Encryption Error with Remote Desktop Connection, 2008 Server, and VPN
I wasn't sure whether the Terminal Services forum was the appropriate location for this post, so I'm posting here. Please advise if there is a more appropriate location.We're a small software shop who has started upgrading dev servers to Win2008. When our people try to connect remotely via a VPN, we get the error message, "Because of an error in data encryption, this session will end. Please try connecting to the remote computer again". We're guessing there's some setting on Windows 2008 itself or on routers that needs to set, but we can't seem to find it. We're stumped. Additional facts on the problem are below. Any help 'preciated; we're going slightly nuts trying to fix this!Thanks in advance.-Billy B The VPN is NOT a Windows VPN software VPN, but a HW-based gateway-to-gateway VPN. The Terminal Server role is NOT installed on these servers. The Server Manager says that this role is not needed for mere "administrative access." We can always connect to the server briefly, and sometimes can work for 10-15 minutes before the error occurs. Errors seem to occur, not surpisingly, whenever the remote user performs an action that requires a check of security credentials. RDC clients are Vista Ultimate with RDC v6.0.6001.18000and WinXP Pro (not sure of version). Same issue. The RDC clients are able to connect to Win2003 servers without a problem. When we physically bring the RDC client workstations inside our firewalls and jack into our LAN, the problem does NOT occur. We have tried futzing with TS Gateway settings on the Advanced Tab of the RDC clients. Changing between "automatically detect" and "do not use" TS Gateway does not affect the situation. The Win2008 servers are configured to "Allow connections from computers running any version of Remote Desktop (less secure)". William G. Barnum
October 8th, 2008 8:27pm

Hi, It seems that it is a known issue with Broadcom NetXtreme II NICs on DELL PowerEdge that is running Windows 2008 Server. If you are using that product, open the Broadcom Advanced Control Suite and disable IPv4 Large Send Offload. The issue should be able to be solved.
Free Windows Admin Tool Kit Click here and download it now
October 10th, 2008 1:04pm

We don't have that NIC, and anyway the problem only seems to occur when the RDP client is coming in over a HW VPN.William G. Barnum
October 15th, 2008 8:35pm

After much AGONY (and no help from "experts" frankly), it looks like we've got a solution.We're a small software shop, and our routers/gateways are low-end LinkSys routers, specifically RVS4000, RV042, and RV082. No complaints about them, mind you; just pointing out that our problem might not occur at bigger shops with beefier networking gear.Anyway, enabling"Rate Control" on the"Bandwidth Management" feature set seemed to make the problem go away. Why this is, exactly, I'm not sure. The best answer we've been able to come up with is that IP packets are "wrapped' in very large "envelopes", which add to the bloat already present from the encryption process, and our network packets were just too big. Enabling Rate Control somehow fixed this problem. Can't say exactly how; I'm a software developer, not a sysadmin. I would say to anyone that experiences these symptoms: look for features on your router or you NIC card that deal with packet size and just play with them in controlled experiments. This Rate Control on the router was one example; the NIC card setting mentioned elsewhere in this thread is another. Different HW will have different params with different names, but hunt around in these areas. -Billy BWilliam G. Barnum
Free Windows Admin Tool Kit Click here and download it now
October 29th, 2008 7:16pm

Thank you Joson- that answer about the Netextreame II was exactly what was causing my problem.
December 16th, 2008 11:42pm

Closing this one out ....There have been a couple of proposed answers. I'm leaving the answer as my post of 10/20/2008. While Zhou Joson's answer does solve the issue for one particular make an model, it did NOT solve it for us.For those reading this thread in the future, if you have theNetXtreme II NIC, then go with Zhou's solution. If you're in the same boat as us, you may have to hunt around more.William G. Barnum
Free Windows Admin Tool Kit Click here and download it now
December 17th, 2008 2:06am

I got a solution. MY networks connected rv042 gatewaty to gateway rv082. RV082 router - Setup - System Management - Bandwidth Management WAN1 Upstream 1500~100,000 Downstream 1500~100,000
October 6th, 2010 1:56am

I have the same setup with the exact problem. Eric_Seo, What did you select from the service drop down?
Free Windows Admin Tool Kit Click here and download it now
October 30th, 2010 5:08pm

I have the same setup with the exact problem. What did you select from the service drop down?
October 30th, 2010 5:09pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics