Wrong credentials used on local LAN/Domain when VPN in effect

Posted: 03-05-2007, 06:37 AM
When I VPN to another network from my Windows Vista Ultimate PC it appears I
loose security credentials on my local network. While VPN'ed out if I
attempt to access any shares on servers in my local network (same domain and
subnet as my PC) I get a challenged for credentials that oddly default to
the credentials I use for my VPN connection. I correct the credentials with
those of my local domain and can get access to the local resource. As soon
as I drop the VPN connection my authentication with local resources returns
to normal (is automatic and seamless, no challenge)

More facts:
1. I DO NOT have the "default gateway" option enabled on the IP stack of the
VPN connection.
2. I am using only IPV4, IPV6 is disabled on the VPN connection.
3. NetBIOS over TCP is enabled on both my local and VPN connection.
4. I'm using the standard Microsoft PPTP VPN connection to a remote ISA
server.

Any ideas?

Thanks for the help in advance.

Reply With Quote

Responses to "Wrong credentials used on local LAN/Domain when VPN in effect"

Aanand Ramachandran
Guest
Posts: n/a
 
Re: Wrong credentials used on local LAN/Domain when VPN in effect
Posted: 03-06-2007, 07:08 AM
Ken,
This is because of a design change in credential caching wherein it does
not fall back to local creds when VPN creds do not work. In order to access
the local resources specify the entire FQDN name of the local resource. THis
should solve the problem
Let me know if you need more help.

thanks
Aanand
"Ken Elmy" <ken.elmy@comcast.net> wrote in message
news:9D6039F2-E2D2-43CE-B817-25DAB0437863@microsoft.com...
> When I VPN to another network from my Windows Vista Ultimate PC it appears
> I loose security credentials on my local network. While VPN'ed out if I
> attempt to access any shares on servers in my local network (same domain
> and subnet as my PC) I get a challenged for credentials that oddly default
> to the credentials I use for my VPN connection. I correct the credentials
> with those of my local domain and can get access to the local resource. As
> soon as I drop the VPN connection my authentication with local resources
> returns to normal (is automatic and seamless, no challenge)
>
> More facts:
> 1. I DO NOT have the "default gateway" option enabled on the IP stack of
> the VPN connection.
> 2. I am using only IPV4, IPV6 is disabled on the VPN connection.
> 3. NetBIOS over TCP is enabled on both my local and VPN connection.
> 4. I'm using the standard Microsoft PPTP VPN connection to a remote ISA
> server.
>
> Any ideas?
>
> Thanks for the help in advance.
>
Reply With Quote
Ken Elmy
Guest
Posts: n/a
 
Re: Wrong credentials used on local LAN/Domain when VPN in effect
Posted: 03-07-2007, 07:05 AM
Aanand,

That did the trick. My first reaction was "you gotta be kidding me!" but
then thinking through the problem it made sense to use the FQDN as the logic
point that directed the stack as to what credentials to use (an probably to
some degree what network to interface to send the request down) -- how else
would you automate it?. The only problem I had remaining was for those
hosts that had public IP addresses I had to add their local address to the
HOSTS file. This appears to be due to the fact that the VPN connection's DNS
becomes the primary name server for the stack. It knows how to resolve the
host names to their public IP address so the local DNS server never gets a
crack at resolving them to their local addresses. The applies specifically
to Exchange servers (and no not all of us are big enough to have a front-end
exchange server in addition to a a mailbox exchange server).

While I don't like typing FQDNs (my domain name is HUGE) I do like the fact
that the appropriate credentials are used on both the local domain and the
remote one over the VPN. Not having to provide credentials for each and
every server I touch is just fantastic!

Now all I have to do is sell everyone on using FQDN's instead of NetBIOS
names when mapping drives, setting up VSS, etc...

BTW, I don't know if this helps or not but I've also started using the
LoginName@FDQN format for my credentials (VPN and local) rather than
DOMAIN\LoginName. In for a penny...in for a pound...

Thanks for all of your help.

"Aanand Ramachandran" <aanandr@microsoft.com> wrote in message
news:45ed1399@news.microsoft.com...
> Ken,
> This is because of a design change in credential caching wherein it does
> not fall back to local creds when VPN creds do not work. In order to
> access the local resources specify the entire FQDN name of the local
> resource. THis should solve the problem
> Let me know if you need more help.
>
> thanks
> Aanand
> "Ken Elmy" <ken.elmy@comcast.net> wrote in message
> news:9D6039F2-E2D2-43CE-B817-25DAB0437863@microsoft.com...
>> When I VPN to another network from my Windows Vista Ultimate PC it
>> appears I loose security credentials on my local network. While VPN'ed
>> out if I attempt to access any shares on servers in my local network
>> (same domain and subnet as my PC) I get a challenged for credentials that
>> oddly default to the credentials I use for my VPN connection. I correct
>> the credentials with those of my local domain and can get access to the
>> local resource. As soon as I drop the VPN connection my authentication
>> with local resources returns to normal (is automatic and seamless, no
>> challenge)
>>
>> More facts:
>> 1. I DO NOT have the "default gateway" option enabled on the IP stack of
>> the VPN connection.
>> 2. I am using only IPV4, IPV6 is disabled on the VPN connection.
>> 3. NetBIOS over TCP is enabled on both my local and VPN connection.
>> 4. I'm using the standard Microsoft PPTP VPN connection to a remote ISA
>> server.
>>
>> Any ideas?
>>
>> Thanks for the help in advance.
>>
>
Reply With Quote
 
LinkBack Thread Tools Display Modes
Reply


Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Something wrong with Vista networking? Some hints about enablingping and file sharing on local network ohaya Windows Vista Networking & Sharing 0 02-17-2007 06:09 PM
Reporting Domain accounts on the local PC Tom Ker Windows XP WMI 4 01-05-2006 09:29 PM
cached domain credentials, vpn, authentication failed Dirk Windows XP Configuration & Management 0 11-04-2004 08:01 PM
Saving Dial-Up Credentials when moving from one domain to another Tomer Windows XP Configuration & Management 0 07-02-2004 08:32 AM
distinguish between local or domain account? Chris Sharp Windows XP WMI 2 06-22-2004 12:21 AM


1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90