Test Lab doesn't work : PPTP -> Error: 734

S

stephen

Hi,

I have set up 5 fresh windows 2003 boxes and have followed
the labs exactly. However I have run into a show stopper
and hoping that I can get some help.

I am trying to get a test lab up and running to prove and
show the capability of WinXP and Win2003 and associated
products instead of Unix.

I am using the Microsoft article :
http://www.microsoft.com/technet/treeview/default.asp?
url=/technet/prodtechnol/windowsserver2003/deploy/confeat/r
motevpn.asp

So I have problems with the PPTP example especially around
the VPN server and XP client sides of things.

I have followed and used the architecture as the document
suggests and I believe that everything appears to be setup
fine. Therefore, I am currently stopped at the section in
the PPTP under CLIENT1 (the WinXP client).

The Steps I followed:
1.) Followed the instructions to log the XP box onto the
domain and could successfully log on to the domain with
VPNUser and ping the 172.16.0.X boxes and ping their
respective hostname.domain etc..
2.) I then shutdown the XP box.
3.) I then moved the connected the XP box to the Internet
isolated hub and started up the XP box and logged on using
the VPNUser domain account.
2.) I then tested that my ipconfig was 10.0.0.1 and I
couldn't ping any of the 172.16.0.X boxes and I couldn't.
3.) I then successfully tested pinging the VPN1 server box
on the Internet IP of 10.0.0.2 network connection.
4.) I then followed the second part of the CLIENT1 install
guide in setting up a network connection eg. changing the
Network Tab , Type of VPN to PPTP VPN etc..
5.) I then connected to this network connection with the
username of domain\VPNUser and also tried it with
domain/VPNUser (as stated in the doco which seems
different to my normal domain\username format ??).
6.) Then I get the Error 734. It seems to get further then
last time but I couldn't guarentee this. The error comes
up extremely fast.

Therefore, the error dialog that comes up with has the
following title : "Verify username and password"

Error 734: The PPP link control prototcol was terminated.

I looked at the help associated with the error from the
error dialog and it suggests to disable LCP. I did this
and I still get the same error. It also suggests to
switch the security setting for the network connection
to "Allow unsecured password". I didn't have this in my
dropdown list just the default and the smartcard option.
I'm really not sure why one would want to use this setting
anyway ???

I also have searched for Error 734 throughout the
Microsoft sites and found only errors relating to Dialup's
and not VPN's.

Anyway, I tried their documented work around by turning
off (no check box) the negotiate multi link for single
link connections. This didn't have any affect, I am still
getting rh same error as documented in my previous news
item (eg Error 734).

Please help so I can prove how great win2003 and WinXP
are .....

Cheers Steve
 
S

stephen

Hi,

Since my last post I have managed to get the PPTP
working. The problem was that I removed the default
security policy's as I just went with the one and only
described in the book, this was a mistake.

Secondly, I had the IAS routing its radius client to
172.16.0.2 (I think the 172.16.0.3 put me off). Anyway it
should have been 172.16.0.4. So it is up and going and
fast, lovely !!. I can access the iis1\root and web page
for iis server.

Then I struck my next problem, the L2TP piece. As its
really the L2TP that I have to demo (mainly to a business
a Unix crowd) I feel I am so close to overwhelming them.

I end up with an error of: 789 and then 792.

I followed the steps in the L2TP document and everything
seemed to work fine until of course I tried to connect to
the L2TP connection. The steps I followed were:

1.) Into the DC and configured the automatic certificate
for a computer
2.) Then I did the gpudate on both the DC and VPN box. I
didn't do it on the IAS box ?
3.) I then logged the client into the intranet domain
network under the VPNUser. No problems, I could ping all
the 172.16.0.X boxes and resolve their hostname.domain and
I also checked that the certificate was loaded into
Certificates -> Personal -> Certificate and it was. A
certificate with the clienthostname.domain. I opened up
the certicate and reviewed it properties and there seemed
to be no problems.
4.) I then shutdown the CLIENT1 (XP box) and connected the
WinXP box back to the isolated Internet hub connection.
5.) Logged in again under VPNuser. This time the log on
took forever. Two Event Viewer application errors were
then generated. I quickly checked that I could ping the
VPN server (VPN1) at 10.0.0.2 and I could. It was
successful and the CLIENT1 had now taken on the 10.0.0.1
IP address.

The first of these application errors said:

Windows cannot obtain the domain controller name for your
computer network. (The specified domain either does not
exist or could not be contacted) Group Policy process is
aborted.

The second application error message (genertaed approx 1
min afterwards) said:
Automatic certificate enrollment for Local System failed
to contact the active directory. The specified domain
either does not exist or could not be contacted.
Enrollment will not be performed.

I thought both of these were fine as I wasn't connected
onto the intranet yet for the active directory links to be
performed ???

Anyway, then I setup the L2TP connection as it says in the
doco. I tried it with both mulitnode and LCP turned off
and on, rebooting and anything else etc.. etc..

The error I consistenly get is:
Connecting to 10.0.0.2
Error 789 : The L2TP connection failed bacause the
security layer encountered a processing error during
initial negotiations with the remote computer.

Then when it auto redials it gives me the next error:
Error 792:
The L2TP connection attempt failed because security
negotiation timed out.

LASTLY, I thought I would try the good ol PPTP connection
to see if it was still working and it was. The PPTP
connection was successful adn I could still access the web
site and c:\ on the iis1 box.

Please help me get this demo up and running, I'm so close.

Cheers
Steve
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top