Server 2003 VPN clients can't verify username and password

Hi,

Hoping someone can help or point me in the right direction. I have a Windows Server 2003 R2 standard SP2 running RRAS. It has Dual NIC's and is configured for PPTP VPN. I am using a BT Business Hub 5 for internet access and using the BT Static IP service. The BT Hub assigns the static IP address chosen to the Server using DHCP. The firewall is configured to port forward PPTP traffic to the 2003 server. This all works correctly.

The 2003 server is on a domain where the DC is a 2008 R2 server. The DC also acts as the DNS and DHCP for the network.

The default gateway for the domain is pointed towards our WinGate proxy server which also acts as a DNS server.

The 2003 server LAN NIC is configured manually, usually I would not configure a deafult gateway on the LAN NIC as the WAN NIC needs the default gateway for the BT Hub.

The problem I am having is if a default gateway is configured on the LAN NIC, I can connect to the VPN and it will logon to the network. Once connected everything works ok. If the connection drops, when trying to reconnect the client can no longer verify the user name and password against the domain and the connection is refused.

If I do not have a default gateway configured in the LAN NIC the VPN clients can not verify the username and password for the domain at all and I get RPC failure errors in the event viewer with the source dnsapi.

Once this error occurs the only way I can get the clients to reconnect is to disable the WAN NIC, restart the RRAS service and enable the WAN NIC again.

Any insight will be much appreciated.

King Regards

Ian

  • Edited by Technophobic Friday, February 20, 2015 9:31 AM Update
February 20th, 2015 11:58am

Hi,

According to your description, my understanding is that WS 2003 R2 with 2 NICs(installs RRAS and configured as VPN server). If default gateway is configured on the LAN NIC,VPN works correctly, but once the connection drops, reconnection of the client will be refused. If default gateway is not configured on the LAN NIC, VPN clients can not verify the username and password. You want to configure DG on WAN NIC and make VPN connection work correctly.

In general, we configure DG on the Internet interface( or interface which is connected to external network) , and configure IP address, subnet mask, and DNS server address on internal interface. Reference Configure TCP/IP on the RRAS Server
https://technet.microsoft.com/en-us/library/dd469687.aspx#bkmk_2

If both of the NICs are assigned private IP address, I recommend you to enable NAT on internal NIC, reference :
How to configure Network Address Translation in Windows Server 2003
http://support.microsoft.com/kb/816581

If the problem still exits, it would be helpful if you may provide the ipconfig /all and route print parameters of the VPN server, and detailed information about the event logged in event viewer or related error message.

Best Regards,
Eve Wang

Free Windows Admin Tool Kit Click here and download it now
February 23rd, 2015 3:07am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics