Always on VPN NPS issue

Walts, Zachary 0 Reputation points
2023-02-24T19:43:46.69+00:00

I'm working on piloting always on vpn. Currently I have a RAS server setup and a separate server with NPS set up for authentication. I'm at the point where I need to verify if the client can connect successfully and access the network before moving on to connection profiles to deploy.

On the client side the client has a proper certificate and is set to use EAP to authenticate. On the RAS side RADIUS is set to send to the NPS server where a network policy is set up for EAP. I am able to get the client to connect to the RAS server, but the client workstation has no internet access and cannot access or ping an internal resource when connected. On the RAS server I receive the following warning:

Event ID 20271

The user [username] connected from [ip address] but failed an authentication attempt due to the following reason: the connection was prevented because of a policy configured on your RAS/VPN server. Specifically, the authentication mentod used by the server to verify your username and password may not match the authentication method configured in your connection profile. Please contact the admin off the RAS server and notify them of this error.

Looking in the NPS logs on the RADIUS server, I'm not seeing any authentication failures. I'm scratching my head on this one. I'm sure this might be a configuration issue, but I don't see how it could be authentication if the connection is succeeding and there are no errors in NPS.

Windows Server Infrastructure
Windows Server Infrastructure
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Infrastructure: A Microsoft solution area focused on providing organizations with a cloud solution that supports their real-world needs and meets evolving regulatory requirements.
513 questions
0 comments No comments
{count} votes