How to fix IKE VPN connection problem on some machines

james bennett 51 Reputation points
2023-05-06T17:35:59.7+00:00

Hello,

I have a few Windows 10 devices that are unable to connect to the AlwaysOn VPN User tunnel.

The User VPN tunnel uses a User certificate and PEAP and works for the majority of Windows machines.

The always on VPN infrastructure uses Windows RAS for VPN termination, Windows NPS for RADIUS User VPN authentication. The VPN URL that the clients connect to goes through an Azure Load balancer, Fortigate firewall before hitting the RAS machine.

The client gets the following error

User's image

As a test, by editing the the clients host file so that it uses the Always on VPN device tunnel to bypass the load balancer and firewall, the user tunnel connects happily - so I'm assuming that the error is somewhere on either the load balancer or firewall, but I just can't figure it out.

The error on the NPS box at failed connection time is

Windows Server Infrastructure
Windows Server Infrastructure
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Infrastructure: A Microsoft solution area focused on providing organizations with a cloud solution that supports their real-world needs and meets evolving regulatory requirements.
544 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Limitless Technology 44,321 Reputation points
    2023-05-09T12:18:45.6666667+00:00

    Hello there,

    Can you share any error message or event ID that you have noticed?

    If your Always On VPN setup is failing to connect clients to your internal network, the cause is likely an invalid VPN certificate, incorrect NPS policies, or issues with the client deployment scripts or in Routing and Remote Access.

    https://video2.skills-academy.com/en-us/troubleshoot/windows-server/networking/troubleshoot-remote-access-vpn-and-aovpn-guidance

    The listed resources in this article can help you resolve issues that you experience when you use Remote Access.

    https://video2.skills-academy.com/en-us/windows-server/remote/remote-access/vpn/always-on-vpn/deploy/always-on-vpn-deploy-troubleshooting

    Hope this resolves your Query !!

    --If the reply is helpful, please Upvote and Accept it as an answer--

    0 comments No comments

  2. Limitless Technology 44,321 Reputation points
    2023-05-09T13:07:11.6266667+00:00

    Hello there,

    After machine reboots, before NIC adapter initializes, NLASVC would attempt detection of domain, if the detection was failed, then this information will be cached and even though NIC gets initialized, the machine still apply the cached information and hence machine detects unidentified network.

    Please try to modify the following registry keys to see if the issue can be resolved:

    First, disable Domain Discovery negative cache by adding the NegativeCachePeriod registry key to following subkey:

    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NetLogon\Parameters

    Name: NegativeCachePeriod

    Type: REG_DWORD

    Value Data: 0 (default value: 45 seconds; set to 0 to disable caching)

    Similar discussion here https://video2.skills-academy.com/en-us/answers/questions/400385/network-location-awareness-not-detecting-domain-ne

    Hope this resolves your Query !!

    --If the reply is helpful, please Upvote and Accept it as an answer--

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.