Windows 7 SSTP VPN first connect issues
Hello! I have issues when connecting to the SSTP server (Server 2008R2 SP1) for the first time. Scenario 1: Windows 7 Pro SP1 x64, English - sometimes it takes long to connect, after it connects the VPN connection gets wrong IP address (169.*), although DNS, WINS are correctly set up via the DHCP server. Disconnect and reconnect and it connects fast and everything works like a charm. This computer NEVER throws 0x80092013. Scenario 2: Windows 7 Pro SP1 x32, Slovak - almost always it takes long to connect, then it throws 0x80092013 error (looks like it couldn't reach the CRL). I click reconnect and it connects in like 1 second and everything works like a charm. This computer NEVER gets wrong IP. Both computers are in a workgroup (while the server is in a domain). Any suggestions, ideas? Could it be associated with the sleep state of the IIS? Thank you for your help.
September 21st, 2011 5:16am

Hi, This problem will happen if client is failing the certificate revocation check of the SSL certificate obtained from server side. Ensure the CRL check servers on the server side are exposed on the Internet. This is because CRL check is done on the client side during SSL connection establishment phase and the CRL check query will be directly going on the Internet. The CRL distribution point in your certificate should point to your external DNS name. The SSTP guide does not address this deployment issue that the VPN server’s internal DNS name is referenced in CRL. By default, the CRL URL is set to server’s internal DNS name (e.g. vpn1.contoso.local). To troubleshoot this issue, follow these steps: 1. Open Server Manager and navigate to Roles, Active Directory Certificate Services 2. Right click on CA name (e.g. mycompany-vpn1-CA) and choose Properties. 3. Click Extensions tab. 4. Select the pre-existing http: URL and click Remove. 5. Click Add… 6. Type http:// 7. Type external URL of VPN server 8. Type CertEnroll/ 9. Insert variable <CaName> 10. Insert variable <CRLNameSuffix> 11. Insert variable <DeltaCRLAllowed> 12. Type .crl 13. Check boxes Include in CRLs… and Include in the CDP… For more information about this problem please refer: http://technet2.microsoft.com/windowsserver2008/en/library/9f69d438-2723-4e15-836f-8e58ef2827141033.mspx?mfr=true http://support.microsoft.com/kb/961880 Please remember to click Mark as Answer on the post that helps you, and to click Unmark as Answer if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
Free Windows Admin Tool Kit Click here and download it now
September 26th, 2011 5:55am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics