Real Geek Forums  

Go Back   Real Geek Forums > Archives > Operating Systems > Windows Vista > Windows Vista Networking & Sharing

Notices

Reply

Vista can't authenticate on VPN connection

 

LinkBack Thread Tools Display Modes
Old 06-22-2007, 04:56 AM   #1 (permalink)
Default Vista can't authenticate on VPN connection

Hello,

I've read up quite a bit about VPN problems with Vista, but can't seem to
find a solution to my issues. We have VPN setup to our Cisco PIX 515E
(which doesn't support MS-CHAP V2). Of course, since Microsoft was nice
enough to remove MS-CHAP V1 in Vista, this now prevents any of our users
from upgrading to Vista, and I'm trying to find a workaround.

Right now, I've made changes to our PIX to allow authentication over PAP,
CHAP or MSCHAPV1. The PIX has always required 128bit encryption. (This
according to the MS KB article discussing the death of MSCHAP V1, should
work).

In my VPN connection security , I've tried every combination of PAP, CHAP
and the various data encryption options, but can't get beyond the dreaded
"Error 732: Your computer and the remote computer could not agree on PPP
control protocols". I don't see anything interesting in the PIX logs or in
the Windows Vista client event logs.

User authentication is being done by an IAS server that the PIX connects to
just fine. Clients running XP, 2000 and OS X can all VPN in without any
problems at all.

Has ANYONE gotten Vista <---> PIX VPN working at all with the Vista VPN
client?

Daniel Peterson
Guest
 
Posts: n/a
Reply With Quote  
Old 06-22-2007, 04:26 PM   #2 (permalink)
Default Re: Vista can't authenticate on VPN connection

You may want to disable PAP, CHAP and MS-CHAP v2. This post may help,

VPN works with all OS except Vista
http://www.chicagotech.net/netforums...opic.php?t=729

Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
"Daniel Peterson" <pythas@hotmail.com> wrote in message news:2903CE86-9E79-4EBB-BA12-AD4EFA568289@microsoft.com...
Hello,

I've read up quite a bit about VPN problems with Vista, but can't seem to
find a solution to my issues. We have VPN setup to our Cisco PIX 515E
(which doesn't support MS-CHAP V2). Of course, since Microsoft was nice
enough to remove MS-CHAP V1 in Vista, this now prevents any of our users
from upgrading to Vista, and I'm trying to find a workaround.

Right now, I've made changes to our PIX to allow authentication over PAP,
CHAP or MSCHAPV1. The PIX has always required 128bit encryption. (This
according to the MS KB article discussing the death of MSCHAP V1, should
work).

In my VPN connection security , I've tried every combination of PAP, CHAP
and the various data encryption options, but can't get beyond the dreaded
"Error 732: Your computer and the remote computer could not agree on PPP
control protocols". I don't see anything interesting in the PIX logs or in
the Windows Vista client event logs.

User authentication is being done by an IAS server that the PIX connects to
just fine. Clients running XP, 2000 and OS X can all VPN in without any
problems at all.

Has ANYONE gotten Vista <---> PIX VPN working at all with the Vista VPN
client?

Robert L [MVP - Networking]
Guest
 
Posts: n/a
Reply With Quote  
Old 06-24-2007, 03:41 AM   #3 (permalink)
Default Re: Vista can't authenticate on VPN connection

Hello,

As I said, I've tried every combination of PAP, CHAP and data encryption.

Other than an email address to send trace logs to for debugging, I didn't see anything new in that link.

Any other suggestions?
"Robert L [MVP - Networking]" <noreply@hotmail.com> wrote in message news:eEbeMoOtHHA.4796@TK2MSFTNGP04.phx.gbl...
You may want to disable PAP, CHAP and MS-CHAP v2. This post may help,

VPN works with all OS except Vista
http://www.chicagotech.net/netforums...opic.php?t=729

Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
"Daniel Peterson" <pythas@hotmail.com> wrote in message news:2903CE86-9E79-4EBB-BA12-AD4EFA568289@microsoft.com...
Hello,

I've read up quite a bit about VPN problems with Vista, but can't seem to
find a solution to my issues. We have VPN setup to our Cisco PIX 515E
(which doesn't support MS-CHAP V2). Of course, since Microsoft was nice
enough to remove MS-CHAP V1 in Vista, this now prevents any of our users
from upgrading to Vista, and I'm trying to find a workaround.

Right now, I've made changes to our PIX to allow authentication over PAP,
CHAP or MSCHAPV1. The PIX has always required 128bit encryption. (This
according to the MS KB article discussing the death of MSCHAP V1, should
work).

In my VPN connection security , I've tried every combination of PAP, CHAP
and the various data encryption options, but can't get beyond the dreaded
"Error 732: Your computer and the remote computer could not agree on PPP
control protocols". I don't see anything interesting in the PIX logs or in
the Windows Vista client event logs.

User authentication is being done by an IAS server that the PIX connects to
just fine. Clients running XP, 2000 and OS X can all VPN in without any
problems at all.

Has ANYONE gotten Vista <---> PIX VPN working at all with the Vista VPN
client?

Daniel Peterson
Guest
 
Posts: n/a
Reply With Quote  
Old 06-24-2007, 05:32 PM   #4 (permalink)
Default Re: Vista can't authenticate on VPN connection

Hi Daniel
Both PAP and CHAP do not support encryption. In order to use them you
would have to turn off 128-bit encryption on the server.

thanks
Aanand

"Daniel Peterson" <pythas@hotmail.com> wrote in message
news:2903CE86-9E79-4EBB-BA12-AD4EFA568289@microsoft.com...
Quote:
> Hello,
>
> I've read up quite a bit about VPN problems with Vista, but can't seem to
> find a solution to my issues. We have VPN setup to our Cisco PIX 515E
> (which doesn't support MS-CHAP V2). Of course, since Microsoft was nice
> enough to remove MS-CHAP V1 in Vista, this now prevents any of our users
> from upgrading to Vista, and I'm trying to find a workaround.
>
> Right now, I've made changes to our PIX to allow authentication over PAP,
> CHAP or MSCHAPV1. The PIX has always required 128bit encryption. (This
> according to the MS KB article discussing the death of MSCHAP V1, should
> work).
>
> In my VPN connection security , I've tried every combination of PAP, CHAP
> and the various data encryption options, but can't get beyond the dreaded
> "Error 732: Your computer and the remote computer could not agree on PPP
> control protocols". I don't see anything interesting in the PIX logs or
> in the Windows Vista client event logs.
>
> User authentication is being done by an IAS server that the PIX connects
> to just fine. Clients running XP, 2000 and OS X can all VPN in without
> any problems at all.
>
> Has ANYONE gotten Vista <---> PIX VPN working at all with the Vista VPN
> client?
Aanand Ramachandran
Guest
 
Posts: n/a
Reply With Quote  
Old 06-25-2007, 06:21 PM   #5 (permalink)
Default Re: Vista can't authenticate on VPN connection

Hello,

Thank you, that's what I was starting to wonder.

Well, that pretty much kills that solution.

THANKS MICROSOFT FOR DEPRECATING MSCHAP V1.

"Aanand Ramachandran" <aanandr@microsoft.com> wrote in message
news:467eaac0$1@news.microsoft.com...
Quote:
> Hi Daniel
> Both PAP and CHAP do not support encryption. In order to use them you
> would have to turn off 128-bit encryption on the server.
>
> thanks
> Aanand
>
> "Daniel Peterson" <pythas@hotmail.com> wrote in message
> news:2903CE86-9E79-4EBB-BA12-AD4EFA568289@microsoft.com...
Quote:
>> Hello,
>>
>> I've read up quite a bit about VPN problems with Vista, but can't seem to
>> find a solution to my issues. We have VPN setup to our Cisco PIX 515E
>> (which doesn't support MS-CHAP V2). Of course, since Microsoft was nice
>> enough to remove MS-CHAP V1 in Vista, this now prevents any of our users
>> from upgrading to Vista, and I'm trying to find a workaround.
>>
>> Right now, I've made changes to our PIX to allow authentication over PAP,
>> CHAP or MSCHAPV1. The PIX has always required 128bit encryption. (This
>> according to the MS KB article discussing the death of MSCHAP V1, should
>> work).
>>
>> In my VPN connection security , I've tried every combination of PAP, CHAP
>> and the various data encryption options, but can't get beyond the dreaded
>> "Error 732: Your computer and the remote computer could not agree on PPP
>> control protocols". I don't see anything interesting in the PIX logs or
>> in the Windows Vista client event logs.
>>
>> User authentication is being done by an IAS server that the PIX connects
>> to just fine. Clients running XP, 2000 and OS X can all VPN in without
>> any problems at all.
>>
>> Has ANYONE gotten Vista <---> PIX VPN working at all with the Vista VPN
>> client?
>
Daniel Peterson
Guest
 
Posts: n/a
Reply With Quote  
Old 03-26-2008, 04:40 PM   #6 (permalink)
Default Re: Vista can't authenticate on VPN connection


I have been able to connect to one of our clients Cisco PIX firewall
with the Vista VPN client. Im not sure what version they are running bu
here is how I made it happen

After setting up the connection go into Propertie

Go to the Options tab and click the PPP Settings butto

Make sure all of these check boxes are NOT selecte

hit ok

While on the Options tab make sure that the Include Windows logo
domain check box is NOT selecte

Next go to the Security Ta

select the Advanced (custom settings) radio butto

Then click the settings butto

in the Advanced security settings form select Optional Encryption fro
the Data Encryption drop dow

select the Allow these protocols radio button and make sure that onl
Challenge Handshake Authentication Protocol(CHAP) is selecte

hit ok

Now head over to the Networking ta

on the networking tab select L2TP IPsec VPN from the Type of VP
dropdow

click the IPsec Settings butto

make sure that the Use certificate for authentication radio button i
selected and the check box underneath it is checke

hit o

Back on the Networking tab I disabled all protocols except for TCP/IPv
, Im not sure that this is necessary but I didn't want any sill
protocols getting in the way

after that hit ok and try to connec

Im not sure if all of these changes were necessary but this is the onl
way I have been able to get a connection to a PIX firewall from vista
Maybe next time Microsoft will consider the rest of the industry whe
they decide to start dropping protocols (prolly not). I wonder wha
kind of firewall Bill uses?!

--
dmaselbas
dmaselbas
Guest
 
Posts: n/a
Reply With Quote  
Reply

Tags
None

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads

Thread Thread Starter Forum Replies Last Post
Using certificates with to authenticate users with L2TP/IPSec jrp Windows Vista Networking & Sharing 0 04-10-2007 08:54 PM
Vista "Attempting to Authenticate" wireless Moe Man Windows Vista Networking & Sharing 2 03-30-2007 02:33 PM
Can't authenticate on Mac connection... IWantXPBack Windows Vista Networking & Sharing 3 03-14-2007 12:40 PM
Copied Profile - Now Outlook Express won't authenticate Sirius Windows XP Configuration & Management 0 07-03-2004 02:27 PM
failure to authenticate bobr Windows XP Work Remotely 0 12-17-2003 12:36 PM


All times are GMT. The time now is 05:47 AM.


Powered by vBulletin® Version 3.7.1
Copyright ©2000 - 2008, Jelsoft Enterprises Ltd.
Copyright © 2005 - 2007 RealGeek.com. All rights reserved.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90