A Windows Vista forum. Vista Banter

Welcome to Vista Banter.

You are currently viewing our boards as a guest which gives you limited access to view most discussions, articles and access our other FREE features. By joining our free community you will have access to ask questions and reply to others posts, upload your own photos and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact contact support.

Go Back   Home » Vista Banter forum » Microsoft Windows Vista » Networking with Windows Vista
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

Networking with Windows Vista Networking issues and questions with Windows Vista. (microsoft.public.windows.vista.networking_sharing)

Vista can't authenticate on VPN connection



 
 
LinkBack Thread Tools Display Modes
  #1 (permalink)  
Old June 22nd 07, 04:56 AM posted to microsoft.public.windows.vista.networking_sharing
Daniel Peterson
external usenet poster
 
Posts: 7
Default Vista can't authenticate on VPN connection

Hello,

I've read up quite a bit about VPN problems with Vista, but can't seem to
find a solution to my issues. We have VPN setup to our Cisco PIX 515E
(which doesn't support MS-CHAP V2). Of course, since Microsoft was nice
enough to remove MS-CHAP V1 in Vista, this now prevents any of our users
from upgrading to Vista, and I'm trying to find a workaround.

Right now, I've made changes to our PIX to allow authentication over PAP,
CHAP or MSCHAPV1. The PIX has always required 128bit encryption. (This
according to the MS KB article discussing the death of MSCHAP V1, should
work).

In my VPN connection security , I've tried every combination of PAP, CHAP
and the various data encryption options, but can't get beyond the dreaded
"Error 732: Your computer and the remote computer could not agree on PPP
control protocols". I don't see anything interesting in the PIX logs or in
the Windows Vista client event logs.

User authentication is being done by an IAS server that the PIX connects to
just fine. Clients running XP, 2000 and OS X can all VPN in without any
problems at all.

Has ANYONE gotten Vista --- PIX VPN working at all with the Vista VPN
client?

  #2 (permalink)  
Old June 22nd 07, 04:26 PM posted to microsoft.public.windows.vista.networking_sharing
Robert L [MVP - Networking]
external usenet poster
 
Posts: 1,227
Default Vista can't authenticate on VPN connection

You may want to disable PAP, CHAP and MS-CHAP v2. This post may help,

VPN works with all OS except Vista
http://www.chicagotech.net/netforums...opic.php?t=729

Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
"Daniel Peterson" wrote in message ...
Hello,

I've read up quite a bit about VPN problems with Vista, but can't seem to
find a solution to my issues. We have VPN setup to our Cisco PIX 515E
(which doesn't support MS-CHAP V2). Of course, since Microsoft was nice
enough to remove MS-CHAP V1 in Vista, this now prevents any of our users
from upgrading to Vista, and I'm trying to find a workaround.

Right now, I've made changes to our PIX to allow authentication over PAP,
CHAP or MSCHAPV1. The PIX has always required 128bit encryption. (This
according to the MS KB article discussing the death of MSCHAP V1, should
work).

In my VPN connection security , I've tried every combination of PAP, CHAP
and the various data encryption options, but can't get beyond the dreaded
"Error 732: Your computer and the remote computer could not agree on PPP
control protocols". I don't see anything interesting in the PIX logs or in
the Windows Vista client event logs.

User authentication is being done by an IAS server that the PIX connects to
just fine. Clients running XP, 2000 and OS X can all VPN in without any
problems at all.

Has ANYONE gotten Vista --- PIX VPN working at all with the Vista VPN
client?

  #3 (permalink)  
Old June 24th 07, 03:41 AM posted to microsoft.public.windows.vista.networking_sharing
Daniel Peterson
external usenet poster
 
Posts: 7
Default Vista can't authenticate on VPN connection

Hello,

As I said, I've tried every combination of PAP, CHAP and data encryption.

Other than an email address to send trace logs to for debugging, I didn't see anything new in that link.

Any other suggestions?
"Robert L [MVP - Networking]" wrote in message ...
You may want to disable PAP, CHAP and MS-CHAP v2. This post may help,

VPN works with all OS except Vista
http://www.chicagotech.net/netforums...opic.php?t=729

Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
"Daniel Peterson" wrote in message ...
Hello,

I've read up quite a bit about VPN problems with Vista, but can't seem to
find a solution to my issues. We have VPN setup to our Cisco PIX 515E
(which doesn't support MS-CHAP V2). Of course, since Microsoft was nice
enough to remove MS-CHAP V1 in Vista, this now prevents any of our users
from upgrading to Vista, and I'm trying to find a workaround.

Right now, I've made changes to our PIX to allow authentication over PAP,
CHAP or MSCHAPV1. The PIX has always required 128bit encryption. (This
according to the MS KB article discussing the death of MSCHAP V1, should
work).

In my VPN connection security , I've tried every combination of PAP, CHAP
and the various data encryption options, but can't get beyond the dreaded
"Error 732: Your computer and the remote computer could not agree on PPP
control protocols". I don't see anything interesting in the PIX logs or in
the Windows Vista client event logs.

User authentication is being done by an IAS server that the PIX connects to
just fine. Clients running XP, 2000 and OS X can all VPN in without any
problems at all.

Has ANYONE gotten Vista --- PIX VPN working at all with the Vista VPN
client?

  #4 (permalink)  
Old June 24th 07, 05:32 PM posted to microsoft.public.windows.vista.networking_sharing
Aanand Ramachandran
external usenet poster
 
Posts: 36
Default Vista can't authenticate on VPN connection

Hi Daniel
Both PAP and CHAP do not support encryption. In order to use them you
would have to turn off 128-bit encryption on the server.

thanks
Aanand

"Daniel Peterson" wrote in message
...
Hello,

I've read up quite a bit about VPN problems with Vista, but can't seem to
find a solution to my issues. We have VPN setup to our Cisco PIX 515E
(which doesn't support MS-CHAP V2). Of course, since Microsoft was nice
enough to remove MS-CHAP V1 in Vista, this now prevents any of our users
from upgrading to Vista, and I'm trying to find a workaround.

Right now, I've made changes to our PIX to allow authentication over PAP,
CHAP or MSCHAPV1. The PIX has always required 128bit encryption. (This
according to the MS KB article discussing the death of MSCHAP V1, should
work).

In my VPN connection security , I've tried every combination of PAP, CHAP
and the various data encryption options, but can't get beyond the dreaded
"Error 732: Your computer and the remote computer could not agree on PPP
control protocols". I don't see anything interesting in the PIX logs or
in the Windows Vista client event logs.

User authentication is being done by an IAS server that the PIX connects
to just fine. Clients running XP, 2000 and OS X can all VPN in without
any problems at all.

Has ANYONE gotten Vista --- PIX VPN working at all with the Vista VPN
client?


  #5 (permalink)  
Old June 25th 07, 06:21 PM posted to microsoft.public.windows.vista.networking_sharing
Daniel Peterson
external usenet poster
 
Posts: 7
Default Vista can't authenticate on VPN connection

Hello,

Thank you, that's what I was starting to wonder.

Well, that pretty much kills that solution.

THANKS MICROSOFT FOR DEPRECATING MSCHAP V1.

"Aanand Ramachandran" wrote in message
...
Hi Daniel
Both PAP and CHAP do not support encryption. In order to use them you
would have to turn off 128-bit encryption on the server.

thanks
Aanand

"Daniel Peterson" wrote in message
...
Hello,

I've read up quite a bit about VPN problems with Vista, but can't seem to
find a solution to my issues. We have VPN setup to our Cisco PIX 515E
(which doesn't support MS-CHAP V2). Of course, since Microsoft was nice
enough to remove MS-CHAP V1 in Vista, this now prevents any of our users
from upgrading to Vista, and I'm trying to find a workaround.

Right now, I've made changes to our PIX to allow authentication over PAP,
CHAP or MSCHAPV1. The PIX has always required 128bit encryption. (This
according to the MS KB article discussing the death of MSCHAP V1, should
work).

In my VPN connection security , I've tried every combination of PAP, CHAP
and the various data encryption options, but can't get beyond the dreaded
"Error 732: Your computer and the remote computer could not agree on PPP
control protocols". I don't see anything interesting in the PIX logs or
in the Windows Vista client event logs.

User authentication is being done by an IAS server that the PIX connects
to just fine. Clients running XP, 2000 and OS X can all VPN in without
any problems at all.

Has ANYONE gotten Vista --- PIX VPN working at all with the Vista VPN
client?


  #6 (permalink)  
Old March 26th 08, 03:40 PM posted to microsoft.public.windows.vista.networking_sharing
dmaselbas
external usenet poster
 
Posts: 1
Default Vista can't authenticate on VPN connection


I have been able to connect to one of our clients Cisco PIX firewalls
with the Vista VPN client. Im not sure what version they are running but
here is how I made it happen.

After setting up the connection go into Properties

Go to the Options tab and click the PPP Settings button

Make sure all of these check boxes are NOT selected

hit ok.

While on the Options tab make sure that the Include Windows logon
domain check box is NOT selected

Next go to the Security Tab

select the Advanced (custom settings) radio button

Then click the settings button

in the Advanced security settings form select Optional Encryption from
the Data Encryption drop down

select the Allow these protocols radio button and make sure that only
Challenge Handshake Authentication Protocol(CHAP) is selected

hit ok.

Now head over to the Networking tab

on the networking tab select L2TP IPsec VPN from the Type of VPN
dropdown

click the IPsec Settings button

make sure that the Use certificate for authentication radio button is
selected and the check box underneath it is checked

hit ok

Back on the Networking tab I disabled all protocols except for TCP/IPv4
, Im not sure that this is necessary but I didn't want any silly
protocols getting in the way.

after that hit ok and try to connect

Im not sure if all of these changes were necessary but this is the only
way I have been able to get a connection to a PIX firewall from vista.
Maybe next time Microsoft will consider the rest of the industry when
they decide to start dropping protocols (prolly not). I wonder what
kind of firewall Bill uses?!?


--
dmaselbas
 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT. The time now is 03:38 PM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2012, Jelsoft Enterprises Ltd.Search Engine Optimization by vBSEO 3.0.0 RC6
Copyright ©2004-2012 Vista Banter.
The comments are property of their posters.