RRAS trouble with certificate based L2TP on Server 2016

Does IT Really Matter in NY 101 Reputation points
2020-08-06T19:03:33.44+00:00

We have two Server 2008 R2 servers running RRAS supporting L2TP VPN for our employees using an internal CA structure. The computers names don't match the certificate name, but match external DNS, so they haven't given us a problem. We are now in the process of replacing these with Server 2016 boxes. All of these servers have two certificates - one with the actual server name (Client & Server Auth purposes), and one with the external DNS name (Server Auth & IKE intermed). One of the new servers is up and running just fine with certificate L2TP connections. The other one, for some reason, doesn't want to work.

It seems like it want to present the incorrect certificate. When a client (win10 or Win7) tries to connect with certificate L2TP, it gets error 835 (fields cannot be validated). If I delete the cert for the actual server name, the L2TP connection works - until the GPO that auto-enrolls runs again. Doesn't make sense since the other new server doesn't have the problem at all, and all the settings seem identical.

I know I could work around the issue by unselecting the "Verify the Name and Usage of server's certificate" on the client, but I really don't want to do that in general, and don't want to make a change to the VPN client GPO.

Googling around doesn't seem to help too much because most of the articles I'm finding are only about PSK L2TP. I find stuff about setting the certificate in NPS authentication settings, but my understanding is that is only for user authentication, after the machines have already established the L2TP tunnel (or am I wrong). Either way, that is set to the correct certificate.

Windows Server Infrastructure
Windows Server Infrastructure
Windows Server: A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.Infrastructure: A Microsoft solution area focused on providing organizations with a cloud solution that supports their real-world needs and meets evolving regulatory requirements.
526 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Candy Luo 12,686 Reputation points Microsoft Vendor
    2020-08-07T08:23:59.627+00:00

    Hi ,

    >>I know I could work around the issue by unselecting the "Verify the Name and Usage of server's certificate" on the client, but I really don't want to do that in general, and don't want to make a change to the VPN client GPO.

    As you said, you have found the workaround for this issue. Please understand, from Q&A platform support level, it is hard for us to analyze the cause for this issue. We can only provide some general suggestions here. If you want to find the root cause, I suggest you contact Premier support team.

    For more information about our Premier support, please see:

    https://www.microsoft.com/en-us/microsoftservices/support.aspx

    Best Regards,

    Candy

    0 comments No comments