corporate connectivity available" when I connect to the VPN. A netsh dnsclient show state also properly detects whether I am inside or outside the corporate network.

However, I still cannot achieve a DirectAccess client re-connection after disconnecting from the VPN. The httpstunnel still reports a 0x274c, failed to connect to the IPHTTPS server. Waiting to reconnect.

I don't see anyting in the Event Viewer on either the client or the server, so I'm not sure  where to look next to continue troubleshooting.

Note - the client seems to have full connectivity to the DA server. I can run a Test-NetConnection -Port 443 -ComputerName da.myserver.com and it is successful. I can ping the hostname da.myserver.com and all 4 replies are successful.

I noticed that if I run an ipconfig on the client, the Tunnel adapter iphttpsinterface states "Media disconnected."

Can anyone assist?



  • Edited by Matt336 Sunday, April 26, 2015 9:45 PM
April 26th, 2015 9:24pm

I found the following KB article, which has helped a little but still hasn't resolved the inability for my client to re-connect after disconnecting from the VPN.

https://technet.microsoft.com/en-us/library/ee809093.aspx?f=255&MSPPError=-2147217396

If I set those two registry entries, a netsh interface httpstunnel show interface now properly reports that I have "other corporate connectivity available" when I connect to the VPN. A netsh dnsclient show state also properly detects whether I am inside or outside the corporate network.

However, I still cannot achieve a DirectAccess client re-connection after disconnecting from the VPN. The httpstunnel still reports a 0x274c, failed to connect to the IPHTTPS server. Waiting to reconnect.

I don't see anyting in the Event Viewer on either the client or the server, so I'm not sure  where to look next to continue troubleshooting.

Note - the client seems to have full connectivity to the DA server. I can run a Test-NetConnection -Port 443 -ComputerName da.myserver.com and it is successful. I can ping the hostname da.myserver.com and all 4 replies are successful.

I noticed that if I run an ipconfig on the client, the Tunnel adapter iphttpsinterface states "Media disconnected."

Can anyone assist?



  • Edited by Matt336 Sunday, April 26, 2015 9:45 PM
Free Windows Admin Tool Kit Click here and download it now
April 26th, 2015 9:24pm

I found the following KB article, which has helped a little but still hasn't resolved the inability for my client to re-connect after disconnecting from the VPN.

https://technet.microsoft.com/en-us/library/ee809093.aspx?f=255&MSPPError=-2147217396

If I set those two registry entries, a netsh interface httpstunnel show interface now properly reports that I have "other corporate connectivity available" when I connect to the VPN. A netsh dnsclient show state also properly detects whether I am inside or outside the corporate network.

However, I still cannot achieve a DirectAccess client re-connection after disconnecting from the VPN. The httpstunnel still reports a 0x274c, failed to connect to the IPHTTPS server. Waiting to reconnect.

I don't see anyting in the Event Viewer on either the client or the server, so I'm not sure  where to look next to continue troubleshooting.

Note - the client seems to have full connectivity to the DA server. I can run a Test-NetConnection -Port 443 -ComputerName da.myserver.com and it is successful. I can ping the hostname da.myserver.com and all 4 replies are successful.

I noticed that if I run an ipconfig on the client, the Tunnel adapter iphttpsinterface states "Media disconnected."

Can anyone assist?



  • Edited by Matt336 Sunday, April 26, 2015 9:45 PM
April 26th, 2015 9:24pm

This only seems to be a problem on our Windows 8.1 Enterprise Hyper-V VMs. When running on a physical machine, no tweaks are necessary and everything works as expected. I suspect it's an issue with the Hyper-V NIC driver, as again - it works perfectly on two different Dell laptops and a Dell desktop.
  • Marked as answer by Matt336 16 hours 30 minutes ago
  • Edited by Matt336 16 hours 30 minutes ago
Free Windows Admin Tool Kit Click here and download it now
May 9th, 2015 10:50am

This only seems to be a problem on our Windows 8.1 Enterprise Hyper-V VMs. When running on a physical machine, no tweaks are necessary and everything works as expected. I suspect it's an issue with the Hyper-V NIC driver, as again - it works perfectly on two different Dell laptops and a Dell desktop.
  • Marked as answer by Matt336 Saturday, May 09, 2015 2:48 PM
  • Edited by Matt336 Saturday, May 09, 2015 2:49 PM
May 9th, 2015 2:48pm

This only seems to be a problem on our Windows 8.1 Enterprise Hyper-V VMs. When running on a physical machine, no tweaks are necessary and everything works as expected. I suspect it's an issue with the Hyper-V NIC driver, as again - it works perfectly on two different Dell laptops and a Dell desktop.
  • Marked as answer by Matt336 Saturday, May 09, 2015 2:48 PM
  • Edited by Matt336 Saturday, May 09, 2015 2:49 PM
Free Windows Admin Tool Kit Click here and download it now
May 9th, 2015 2:48pm

This only seems to be a problem on our Windows 8.1 Enterprise Hyper-V VMs. When running on a physical machine, no tweaks are necessary and everything works as expected. I suspect it's an issue with the Hyper-V NIC driver, as again - it works perfectly on two different Dell laptops and a Dell desktop.
  • Marked as answer by Matt336 Saturday, May 09, 2015 2:48 PM
  • Edited by Matt336 Saturday, May 09, 2015 2:49 PM
May 9th, 2015 2:48pm

This only seems to be a problem on our Windows 8.1 Enterprise Hyper-V VMs. When running on a physical machine, no tweaks are necessary and everything works as expected. I suspect it's an issue with the Hyper-V NIC driver, as again - it works perfectly on two different Dell laptops and a Dell desktop.
  • Marked as answer by Matt336 Saturday, May 09, 2015 2:48 PM
  • Edited by Matt336 Saturday, May 09, 2015 2:49 PM
Free Windows Admin Tool Kit Click here and download it now
May 9th, 2015 2:48pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics