Win 7 Pro 64 occasionally fails to connect using IKEV2 to Win2008R2 Routing and Remote Access server

I'm a networking guy and having this troubling VPM issue that I can't find.
I have a number of VPN connections from my Win7Pro 64 PC to various customers.  Their end points are all Windows Routing and Remote Access on Windows 2008R2 STD servers.
Every once and a while I will hang at Verifying User ID and Password and eventually get  ERROR 809. Change the security type on my VPN connection from IKEV2 to PPTP - never an issue, connects in right away.
I can also try from another PC (at the same or alternate location) to get into that same server using the same credentials and access - no issue using either IKEV2 or PPTP.
This has happened at various times to various customers. Here is what I know it is not:
- Not the local or remote routers or Firewalls since I can always get in from other PC's going through the same network. Even so, tried rebooting all several times
- Not an ISP issue at either end since I can always get into other IKEV2 servers from the same PC and from other PC's to the server I can't from my PC.
This leads to the only logical conclusion.  It is something to do with my Win7Pro 64 PC but for the life of my I can not find it.
I have obviously tried rebooting the Win7Pro PC. I have also tried recreating the VPN connection several times. Nothing.
Help!

Hi,
I know that you've mentioned that it is not a issue about firewall or router settings, but this error usually comes when some firewall between client and server is blocking the ports used by VPN tunnel.
so to allow IKEv2 traffic, please make sure to configure the network firewall to open UDP ports 500 and 4500, and to allow IP protocol 50.
If that is not possible, deploy SSTP based VPN tunnel on both VPN server and VPN client – that allows VPN connection across firewalls, web proxies and NAT
You can refer to this blog
http://blogs.technet.com/b/rrasblog/archive/2006/06/14/which-ports-to-unblock-for-vpn-traffic-to-pass-through.aspx
Regards
Yolanda
TechNet Community Support

Similar Messages

  • Routing And Remote Access Service: Error 1068: The dependency service or group failed to start

    Hi,
    I tried to establish a PPP connection between my windows 8.1 PC and another kind of machine using an USB cable. So, as usual on Windows XP and Windows 7,
    I configured the COM in the modem list and I tried to start the
    "Routing And Remote Access" service and then
    I got this message.
    So any idea why is failing?
    Please help!
    Thanks thaks thanks

    Hi,
    Was your issue resolved?
    If no, please reply and tell us the current situation in order to provide further help.
    Karen Hu
    TechNet Community Support

  • Routing and Remote Access fails to install

    Hello, I recently installed Windows Server 2008 beta 3 onto my new computer, which went smothly. I have ADDS, DHCP, DNS, IIS, Terminal Services, and Network Policy and Access Service installed and they all work perfectly. However, I recently tried to install Routing and Remote Access, but I got the following error message when I finished the configuration wizard: "Installation of the Routing and Remote Access Service failed because: Class not registered (80040154). Whats causing this, and how do I fix this?

    I also have this trouble of an error when installing Routing and Remote Access "class not registered..."
    It is a Windows Server 2008 RTM clean install.
    Added machine to our Windows 2003 domain and then after reboot added Windows Powershell.
    Logged in as domain admin and then when tried to add routing and remote access got the message described by everyone else.
    Like others I need to know how to get over this problem.

  • Macbook pro occasionally fails to connect to the internet

    Hi...  A few months ago I bought a new 15 inch Retina display MacBook Pro.  it's the third macbook pro I've owned but the first with the following problem.  About 5% of the time, when I boot the computer it fails to connect to my home network.  While this is happening I will click on Network Diagnostics.  I will, one at a time, walk through the following screens of that diagnostic tool..
    Select Location...  Always shows my Location so I click Continue
    Choose network port configuration...  That always shows the correct Wi-Fi radio button selected so I again click Continue
    Select Wi-Fi Network...  It always shows my home network so again I just click Continue
    Then comes the interesting part.  The next screen that comes up is the one where you choose between DHCP or PPPoE.  The moment that screen comes up, first DHCP is already selected which is correct.  But more importantly the moment that screen comes up, the network connects and a new window opens up that says,
    Network Change Detected.
    Your network configuration has changed.  Click OK to proceed to the next step
    What could be wrong that prompts the system to fail to connect once in a while even though it seems to only need me to click through the Network Diagnostic without actually doing anything and when I get to this DHCP screen, boom it connects by itself???
    Any ideas of what's going on???
    thanks... bob...

    1. Power off the router. Unplug it from the wall. Wait a while.
        Plug it back to the wall. Power the router on. Wait until all the lights are lit properly. It will take a while.
        Restart the computer.
        Start up in Safe Mode.
        http://support.apple.com/kb/PH14204
    2. Deselect Proxies if selected.
        System Preference > Network > Advanced  > Proxies Tab
        Under "Select Protocol", uncheck any box if selected.
        Click "OK" then  "Apply”.

  • Anyconnect Failed to Connect using WEBVPN on IOS Router 2800 Series

    Hi All,
    Kindly need your help. I was trying to built Remote Access VPN connection on my lab environment. The component is Router 2811 with (c2800nm-advsecurityk9-mz.124-22.T5.bin), Anyconnect Client ( anyconnect-win-3.1.05160-k9.pkg ), Laptop ( Firewall and Antivirus disabled, already register webvpndomain.com into hosts file on Win32/Driver/Etc ).
    I was able to connect using anyconnect if I'm initiate connection via web (https://webvpndomain.com) and start tunnel connection SVC. I'm also able to reach my LAN and I get my private IP Address assigned by my vpn pool on the router. The problem is when I'm initiate connection to vpn directly from the computer, I mean I'm not using web (https://webvpndomain.com) and I'm just press "connect" on my anyconnect software that already installed on my Laptop the connection always fail. I get error message : Connection attempt has failed
    Here I'm also attach my router configuration, so you can see what I've done or what mistake that I've made on the configuration.
    Is anybody in here have experience this problem on deploying Remote Access VPN using webvpn and anyconnect as vpn client ?
    I'm really appreciate anybody that get into this discussion
    Best Regards,
    Nanda

    Try using webvpndomain.com/myVPNGW as host

  • Can implement port forwarding using win2003 routing and remote acccess?

    I have a sql server 2005 with a  internet ip address b and a computer onwindows 2003 with a internet ip address a .
    Now I want to use address "a" 's 14330 port to access sql server 2005 on ip address "b" with port 1433.
    I use router and remote access to implement this,but fail.
    in every server only have a adaptor and a ip.
    How to do it?
    Please tell me how to implement it from "routing and remote access" in detail.
    I dont want use netsh.

    Hi,
    I think this will not work. As we know, when a source computer send a request to SQL server, the packet should contain the following information.
    Source IP and port number (this port is a randomly generated)
    Destination IP and port 1433 (SQL by default)
    So we cannot control which port to use when connecting another service.
    Hope this helps.

  • NTLM authentication fails to connect using webdav on osX

    We are having problems in our organization getting our macs connected via webdav using NTLM authentication.
    Our structure is as follows:
    Netapp/IBM nSeries gateway/filer model n6040 which is our FTP/CIFS/Webdav host.
    Windows Server 2008 R2 Domain Controller with Active Directory
    Windows 7, Mac osX clients (various versions).
    From the windows side, we are able to connect to our filer via FTP, CIFS, and http/Webdav after we authenticate using our AD credentials.  From the Mac side, we can authenticate and connect to our filer using FTP, CIFS (using Connect to Server "smb://ourfiler.com") and through a browser using the address of http://ourfiler.com.  This type of connection using webdav works with Firefox but not using Safari or Chrome but isn't adequate enough for our users since the browser based connection is read only.  However, when we try to Connect to Server via webdav using our server address of http://ourfiler.com:80, we never get past the "Enter your name and password for the server "ourfiler.com." 
    We tried a third party webdav client on our macs: Cyberduck, which also fails to connect using webdav.   We also tried a separate linux client and were able to connect without any problems.
    Since authetication for webdav works on windows and linux, we're thinking there is problem with osX itself.  Has anyone else had this problem or can anyone suggest any workarounds/solutions?

    Sorry for the late replies gentleman... for some reason I didn't get email alerts when you guys posted....
    Anyways, yes the DC is on a different subnet and no we don't have WINS.  The way I understand it is the client will contact the master browser in it's local subnet... all the master browsers in all other subnets contacts the Domain master browser ...
    and they share the server list this way... I mean it's a little more complicated than that....well to me at least...
    Can you try resolving the short name with the domain controller being on another subnet and you having a different master browser in your client subnet?
    What is the process the client goes thru when looking up Domain netbios name?  LIke for DNS, it's straight forward... the client looks at DNS server, then for the SRV records for the Site the client is in and get's domain controller.......   How
    does this work for netbios domain name?  There is NO WINS in the environment.
    Chau

  • Why does my Iphone 4s connect to my Wi-Fi network and latter in the day fail to connect until I reboot the router

    Why does my Iphone 4s connect to my wi-fi with a password and latter in the day fail to connect until I reboot the router?  Is there a setting on my router that would avoid this issue.  All my other devices connect alright

    OK so it now looks like on my iPhone 5 iwth iOS 6.1 the LTE network is conflicting with my home wifi (Airport Extreme). At the Apple store the LTE signal is lost in and wifi works like a charm. At home tired all of the "fixes"
    -No security
    -WEP
    -Reset network,
    -Complete reset and reload on the phone
    -ETC ETC ETC
    Just turned off the cell radio and it worked. Turned on the cell radio but kept LTE off and it worked.
    Apple let's get a fix so we can use your "great" phone. I have just received a BB Z10 from work and it seems to work flawlessly.

  • My Time machine won't back up.  Recently updated to OS x 10.7.5.  Error message is as follows:  "The backup disk image "/Volumes/Time Machine Backup/Scott's MacBook Pro.sparsebundle" is already in use."  What is wrong and how do I fix it?  Thanks.

    My Time machine won't back up.  Recently updated to OS x 10.7.5.  Error message is as follows:  "The backup disk image “/Volumes/Time Machine Backup/Scott’s MacBook Pro.sparsebundle” is already in use."  What is wrong and how do I fix it?  Thanks.

    Have you tried restarting the computer? Also, see Time Machine Error from this pages sidebar under More Like This.

  • I've recently received an error message from Time Machine that my Macbook Pro's sparsebundle is in use.  What is this and what can I do about it?

    I've recently received an error message from Time Machine that my Macbook Pro's sparsebundle is in use.  What is this and what can I do about it?

    This is asked at least 5-6 times a day here.
    Look at the right hand column.. more like this.
    It is a bug in Mountain Lion.
    Read C12 http://pondini.org/TM/Troubleshooting.html
    But the fast solution.. unplug the TC.. count to 10.. plug it back in.

  • I have final cut pro x-i have been using the share button previously and had no problem.as of today i share a movie to 720hd, and after a white it says share successful but i cannot find where the movie has been saved???need help

    i have final cut pro x-i have been using the share button previously and had no problem.as of today i share a movie to 720hd, and after a while it says share successful but i cannot find where the movie has been saved???need help--i cannot find the destination. can this be changed.it used to go to itunes, home video.thanks, dimitrios

    EExactly what settings are you using. Some go to iTunes.

  • I have been using WRT54G wireless broadband router and WU...

    I have been using WRT54G wireless broadband router and WUSB54G on my home PC for the last 2 years. It was working fine until recently I encountered serious connection problem.
    The WUSB54G cannot connect with WRT54G.
    Error message " Cannot assocaite with the access point.
    I have checked the followings to try and solve the problem.
    1) Refresh site survey the WUSB54G does not show my SSID, but it can show my neighbour'sSSID.
    3) When I use my notebook with built-in wireless network adaptor to access wirelss broadband there is no problem at all. I can access my SSID.
    4) I have try reseting the WRT54G and changing password but still can not solve the problem.
    5) Uninstall and re-install
    5) I have installed a new USB adapter (WUSB54GG) thinking that it could be the old WUSB54G is faulty. But still encounter same problem.
    I am using Window XP Professional. What could be the problem?
    Please provide your professional advice. Thank you.

    Hi, Try to update firmware of router. You can get latest version from www.linksys.com/download, Hope it will help you

  • Using AX with Linsys router and WEP security

    I have a Dell Inspiron 700m running XP. I use a Linksys wireless router for internet access. I have configured my AX to connect to the router and, with the WEP security turned off, it worked fine. However, when I turned WEP back on, reset the AX, and tried to configure it as a client to my wireless network, it didn't work. Rather, I could not connect to my wireless network, and can only connect directly to the AX network. Any suggestions?
    Thanks,
    Tom
    Dell Inspiron 700m   Windows XP  

    One of the problems with WEP is that the actual standard relies on a 10 character HEX key for 40bit WEP and a 26 character HEX key for 128bit WEP.
    In order to make things easier for people, vendors use certain algorithms to convert simple alphanumeric passwords (or passphrases) into HEX keys, thus enabling people to use simple memorable WEP password rather than lengthy HEX keys.
    The problem is that different vendors use different algorithms to generate the HEX key and therefore a ASCII password on an AEBS will be hashed differently on a Netgear client and vice versa.
    One thing is a 13 character 128 bit WEP password will be hashed by all vendors in the same way (if you use 40bit WEP then a 5 character password is required).
    Having said that, this will only work if they use an algorithm, some don't and in these cases you must use the HEX key regardless of the length of the plain text password.
    AirPort: Joining an encrypted wireless network
    http://docs.info.apple.com/article.html?artnum=106424
    Choosing a password for networks that use Wired Equivalent Privacy (WEP)
    http://docs.info.apple.com/article.html?artnum=108058
    iFelix

  • Wireless connection between D-Link WiFi router and Time capsule stopped working

    We have an ISP provided D-Link wireless router (DIR-615) to which we wirelessly connected our 2Tb Time Capsule for back up and to connect a USB printer to out network. This worked perfectly for 3 1/2 years, until about a month ago, when the time capsule suddenly decided to go "off line". ie we could no longer access it or the printer via our wireless network. We had changed nothing - just one day it stopped working.
    We tried to get it back online with no success. As the 2Tb Time Capsule was almost 7 years old and had had some HDD issues in the passed, we figured it had got old and died and that it was time to replace it; so we bought a new 3Tb Time Capsule, thinking this would get everything back to normal.
    However much as we tried, we were also unable to get the new 3Tb Time Capsule to connect wirelessly to the D-Link wireless router. The Airport Utility did not show the D-Link wireless router or its wireless network, although we were (and are) able to see it in Systems Preferences>Networks from all our multiple devises. This in itself seemed odd. No matter what we tried, the Airport Utility would not find the D-Link wireless router and hence we could not add the 3Tb Time Capsule to the existing wireless network.
    At the end of the day we got fed up with trying to add the 3Tb Time Capsule to the D-Link wireless network, and connected it via a LAN cable to the D-Link router instead. We then set it up as its own network. Worked gerat. Having done that we thought maybe the old 2Tb Time Capsule might not have been the problem after all, so we tried extending our new 3Tb Time Capsule wireless network using the 2Tb Time Capsule wirelessly. This worked perfectly! And we are now almost back to what we wanted.
    So although we have a work around, this means now have 2 separate wireless networks as opposed to the original single wireless network where everything talked to everything else.
    Can anyone shed any light on any of the following:-
    1. Why the original wireless network connection between the D-Link router and the 2Tb Time Capsule just stopped working? Was there some software change from Apple that "decided" D-Link wireless routers were no longer secure; and therefore the TCs could no longer connect to them?
    2. Why it was not possible to extend the existing D-Link wireless network using the the new 3Tb Time Capsule?
    3. Is there is anyway that we can get back to a single wireless network based around the D-Link wireless router as the primary router connecting to the modem, where the 2 Time Capsules connect as "wireless satellite base stations"?

    1. Why the original wireless network connection between the D-Link router and the 2Tb Time Capsule just stopped working? Was there some software change from Apple that "decided" D-Link wireless routers were no longer secure; and therefore the TCs could no longer connect to them?
    A firmware update to the TC came along and you agreed to it without perhaps even noticing.. it then smashed your setup because Apple do not recommend the setup you were using and it is very poor.
    2. Why it was not possible to extend the existing D-Link wireless network using the the new 3Tb Time Capsule?
    Because it is such a poor setup that Apple have taken away your ability to choose it unless you know exactly what you are doing.
    3. Is there is anyway that we can get back to a single wireless network based around the D-Link wireless router as the primary router connecting to the modem, where the 2 Time Capsules connect as "wireless satellite base stations"?
    Yes, this I can help you with.
    I have several ways around the problem.. but the first one is.. why use the DIR-615 at all.. it is not a modem.. it is a very ordinary bottom end, poor single band slow wireless router.
    Why don't you simply remove the DIR-615 from the network completely.. plug whatever it is the ISP supplies you.. an ethernet connection from whatever that modem is you mentioned into the WAN port of the Time Capsule. And use the TC in some router mode.. same as the DIR-615 was setup.. dhcp or pppoe or whatever.. I doubt the TC cannot match it.
    If you have issues please post a few screenshots from the DIR-615 to show how it is setup from the WAN side.. and as long as you are given the username and password or whatever the ISP uses to authenticate then chuck out the DIR-615.
    Tell me if that is a goer.. if not we can work out a few other methods..
    eg. Simply turn off the wireless in the DIR-615. It is poor cf the TC and there is no need for it.. with the TC in bridge only use the TC for wireless as well as wireless extend with your old TC.
    Or setup roaming network where everything uses the same SSID.
    Then you will have one wireless network. And it won't matter what as long as it connects.. although IMHO this is not right as the TC is such a superior router now you are wasting your new TC.

  • I'd like to use Time Capsule as Router and remove D-Link Router.  Is that what it's designed for?

    I currently use a D-Link Router and also have a 1st generation time capsule as use as a back up device.  I've just purchased a new 2TB Time Capsule and would like to use it as my primary "only" router just after my cable modem, it that there primary design?
    Currently I have a Cable modem with a Static IP address and then on the D-Link I've configured my NAS, Power Mac, iMac and Computers with all there own IP address.  I've looked on the Time Capsule I have hooked up now and I'm not sure if the TC will let me do that.
    I really should of researched before, but I'd just bought a mini mac with lion server and it talked about the ease of using TC with it and purchased before researching...

    I've just purchased a new 2TB Time Capsule and would like to use it as my primary "only" router just after my cable modem, it that there primary design?
    Yes, the Time Capsule is designed to connect directly to a modem.
    on the D-Link I've configured my NAS, Power Mac, iMac and Computers with all there own IP address
    You can set up "static" IP addresses for each of your network devices....IF....the Time Capsule is set up to be the "main"' router on the network.
    Open AirPort Utility and click Manual Setup
    Click the Internet icon
    Click the DHCP tab below the icons
    The DHCP Reservations box will allow to you assign a specific IP address based on the MAC address or AirPort ID of each device.
    Devices could be assigned IP addresses in the 10.0.1.x range or 192.168.1.x range depending on your preference.

Maybe you are looking for

  • What is the difference between wi-fi and wi-fi cellular in purchasing an i-pad?

    I am confused about the difference, and want to make a purchase, but don't know if I actually need the cellular or 3G, or what they would be for on an i-pad.  Thanks.

  • MTOM Base64 Decoding

    Hello Experts I am doing a SOAP -> REST scenario (PI 7.31), where I am receiving base64 encoded node "-<ns2:content><xop:Include xmlns:xop="http://www.w3.org/2004/08/xop/include" href="cid:[email protected]"/> Need pointers on removing this node or d

  • Trully need help folks......

    import java.awt.*; import java.awt.event.*; import javax.swing.*; class VideoStoreMainFrame extends JFrame      private JButton managerButton, cashierButton, customerButton;      private JLabel note;      public VideoStoreMainFrame()           super(

  • Installing IAS on a P$

    I'm trying to IAS on a Pentium 4 with Windows 2000?. I know that iPlanet does not support W2K but we have it running on P3s now in W2K when we ignore the warning. The only difference is the chip. On the P4 the server will not load and I get the follo

  • BPMon alert reporting not showing any data for Trend Analysis

    Hi, I have setup BPMon and performed the initial setup for BW reporting. There are alerts being generated by the BPMon setup and the data has been transferred to the 0SM_BPM cube. But when I start the Trend Analysis report I dont get any Solution for