<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Troubleshooting Vista VPN problems</title><link>http://blogs.technet.com/rrasblog/archive/2007/04/08/troubleshooting-vista-vpn-problems.aspx</link><description>Hello all. There have been quite a few questions/posts on the technet forums about issues you folks have seen with Windows Vista VPN clients. So we thought we would come up with a post on the common configuration issues and some troubleshooting tips.</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: Troubleshooting Vista VPN problems</title><link>http://blogs.technet.com/rrasblog/archive/2007/04/08/troubleshooting-vista-vpn-problems.aspx#744274</link><pubDate>Tue, 10 Apr 2007 16:01:41 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:744274</guid><dc:creator>Nóri</dc:creator><description>&lt;p&gt;I've been running Vista on my two work machines since RTM. My work requires me to VPN to my customers. I see that the VPN client in Vista now puts the DNS address of the VPN connection as the preferred one.&lt;/p&gt;
&lt;p&gt;That's fine for our own VPN connection but this creates problems when connecting to customers. Since the DNS now queries their DNS server I get locked out of network drives mapped to DFS shares, Outlook starts prompting me for a password (RPC over HTTP) etc.&lt;/p&gt;
&lt;p&gt;This probably happens because we're utilizing split DNS and use the same internal and external domain name.&lt;/p&gt;
&lt;p&gt;But I've not been able to find a way to revert this behaviour to the way XP worked.&lt;/p&gt;
</description></item><item><title>re: Troubleshooting Vista VPN problems</title><link>http://blogs.technet.com/rrasblog/archive/2007/04/08/troubleshooting-vista-vpn-problems.aspx#748693</link><pubDate>Wed, 11 Apr 2007 12:03:59 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:748693</guid><dc:creator>rrasblog</dc:creator><description>&lt;p&gt;When you are connected over VPN, the DNS address of the VPN is preferred one. But if name resolution fails with this DNS server, then the DNS server of the next available network adapter should be tried. &lt;/p&gt;
&lt;p&gt;Have you enabled Split tunneling on the VPN connection to customer? If not, then you wont be able to access your network drives when connected to the customer. &lt;/p&gt;
&lt;p&gt;Also, can you please elaborate on the below statement?&lt;/p&gt;
&lt;p&gt;&amp;gt;&amp;gt;This probably happens because we're utilizing split DNS &amp;gt;&amp;gt;and use the same internal and external domain name.&lt;/p&gt;
&lt;p&gt;-Deepti&lt;/p&gt;
</description></item><item><title>re: Troubleshooting Vista VPN problems</title><link>http://blogs.technet.com/rrasblog/archive/2007/04/08/troubleshooting-vista-vpn-problems.aspx#749142</link><pubDate>Wed, 11 Apr 2007 14:23:28 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:749142</guid><dc:creator>Yuguang</dc:creator><description>&lt;p&gt;I found a very very strange thing in vista.&lt;/p&gt;
&lt;p&gt;Everyone can Replicate the problem in his vista machine.&lt;/p&gt;
&lt;p&gt;1, repare a clean vista, and add two vista firewall rules which says ALLOW ALL PROTOCOL ALL IP IN and OUT&lt;/p&gt;
&lt;p&gt;2, start the RemoteAccess service or create a incomming connection, add a user&lt;/p&gt;
&lt;p&gt;3, create a pptp connection and set the server ip to 127.0.0.1&lt;/p&gt;
&lt;p&gt;4, dial the pptp connection&lt;/p&gt;
&lt;p&gt;5, the dial dialog is hang on the &amp;quot;verify the username and passwd&amp;quot;, and at the end, you will get a 628 error.&lt;/p&gt;
&lt;p&gt;6, if dail through calling RasDial, you will get a 806 error.&lt;/p&gt;
&lt;p&gt;7, if vista firewall is disabled, everything works fine.&lt;/p&gt;
&lt;p&gt;BTW: I do same thing in win2k, winxp,win2k3, everything works fine, in these platform, I can establish a pptp connection to self (127.0.0.1), but in vista, I can't if the vista firewall is enabled (even ALLOW all traffic).&lt;/p&gt;
&lt;p&gt;I also used the pptpsrv.exe and pptpclnt.exe to test 127.0.0.1 to 127.0.0.1. The result is:&lt;/p&gt;
&lt;p&gt;1, Run pptpsrv.exe and then run pptpclnt.exe, everything works fine.&lt;/p&gt;
&lt;p&gt;2, Run pptpsrv.exe and then dial pptp connection to 127.0.0.1, the pptpsrv.exe can't receive any GRE packet.&lt;/p&gt;
&lt;p&gt;So, it seems that the vista's pptp client can't send any GRE packet to 127.0.0.1 if the vista firewall enabled. But in the same Env. the pptpclnt.exe can send (through socket(raw,GRE_PROTOCOL) and sendto(...)) GRE packet to 127.0.0.1.&lt;/p&gt;
</description></item><item><title>re: Troubleshooting Vista VPN problems</title><link>http://blogs.technet.com/rrasblog/archive/2007/04/08/troubleshooting-vista-vpn-problems.aspx#757127</link><pubDate>Fri, 13 Apr 2007 05:15:54 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:757127</guid><dc:creator>yuguang</dc:creator><description>&lt;p&gt;Another limit in vista.&lt;/p&gt;
&lt;p&gt;I found vista can only establish 2 pptp connections to outer&lt;/p&gt;
&lt;p&gt;(uncheck default gateway)&lt;/p&gt;
&lt;p&gt;When establish the 3rd pptp connection, the pptp dialer will report 800 error.&lt;/p&gt;
</description></item><item><title>re: Troubleshooting Vista VPN problems</title><link>http://blogs.technet.com/rrasblog/archive/2007/04/08/troubleshooting-vista-vpn-problems.aspx#758142</link><pubDate>Fri, 13 Apr 2007 09:56:40 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:758142</guid><dc:creator>rrasblog</dc:creator><description>&lt;p&gt;&amp;gt;&amp;gt;I found vista can only establish 2 pptp connections to &amp;gt;&amp;gt;outer (uncheck default gateway)&lt;/p&gt;
&lt;p&gt;&amp;gt;&amp;gt;When establish the 3rd pptp connection, the pptp dialer &amp;gt;&amp;gt;will report 800 error.&lt;/p&gt;
&lt;p&gt;Yuguang, you can establish only two simultaneous PPTP connections from the same machine. This is same for L2TP also. This has been the behaviour with Windows XP too.&lt;/p&gt;
&lt;p&gt;-Janani&lt;/p&gt;
</description></item><item><title>re: Troubleshooting Vista VPN problems</title><link>http://blogs.technet.com/rrasblog/archive/2007/04/08/troubleshooting-vista-vpn-problems.aspx#758643</link><pubDate>Fri, 13 Apr 2007 11:16:48 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:758643</guid><dc:creator>yuguang</dc:creator><description>&lt;p&gt;Very thanks for your reply!&lt;/p&gt;
&lt;p&gt;How can I establish more two simultaneous PPTP connections in vista or winxp? &lt;/p&gt;
&lt;p&gt;Is there a work around for this problem?&lt;/p&gt;
&lt;p&gt;BTW: I tested in win2k3, win2k3 can establish more than two simultaneous PPTP connections from the same machine.&lt;/p&gt;
</description></item><item><title>re: Troubleshooting Vista VPN problems</title><link>http://blogs.technet.com/rrasblog/archive/2007/04/08/troubleshooting-vista-vpn-problems.aspx#772803</link><pubDate>Sun, 15 Apr 2007 16:06:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:772803</guid><dc:creator>yuguang</dc:creator><description>&lt;p&gt;Janani:&lt;/p&gt;
&lt;p&gt; &amp;nbsp; Could you please take a look at the vista pptp client and vista firewall?&lt;/p&gt;
&lt;p&gt; &amp;nbsp; Why vista can't dial pptp to 127.0.0.1 when vista firewall is enabled?&lt;/p&gt;
&lt;p&gt; &amp;nbsp; Is there any work around solution?&lt;/p&gt;
&lt;p&gt;BTW: I have known how to establish more than 2 connections in winxp/vista (I modify the registry HLM\system\controlclass\net_guid\0001\WanEndpoints).&lt;/p&gt;
</description></item><item><title>re: Troubleshooting Vista VPN problems</title><link>http://blogs.technet.com/rrasblog/archive/2007/04/08/troubleshooting-vista-vpn-problems.aspx#777073</link><pubDate>Tue, 17 Apr 2007 00:14:01 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:777073</guid><dc:creator>pellen</dc:creator><description>&lt;p&gt;I have a pptp-vpn on my m0n0wall gateway. When i used Windows XP on my laptop it worked flawless to connect to the VPN where ever i was. Now im on Vista and when i connect to my VPN i get a dedicated ip (v4) from the vpn-server, but then my local network connection that connects me to the internet dies somehow...and that makes the vpn connection die too...i have noooo idea why it behaves like this and it drives me nuts :(&lt;/p&gt;
&lt;p&gt;Please help me :/&lt;/p&gt;
</description></item><item><title>re: Troubleshooting Vista VPN problems</title><link>http://blogs.technet.com/rrasblog/archive/2007/04/08/troubleshooting-vista-vpn-problems.aspx#777235</link><pubDate>Tue, 17 Apr 2007 01:09:41 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:777235</guid><dc:creator>Donna</dc:creator><description>&lt;p&gt;I can estabilish the VPN connection, but it drops all internet capabilities and the status shows local only. &amp;nbsp;What is the .inf file that needs to be selected if you want to install IPv4?&lt;/p&gt;
</description></item><item><title>re: Troubleshooting Vista VPN problems</title><link>http://blogs.technet.com/rrasblog/archive/2007/04/08/troubleshooting-vista-vpn-problems.aspx#777251</link><pubDate>Tue, 17 Apr 2007 01:23:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:777251</guid><dc:creator>pellen</dc:creator><description>&lt;p&gt;yaay...problem solved...it was my FON-router that screwed the network my VPN was on :)&lt;/p&gt;
</description></item><item><title>re: Troubleshooting Vista VPN problems</title><link>http://blogs.technet.com/rrasblog/archive/2007/04/08/troubleshooting-vista-vpn-problems.aspx#779000</link><pubDate>Tue, 17 Apr 2007 08:46:34 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:779000</guid><dc:creator>rrasblog</dc:creator><description>&lt;p&gt;&amp;gt;&amp;gt;I can estabilish the VPN connection, but it drops all &amp;gt;&amp;gt;internet capabilities and the status shows local only. &amp;nbsp;&amp;gt;&amp;gt;What is the .inf file that needs to be selected if you want &amp;gt;&amp;gt; to install IPv4?&lt;/p&gt;
&lt;p&gt;Donna, please check if you have enabled the &amp;quot;Use remote default gateway&amp;quot; on your VPN connection. If you want to continue to use internet and use the VPN connection only for corp traffic, then this setting should be unchecked.&lt;/p&gt;
&lt;p&gt;If I understand your question correctly, you can install IPv4 using the command &amp;quot;netsh interface ipv4 install&amp;quot; and uninstall using &amp;quot;netsh interface ipv4 uninstall&amp;quot;&lt;/p&gt;
&lt;p&gt;-Janani&lt;/p&gt;
</description></item><item><title>re: Troubleshooting Vista VPN problems</title><link>http://blogs.technet.com/rrasblog/archive/2007/04/08/troubleshooting-vista-vpn-problems.aspx#780209</link><pubDate>Tue, 17 Apr 2007 16:12:16 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:780209</guid><dc:creator>yuguang</dc:creator><description>&lt;p&gt;I got the reason about &amp;quot;why vista pptp client can't dial itself when vista firewall is enabled&amp;quot;&lt;/p&gt;
&lt;p&gt;There are two registry keys in&lt;/p&gt;
&lt;p&gt;Service\SharedAccess\Defaults\FirewallPolicy\DisableStatefulPPTP&lt;/p&gt;
&lt;p&gt;Service\SharedAccess\Parameters\FirewallPolicy\DisableStatefulPPTP&lt;/p&gt;
&lt;p&gt;the default value is 0, change them to 1 will make everything works fine.&lt;/p&gt;
&lt;p&gt;I don't know if it's firewall's bug or MS don't want users establish PPTP connections to 127.0.0.1.&lt;/p&gt;
&lt;p&gt;Anyway, it provide a &amp;nbsp;workaround solution.&lt;/p&gt;
</description></item><item><title>re: Troubleshooting Vista VPN problems</title><link>http://blogs.technet.com/rrasblog/archive/2007/04/08/troubleshooting-vista-vpn-problems.aspx#801747</link><pubDate>Sat, 21 Apr 2007 22:02:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:801747</guid><dc:creator>Nóri</dc:creator><description>&lt;p&gt;I've enabled split tunneling on the VPN entry. Doesn't seem to fallback to our DNS server.&lt;/p&gt;
&lt;p&gt;Regardings Split DNS. We have the same server names for both external and internal. So for example my Outlook client connects to the same DNS name for both internal and external requests.&lt;/p&gt;
</description></item><item><title>re: Troubleshooting Vista VPN problems</title><link>http://blogs.technet.com/rrasblog/archive/2007/04/08/troubleshooting-vista-vpn-problems.aspx#804737</link><pubDate>Sun, 22 Apr 2007 18:01:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:804737</guid><dc:creator>Matt</dc:creator><description>&lt;p&gt;I've recently installed Vista Ultimate on one of my laptops, XP Pro is still on another. &amp;nbsp;Using the native VPN client (IPSec) on the XP laptop I'm able to connect with no problems to a Linksys BEFVP41 endpoint. &amp;nbsp;Unfortunately I've had no such luck with Vista. &amp;nbsp;I'm this }{ close to getting it to work...looking at the VPN log on the Linksys I can see negotiations beginning, but then I get an error to the effect of &amp;quot;check Perfect Forward Secrecy settings&amp;quot; (PFS is enabled on the endpoint). &amp;nbsp;I can't find where in the Consec rule to enable PFS...in fact I can't seem to find it anywhere in AdvFirewall Configuration. &amp;nbsp;Can someone help me out? &amp;nbsp;What reg key do I need to hack, what little-known menu do I need to access? &amp;nbsp;I've about worn out Google looking for the solution.&lt;/p&gt;
&lt;p&gt;Love Vista so far, but this may be a deal-breaker for me. &amp;nbsp;Help me MS!&lt;/p&gt;
</description></item></channel></rss>