I've been slowing converting clients from PPTP to L2TP but keeping coming
across some XP machines that won't make L2TP connections. Those machines
will report that a local machine certificate is not present. I have
confirmed:
i) local machine cert is present and has a valid key
ii) the trusted CA certificate is installed and matches the one on the VPN
server.
iii) NAT traversal is not an issue
I basically follow an identical procedure to install the certificates on a
client, 75% work without issue and 25% simply refuse to, no matter what is
tried. There are no special policies on the VPN server to restrict access,
these machines simply cannot see that they have a valid machine certificate
installed. Installing new certificates does not help. The troubleshooting
info I've found simply says to make sure the cert is there and that it has a
valid key and cert path, which they do. Don't know what else to try, any
ideas?
|