VPN clients stuck at verifying username/password (Full Version)

All Forums >> [ISA 2006 Firewall] >> VPN



Message


moit -> VPN clients stuck at verifying username/password (13.Mar.2009 5:22:56 PM)

We have Windows Server 2003 SP2 with ISA 2006 SP1
This issue started happening recently when a client tries to connect to the VPN they are stuck at verifying username and password prompt and then it times out.  In the ISA Server System Log event id

Event Type: Warning
Event Source: Rasman
Event Category: None
Event ID: 20209
Date:  3/13/2009
Time:  4:02:43 PM
User:  N/A
Computer: SRVR
Description:
A connection between the VPN server and the VPN client (IP) has been established, but the VPN connection cannot be completed. The most common cause for this is that a firewall or router between the VPN server and the VPN client is not configured to allow Generic Routing Encapsulation (GRE) packets (protocol 47). Verify that the firewalls and routers between your VPN server and the Internet allow GRE packets. Make sure the firewalls and routers on the user's network are also configured to allow GRE packets. If the problem persists, have the user contact the Internet service provider (ISP) to determine whether the ISP might be blocking GRE packets.
For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

is logged.

When I restart the RAS Service clients can connect again for a period of  time then again same thing happens. Any ideas?
All help is appreciated. Thanks 




ONGC -> RE: VPN clients stuck at verifying username/password (22.Mar.2009 8:16:51 PM)

Hi There,

I too am having this issue.  If any assistance could be offered it would be much appreciated.

Cheers

Steve




nanaik -> RE: VPN clients stuck at verifying username/password (23.Mar.2009 1:25:38 AM)

most probably you have not specified idle time out or client session time out in RRAS. Eg. When you specief VPN Range for /24 or say / 23 so you have 256 or 512 IP address allocate. If you disable those option whenever a new client connect assign with new IP Address. once it finish it will connect but have not assign new session with valid IP. change the setting as per your requirement and your users.
 
 RRAS---  Open remote access policy--- open ISA Policy ---- Edit profile --- Dial in constraints--- set as per your requiremet.
 
Let me know if you found solution other than the same.




nanaik -> RE: VPN clients stuck at verifying username/password (23.Mar.2009 1:29:48 AM)

When you restart the RRAS Service, it reset everything and start allocating IP from first.





mrjahnara -> RE: VPN clients stuck at verifying username/password (20.Apr.2009 9:59:46 AM)

Hi,

I am having the same issue and in my case the cisco router is not allowing the GRE protocol. I tried within the local network it works fine, the ISA server is accepting the VPN connection, but from outside connection is establishing but timeout after verifying username and password.

Have any one got the solution for this? please help.




Thanks and Regards




pwindell -> RE: VPN clients stuck at verifying username/password (20.Apr.2009 11:52:30 AM)

To anyone this may matter to:

The KB956570 patch screws up VPN.  If you ISA has this patch installed you can either try removing it or try disabling it with the script mentioned in this:

http://support.microsoft.com/kb/956570




Page: [1]