Error Description: 13801: IKE authentication credentials are unacceptable.

Hi There

I need a solution for this Error Description: 13801: IKE authentication credentials are unacceptable..

Thanks

Farhan

August 20th, 2015 2:21pm

Hi Farhan,

This is a good TechNet blog with possible causes and fixes:

http://blogs.technet.com/b/rrasblog/archive/2009/08/12/troubleshooting-common-vpn-related-errors.aspx

Free Windows Admin Tool Kit Click here and download it now
August 20th, 2015 4:04pm

Hi Farhan,

The article provided by Basty_ss lists the possibilities that may cause this issue:

>The machine certificate used for IKEv2 validation on RAS Server does not have server Authentication as the EKU:

We may check it by the following steps: On VPN server, run mmc, add snap-in certificates, expand certificates-personal-certificates, double click the certificate installed, click detail for enhanced key usage, verify if there is server authentication below.

>The machine certificate on RAS server has expired.

If the issue is caused by this reason, you may connect CA administrator, enroll a new certificate that doesnt expire.

>The root certificate to validate the RAS server certificate is not present on client.

If the client and server are domain members, the root certificate will be installed automatically in trusted root certification authorities. We may check if the certificate exits.

> VPN Server Name as given on client doesnt match with the subjectName of the server certificate.

On client, Open VPN connection properties, click General, in host name or IP address of destination we need to enter the subject name of the certificate used by VPN server instead of the IP address of VPN server. The subject name of servers certificate usually configured as the FQDN of VPN server.

In my opinion, the forth possibility is most likely to be the cause.

Best regards,

Anne he

August 23rd, 2015 10:01pm

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics