Hi,
I have tried to configure a Site-to-Site VPN in a testing environment (2x
Win 2003 Enterprise Servers) by following the instructions from MS
(
http://technet2.microsoft.com/window...mspx?mfr=true).
I have been following nearly exactly those instructions.
Both servers are DCs, each one configured with an Enterprise-Root-CA. RRAS
is configured for VPN and Demand-dial-routing. RRAS policies have been set
up. Authentication has been set up to use EAP with certificates (server,
policy, dial-on-demand connection). Encryption was set to L2TP/IPSec.
Certificates have been created using autoenrollment and webinterface and they
have been published to the neccessary places and have been mapped to the user
accounts where neccessary. The proper certificates have been set for the
credentials of the dial-on-demand interfaces.
While trying to establish a connection between the demand-dial-interfaces
the following error occurs:
"The connection to the interface has been disconnected."
"The following error occured: The interface credentials have not been set."
I changed the authentification method to MS-CHAP-V2. Now i was able to
establish the connection.
I changed the authentification method back to EAP with certificates.
I created a dialup connection with the same configuration as the demand-dial
interfaces. I used the certificate for the demand-dial interface for
authentification and was able to establish a connection. The
demand-dial-interface on the other side showed "connected".
I used the dialup dial function for the demand-dial connection by opening
the router.pbk (c:\windows\system32\ras, contains the configuration for the
demand-dial connection) and was able to establish a connection. The
demand-dial-interface on the other side showed "connected".
(I tried the steps mentioned before on both sides)
It looks like the error does only occur when I'm trying to establish the
connection between the demand-dial interfaces by selecting "connect" at one
of the demand-dial interfaces.
The same error occurs also with encryption set to PPTP.
Has anyone an idea why this error occurs and how to fix it?
Thank you in advance!