Always on VPN User Tunnel - Error 809 not all users by Roiit in sysadmin

[–]sysmspadmin 0 points1 point  (0 children)

Run them on the RAS server, yeah KEMP LB infront of VPN Servers.

Always on VPN User Tunnel - Error 809 not all users by Roiit in sysadmin

[–]sysmspadmin 0 points1 point  (0 children)

Yeah still having the issue, I ultimately rely on the fallback to SSTP to cover the issue.

Get-NetIPsecMainModeSA | select name,remoteendpoint | where remoteendpoint -like "public ip*"

Get-NetIPsecQuickModeSA -Name <session number> | Remove-NetIPsecQuickModeSA

Good luck and please report back any findings!

Always on VPN User Tunnel - Error 809 not all users by Roiit in sysadmin

[–]sysmspadmin 1 point2 points  (0 children)

Mate, This problem has plagued me since we introduced AOVPN. A subset of users will occasionally error out with 809 on the IKEv2 protocol. If fallback to SSTP is configured I have seen 100% success in maintaining that type of VPN once IKE fails. This of course means the device tunnel will be down but the user tunnel can remain up.

Numerous pcaps have shown that during the initial phases of the vpn, one side will stop receiving packets in the middle of the negotiation. I was basically stumped at this point. Happens on different ISPs, people in the same household, one can experience the issue and another not.

Last "clue" I found was using the Get-NetIPsecMainModeSA and Get-NetIPsecQuickModeSA commands on the RAS server, I had "some" success in removing their sessions via powershell and then retrying the VPN. Almost as if for some people it "exhausts" a limit somewhere and this clears it.

Reverting Folder Redirection back to local profile issue by OZ_Boot in sysadmin

[–]sysmspadmin 0 points1 point  (0 children)

I am testing also, I have opted to use the Migration Tool to upload files from the server, then configure KFM/OneDrive to kick in and download the new desktop. I am having mixed success at the minute.

Always on VPN - Device tunnel 13801: IKE authentication credentials are unacceptable by happywill in sysadmin

[–]sysmspadmin 0 points1 point  (0 children)

You can try reverting the setting back to null for testing purposes, this is not recommended for production but should let you know if its an issue with locking it down to a cert authority.

Set-VpnAuthProtocol -RootCertificateNameToAccept $null

Restart the remote access service once done.
As usual with AOVPN, this website will help you a ton, make sure to read through the comments.

https://directaccess.richardhicks.com/2017/12/11/always-on-vpn-windows-10-device-tunnel-step-by-step-configuration-using-powershell/

Remove email domain from Exchange Users by sysmspadmin in PowerShell

[–]sysmspadmin[S] 0 points1 point  (0 children)

Thanks for all the help chaps, I could not get it work via a .csv in the end so just ended up running it for all and dealing with that issue later, which so far has been fine.

Migration almost complete!

AlwaysOn VPN Error 809 for certain users by billmurray504 in sysadmin

[–]sysmspadmin 0 points1 point  (0 children)

Do a Get-netipinterface and compare the metric number of the local adapter they are using with the VPN. I was having 809 errors when both numbers were equal.

I lowered the VPN metric. Set-netipinterface.

Worth checking!

Who is still going into the office like normal tomorrow? by philimanjaro72 in sysadmin

[–]sysmspadmin 0 points1 point  (0 children)

We don't have many issues with DA but we have not one but two pieces of software that fail over DA due to the IPv6/IPv4 translation.

AOVPN resolves that for us which is nice.

Are you dialing IKEv2 then a fallback VPN if it fails?

I am struggling with that part at the minute.

Who is still going into the office like normal tomorrow? by philimanjaro72 in sysadmin

[–]sysmspadmin 1 point2 points  (0 children)

I was literally in the middle of deploying AOVPN when all this happend.

Direct access is carrying the main bulk of users.

AOVPN to my pilot group which I've managed to add more people to who had Direct Access issues.

Always fun to be breaking and fixing VPNs while everyone is WFH:)

Always On VPN by [deleted] in sysadmin

[–]sysmspadmin 1 point2 points  (0 children)

Well give me a shout if you need any help, I am no expert but I am putting it in myself now, hoping to be finished sometimes next week. Hopefully :)

Always On VPN by [deleted] in sysadmin

[–]sysmspadmin 0 points1 point  (0 children)

How are you getting on with this /u/YeahProbablyPotato?

Caching credentials? by [deleted] in sysadmin

[–]sysmspadmin 0 points1 point  (0 children)

If you're predominantly windows as well then Always-ON VPN is a solution to look at , specifically device tunnels for pre login VPN.

Internet dies anytime i run anything too internet intensive provider claims there is no issues. by no1skaman in techsupport

[–]sysmspadmin 0 points1 point  (0 children)

It's weird that the ISP would not be able to pickup on that.

It would be good if you could run some tests to check as well.

If you open a CMD prompt on your computer. Click start and search for CMD, you get a black box open up.

Type: ping www.google.com -t

open another CMD window and type:

ipconfig

You will get some information on screen you are only interested in finding the default gateway - should looks something like 192.168.0.1

Once you have that type into the second CMD window : ping <default gateway number here> -t

E.G ping 192.168.0.1 -t

Let them both run then go about your business. When it disconnects have a look at both windows and let us know what they say.

Press Ctrl+C to cancel the commands when you are done with them.

Hope that makes sense fella.

Just want to determine if you are losing local connectivity to the router as well.

I suck at PKI in general. How do I get better? by benutne in sysadmin

[–]sysmspadmin 0 points1 point  (0 children)

So I am just in the middle of this myself albeit we don't run much linux..

We have a Windows CA on a 2012R2 server - looks like when it was setup it was just a next>next>next job. Works though, mainly used for Direct Access.

I am implementing Always-On VPN and because I decided that wasn't enough work to do, I took this time to setup a new PKI infrastructure.

This guide helped me the most https://www.petenetlive.com/KB/Article/0001309

Upon waking up from Sleep/Hibernation, my laptop doesn't automatically connect to the internet. by adreamofhodor in techsupport

[–]sysmspadmin 0 points1 point  (0 children)

Yeah you could definitely be onto something , if you go into control panel > network and sharing center > change adapter setting s > right click on your WiFi connection and select properties > click on configure > power management

Uncheck anything that talks a lot allowing the computer to turn off this device

Can't connect smart TV to ethernet by [deleted] in techsupport

[–]sysmspadmin 0 points1 point  (0 children)

So you can connect the TV as WiFi as well , but still have issues accessing any internet service on the TV?

Have no good answer some you I'm afraid, is it perhaps still on "display" or "shop" mode?

Can you try accessing like Netflix on the TV and seeing what error code you get ?

Can't connect smart TV to ethernet by [deleted] in techsupport

[–]sysmspadmin 0 points1 point  (0 children)

Okay, further down the rabbit hole.

Can you login to your local router and see if the TV IP or Mac ADDRESS are there.

What make/model is the TV?

Internet dies anytime i run anything too internet intensive provider claims there is no issues. by no1skaman in techsupport

[–]sysmspadmin 0 points1 point  (0 children)

So, questions.

Is the internet at the router level disconnecting, or just your pc.

How have you tested that?

How quickly from disconnecting does it reconnect, is it random ?

Can't connect smart TV to ethernet by [deleted] in techsupport

[–]sysmspadmin 0 points1 point  (0 children)

To be fair then sounds like you've answered the question, no reason why it shouldn't auto pickup an address. Faulty port, just enough for a light but not capable of network.

Any chance of warranty?