Windows 2003 Server - VPN dropping to single user access...
Hello all. I have a situation that is becoming a real pain as more and more employees make use of VPN to facilitate working from home. I have configured Routing and Remote Access and users are connecting to the server and accessing shared resources. However, on an intermittent basis the server drops down to only allowing 1 connection at a time. I have been Googling this now for a long while and still no joy/solution. The only recourse is to reboot the server and all is hanky dory again. Is it possible that what I'm experiencing is an isolated case? Or is it that my search phrases so far have been useless and that there really is a solution to this nightmare? I'm starting to get calls late in the evening for server reboot requests as most users are now savvy to the fact that a reboot will grant them access to the resources they so desire! Suffice it to say that I'm starting to get a little miffed by this arrangement. My search in the event log does not reveal any obvious issues at the time of VPN disconnects but I could be missing something obvious elsewhere but don't know where! Appreciate any assistance and will furnish whatever info is required to help sort this issue out. Regards, anthonyk.
September 13th, 2010 12:58am

Hi, What's the OS version of VPN server? Have you changed the number of PPTP or L2TP ports to allow more concurrent connections in RRAS? You may like to right clicking "Ports" in Routing and Remote Access and change the number. Yin.
Free Windows Admin Tool Kit Click here and download it now
September 13th, 2010 8:02am

Hi, What's the OS version of VPN server? Have you changed the number of PPTP or L2TP ports to allow more concurrent connections in RRAS? You may like to right clicking "Ports" in Routing and Remote Access and change the number. Yin.
September 13th, 2010 12:28pm

Hi Tony, Thanks for post here. If you are using windows server web edition to contain RRAS, then I think the situation you encountered is normal, because windows server 2003 Web Edition can accept only one VPN connection at a time. Have you deployed RADIUS server for VPN connection authentication? Could you describe in detail that how you configure RRAS on your server to provide VPN service ? For further investigation , I suggest to following the article below to collect more detail information from logs to isolate this issue. Enabling logs for RRAS http://blogs.technet.com/b/rrasblog/archive/2005/12/22/416421.aspx Here are some articles for you reference : Remote Access Problems and Solutions http://technet.microsoft.com/en-us/library/dd469791(WS.10).aspx Troubleshooting Remote Access http://technet.microsoft.com/en-us/library/dd469757(WS.10).aspx Thanks . Tiger Li Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
September 14th, 2010 9:39am

This is actually quite shocking. I thought I had entered all the pertinent details - :(! The server in question is a Windows 2003 Server - fully patched: Version 5.2 (Build 3790.srv03_sp2_gdr.100216-1301 : Service Pack 2) The server sites behind a Linux (CentOS 5.5) based firewall that forwards all VPN related ports and protocols to the server. Remember that after a server reboot, I can have several simultaneous connections. Sometimes it will run for more than a month and sometimes I may have 2 reboots in as many days. Whenever users start reporting error 800, I normally log on to the server and check RRAS. Restarting the service doesn't do any good. It will only allow one user at a time until I reboot the server. We are a small business (<40 employees) and this is the only Windows server responsible for all authentication - it is quite laden to say the least. It also hosts the following services: DC (only on DC in the organization), DHCP, DNS, WINS, Exchange Server 2003 Standard. I will proceed with the suggestions posted by Tiger Li and hopefully we can get on the road to recovery! Regards, anthonyk.
September 19th, 2010 9:03pm

Hi anthonyk, Thanks for update. So when a user connected ,what happen when another user connects? Any error ID would be encountered ? Just FYI ,for troubleshooting Error 800 ,I’d like to you check the article below : Troubleshooting common VPN related errors http://blogs.technet.com/b/rrasblog/archive/2009/08/12/troubleshooting-common-vpn-related-errors.aspx You may also use network monitor to capture and verify network packets when this issue occurred again. I was encountered a similar issue that caused by edge device advertises a 0 window size in the TCP handshake on port 1723. Microsoft Network Monitor 3.4 http://www.microsoft.com/downloads/en/details.aspx?FamilyID=983b941d-06cb-4658-b7f6-3088333d062f Thanks. Tiger LiPlease remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
September 20th, 2010 2:31am

Hi anthonyk, Thanks for update. So when a user connected ,what happen when another user connects? Any error ID would be encountered ? Just FYI ,for troubleshooting Error 800 ,I’d like to you check the article below : I've had a look at the links but nothing in there could help. I have now installed Network Monitor 3.4 and I now have a situation where not a single connection is being made. I've captured a few packets using the filter below: tcp.port == 1723 or PayLoadheader.LowerProtocol.port == 1723 Please let me know where I can upload the capture file for your perusal. Cheers, anthonyk.
October 3rd, 2010 8:51pm

Hi anthonyk, Thanks for update. For your convenience, I have created a workspace for you. You can upload the captured file via the following link. (Please choose "Send Files to Microsoft") https://sftasia.one.microsoft.com/choosetransfer.aspx?key=061dbbc8-fc9d-4ca7-8625-06ea8b54615e Password: 1GCfg_*%5ouL Thanks. Tiger Li Please remember to click “Mark as Answer” on the post that helps you, and to click “Unmark as Answer” if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
October 4th, 2010 5:29am

Apologies for delay. I'm in the process of uploading the file. Regards, anthonyk. EDIT: Looks like I did not save the file and was about to upload an older file captured with wireshark - not sure what would be in that one. I'll monitor the situation keenly and will upload the file once the problem returns - guaranteed to be within the next 10-20 days!
October 14th, 2010 3:08am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics