CMAK VPN & "Log on using dial-up connection" failing

G

Guest

I have set up a Win2003 RRAS L2TP IPSec vpn for XP Pro SP2 clients connecting
from remote cable internet connections. All remote PCs are members of the
domain. The VPN client connection is built with CMAK.

Users with cached credentials can successfully log onto the local machine
and establish the VPN connection to the server. However, the "Log on using
dial-up connection" option at the Windows Logon screen fails with a 691
access denied error.

Reviewing the IASSAM.LOG shows a failed attempt by the guest account to log
in corresponding to the failed remote connection attempt (see below). If I
manually create the VPN connection (rather than use CMAK), the dial-up
connection at Windows logon works.

Does anyone have an idea where I need to look in CMAK to correct the
problem...? Thanks!

[1796] 09-20 09:15:32:634: NT-SAM Names handler using default user identity
IT_DOMAIN\noguest03.
[1796] 09-20 09:15:32:634: identity is "IT_DOMAIN\noguest03"
[1796] 09-20 09:15:32:634: Username is already an NT4 account name.
[1796] 09-20 09:15:32:634: SAM-Account-Name is "IT_DOMAIN\noguest03".
[1796] 09-20 09:15:32:634: NT-SAM Authentication handler received request
for IT_DOMAIN\noguest03.
[1796] 09-20 09:15:32:634: Processing MS-CHAP v2 authentication.
[1796] 09-20 09:15:32:634: LogonUser failed: Logon failure: unknown user
name or bad password.
[1796] 09-20 09:15:41:696: NT-SAM Names handler using default user identity
IT_DOMAIN\noguest03.
[1796] 09-20 09:15:41:696: identity is "IT_DOMAIN\noguest03"
[1796] 09-20 09:15:41:696: Username is already an NT4 account name.
[1796] 09-20 09:15:41:696: SAM-Account-Name is "IT_DOMAIN\noguest03".
[1796] 09-20 09:15:41:696: NT-SAM Authentication handler received request
for IT_DOMAIN\noguest03.
[1796] 09-20 09:15:41:696: Processing MS-CHAP v2 authentication.
[1796] 09-20 09:15:41:696: LogonUser failed: Logon failure: unknown user
name or bad password.
 
R

Robert L [MS-MVP]

If you want to use Log on using dial-up connection, you don't need the CMAK. You just create regular VPN connection.

Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
I have set up a Win2003 RRAS L2TP IPSec vpn for XP Pro SP2 clients connecting
from remote cable internet connections. All remote PCs are members of the
domain. The VPN client connection is built with CMAK.

Users with cached credentials can successfully log onto the local machine
and establish the VPN connection to the server. However, the "Log on using
dial-up connection" option at the Windows Logon screen fails with a 691
access denied error.

Reviewing the IASSAM.LOG shows a failed attempt by the guest account to log
in corresponding to the failed remote connection attempt (see below). If I
manually create the VPN connection (rather than use CMAK), the dial-up
connection at Windows logon works.

Does anyone have an idea where I need to look in CMAK to correct the
problem...? Thanks!

[1796] 09-20 09:15:32:634: NT-SAM Names handler using default user identity
IT_DOMAIN\noguest03.
[1796] 09-20 09:15:32:634: identity is "IT_DOMAIN\noguest03"
[1796] 09-20 09:15:32:634: Username is already an NT4 account name.
[1796] 09-20 09:15:32:634: SAM-Account-Name is "IT_DOMAIN\noguest03".
[1796] 09-20 09:15:32:634: NT-SAM Authentication handler received request
for IT_DOMAIN\noguest03.
[1796] 09-20 09:15:32:634: Processing MS-CHAP v2 authentication.
[1796] 09-20 09:15:32:634: LogonUser failed: Logon failure: unknown user
name or bad password.
[1796] 09-20 09:15:41:696: NT-SAM Names handler using default user identity
IT_DOMAIN\noguest03.
[1796] 09-20 09:15:41:696: identity is "IT_DOMAIN\noguest03"
[1796] 09-20 09:15:41:696: Username is already an NT4 account name.
[1796] 09-20 09:15:41:696: SAM-Account-Name is "IT_DOMAIN\noguest03".
[1796] 09-20 09:15:41:696: NT-SAM Authentication handler received request
for IT_DOMAIN\noguest03.
[1796] 09-20 09:15:41:696: Processing MS-CHAP v2 authentication.
[1796] 09-20 09:15:41:696: LogonUser failed: Logon failure: unknown user
name or bad password.
 
G

Guest

Thanks, Robert. That is my work around, but to simplify deployment and
administration, I was hoping to use the simple self-installing .exe that CMAK
creates...
 
R

Robert L [MS-MVP]

Yes, the CMAk will be easy for the administrator. Normally, we don't recommend our clients to logon domain. We just logon local computer and run CMAK.

Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
Thanks, Robert. That is my work around, but to simplify deployment and
administration, I was hoping to use the simple self-installing .exe that CMAK
creates...

Robert L said:
If you want to use Log on using dial-up connection, you don't need the CMAK. You just create regular VPN connection.

Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
I have set up a Win2003 RRAS L2TP IPSec vpn for XP Pro SP2 clients connecting
from remote cable internet connections. All remote PCs are members of the
domain. The VPN client connection is built with CMAK.

Users with cached credentials can successfully log onto the local machine
and establish the VPN connection to the server. However, the "Log on using
dial-up connection" option at the Windows Logon screen fails with a 691
access denied error.

Reviewing the IASSAM.LOG shows a failed attempt by the guest account to log
in corresponding to the failed remote connection attempt (see below). If I
manually create the VPN connection (rather than use CMAK), the dial-up
connection at Windows logon works.

Does anyone have an idea where I need to look in CMAK to correct the
problem...? Thanks!

[1796] 09-20 09:15:32:634: NT-SAM Names handler using default user identity
IT_DOMAIN\noguest03.
[1796] 09-20 09:15:32:634: identity is "IT_DOMAIN\noguest03"
[1796] 09-20 09:15:32:634: Username is already an NT4 account name.
[1796] 09-20 09:15:32:634: SAM-Account-Name is "IT_DOMAIN\noguest03".
[1796] 09-20 09:15:32:634: NT-SAM Authentication handler received request
for IT_DOMAIN\noguest03.
[1796] 09-20 09:15:32:634: Processing MS-CHAP v2 authentication.
[1796] 09-20 09:15:32:634: LogonUser failed: Logon failure: unknown user
name or bad password.
[1796] 09-20 09:15:41:696: NT-SAM Names handler using default user identity
IT_DOMAIN\noguest03.
[1796] 09-20 09:15:41:696: identity is "IT_DOMAIN\noguest03"
[1796] 09-20 09:15:41:696: Username is already an NT4 account name.
[1796] 09-20 09:15:41:696: SAM-Account-Name is "IT_DOMAIN\noguest03".
[1796] 09-20 09:15:41:696: NT-SAM Authentication handler received request
for IT_DOMAIN\noguest03.
[1796] 09-20 09:15:41:696: Processing MS-CHAP v2 authentication.
[1796] 09-20 09:15:41:696: LogonUser failed: Logon failure: unknown user
name or bad password
 
G

Guest

Unfortunately, we have remote domain users (accessing domain shares, client
server apps, etc.) who have not logged on to the remote machines before.
Their local accounts won't be able to access the domain resources and since
they haven't logged on to the computers with their domain accounts before,
they don't have cached credentials and, therefore, can't get to the CMAK VPN
client...

Robert L said:
Yes, the CMAk will be easy for the administrator. Normally, we don't recommend our clients to logon domain. We just logon local computer and run CMAK.

Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
Thanks, Robert. That is my work around, but to simplify deployment and
administration, I was hoping to use the simple self-installing .exe that CMAK
creates...

Robert L said:
If you want to use Log on using dial-up connection, you don't need the CMAK. You just create regular VPN connection.

Bob Lin, MS-MVP, MCSE & CNE
Networking, Internet, Routing, VPN Troubleshooting on http://www.ChicagoTech.net
How to Setup Windows, Network, VPN & Remote Access on http://www.HowToNetworking.com
I have set up a Win2003 RRAS L2TP IPSec vpn for XP Pro SP2 clients connecting
from remote cable internet connections. All remote PCs are members of the
domain. The VPN client connection is built with CMAK.

Users with cached credentials can successfully log onto the local machine
and establish the VPN connection to the server. However, the "Log on using
dial-up connection" option at the Windows Logon screen fails with a 691
access denied error.

Reviewing the IASSAM.LOG shows a failed attempt by the guest account to log
in corresponding to the failed remote connection attempt (see below). If I
manually create the VPN connection (rather than use CMAK), the dial-up
connection at Windows logon works.

Does anyone have an idea where I need to look in CMAK to correct the
problem...? Thanks!

[1796] 09-20 09:15:32:634: NT-SAM Names handler using default user identity
IT_DOMAIN\noguest03.
[1796] 09-20 09:15:32:634: identity is "IT_DOMAIN\noguest03"
[1796] 09-20 09:15:32:634: Username is already an NT4 account name.
[1796] 09-20 09:15:32:634: SAM-Account-Name is "IT_DOMAIN\noguest03".
[1796] 09-20 09:15:32:634: NT-SAM Authentication handler received request
for IT_DOMAIN\noguest03.
[1796] 09-20 09:15:32:634: Processing MS-CHAP v2 authentication.
[1796] 09-20 09:15:32:634: LogonUser failed: Logon failure: unknown user
name or bad password.
[1796] 09-20 09:15:41:696: NT-SAM Names handler using default user identity
IT_DOMAIN\noguest03.
[1796] 09-20 09:15:41:696: identity is "IT_DOMAIN\noguest03"
[1796] 09-20 09:15:41:696: Username is already an NT4 account name.
[1796] 09-20 09:15:41:696: SAM-Account-Name is "IT_DOMAIN\noguest03".
[1796] 09-20 09:15:41:696: NT-SAM Authentication handler received request
for IT_DOMAIN\noguest03.
[1796] 09-20 09:15:41:696: Processing MS-CHAP v2 authentication.
[1796] 09-20 09:15:41:696: LogonUser failed: Logon failure: unknown user
name or bad password
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top