IndyColtsFan
Lifer
Ok guys, help me out here. It has been forever since I configured an ISA PPTP server but I thought I remembered everything. Something isn't quite right though, because no matter what I try, I get an Error 691 when trying to connect. The details:
DOMAIN CONTROLLER -- TEST domain
Windows 2008 w/ SP2 -- I turned the firewall off
IP: 10.2.1.5 / 24
Runs DNS and DHCP as well
ISA SERVER
Windows 2003 w/ SP2
ISA 2006 w/ SP1
Internal NIC: 10.2.1.201 /24
External NIC: 10.1.1.8 /24 Gateway is 10.1.1.201 on external NIC
*Internal NIC has 10.2.1.5 as a DNS server
ISA server is configured to enable PPTP for the domain users group in the TEST domain. ISA will hand out IPs from the internal DHCP server.
When I connect, I get an Error 691 which says user name and password combination aren't correct (they are) or that the selected authentication protocol is not permitted on the remote access server (MS-CHAP v2 is selected on both). I have enabled remote access for the accounts I am testing with in the Dial-In permissions tab on User Manager. There is also an IAS 5052 event in the ISA logs and that seems to indicate that the domain controller can't be found, BUT if you look at the domain controller logs you can see the authentication request.
I don't know what the issue could be. I've tried from a couple of different clients and get the same error. I am wondering if it is something about Windows 2008 that I don't know to do. I am bringing up another test Windows 2003 box and I plan on making it a DC and using that as a last resort.
Any ideas? As I mentioned, I don't remember this being very difficult to configure and I've set up far more complex VPN client access topologies with ISA in the past. I am hoping I am just forgetting a step since it has been so many years.
Thanks!
DOMAIN CONTROLLER -- TEST domain
Windows 2008 w/ SP2 -- I turned the firewall off
IP: 10.2.1.5 / 24
Runs DNS and DHCP as well
ISA SERVER
Windows 2003 w/ SP2
ISA 2006 w/ SP1
Internal NIC: 10.2.1.201 /24
External NIC: 10.1.1.8 /24 Gateway is 10.1.1.201 on external NIC
*Internal NIC has 10.2.1.5 as a DNS server
ISA server is configured to enable PPTP for the domain users group in the TEST domain. ISA will hand out IPs from the internal DHCP server.
When I connect, I get an Error 691 which says user name and password combination aren't correct (they are) or that the selected authentication protocol is not permitted on the remote access server (MS-CHAP v2 is selected on both). I have enabled remote access for the accounts I am testing with in the Dial-In permissions tab on User Manager. There is also an IAS 5052 event in the ISA logs and that seems to indicate that the domain controller can't be found, BUT if you look at the domain controller logs you can see the authentication request.
I don't know what the issue could be. I've tried from a couple of different clients and get the same error. I am wondering if it is something about Windows 2008 that I don't know to do. I am bringing up another test Windows 2003 box and I plan on making it a DC and using that as a last resort.
Any ideas? As I mentioned, I don't remember this being very difficult to configure and I've set up far more complex VPN client access topologies with ISA in the past. I am hoping I am just forgetting a step since it has been so many years.
Thanks!