coreykeeling Posted July 10, 2018 Posted July 10, 2018 Afternoon, I have been following the following guide to setup Always on VPN with IKE but I am having issues with IKE not finding a valid machine certificate and I don't know why. Part 1 https://www.petenetlive.com/KB/Article/0001399 ​Part 2 https://www.petenetlive.com/KB/Article/0001403 I am using a Windows Server 2016 with RRAS and NPS. I have a public certificate which is installed under Local Computer > Personal > Certificates and two internal certificates stored under the same location. The one private cert just has the following EKU Client and Server Authentication where as the other cert has Client & Server Authentication as well as IP Security IKE Intermediate. The client machine has a user certificate with client authentication and a machine certificate with client & server authentication. Can anyone help me to see where I am going wrong? I know Microsoft does not have a lot of documentation on the Always On VPN feature but it is something I would like to implement with the new staff laptops. Regards I 1
Jawloms Posted July 10, 2018 Posted July 10, 2018 At this tutorial; https://4sysops.com/archives/active-directory-group-policy-and-certificates-for-always-on-vpn/ This is in the comments; Great article, keen to see the final articles! As an FYI, was following this to the letter in my test environment but could not get the user certificate deployed. Permissions and certificate was correctly setup. Turns out the "Microsoft Platform Crypto Provider" requires a TPM chip, as I was using a VM for the client machine (which obviously has no TPM hardware) I would see the error message "Can not find a valid CSP in the local machine" when trying to manually enroll the certificate. Solution is to also tick "Microsoft Software Key Storage Provider" and have it second in order after "Microsoft Platform Crypto Provider" Any use?
coreykeeling Posted July 10, 2018 Author Posted July 10, 2018 Unfortunately not but thank you. I have the user certificate deployed to the machine ok and have the options ticked as recommended in the comments.
markwilfan Posted July 10, 2018 Posted July 10, 2018 ahh man! I had this and for the life of me I can't remember what the fix was. What does the cert look like in cert manager for the user? This is what mine looks like I have a feeling it was to do with the vpn connection This is my VPN connection expanded out. Was created with an MS PS script - - - Updated - - - flanders is my NPS btw
coreykeeling Posted July 10, 2018 Author Posted July 10, 2018 ahh man! I had this and for the life of me I can't remember what the fix was. What does the cert look like in cert manager for the user? This is what mine looks like [ATTACH=CONFIG]49645[/ATTACH] I have a feeling it was to do with the vpn connection This is my VPN connection expanded out. Was created with an MS PS script [ATTACH=CONFIG]49646[/ATTACH] - - - Updated - - - flanders is my NPS btw I have the same setup as you but still no luck. Do you have two internal certificates one for NPS and another for the VPN Server? Photo of mine:
markwilfan Posted July 10, 2018 Posted July 10, 2018 That looks like a server cert. Your users need a users cert
markwilfan Posted July 10, 2018 Posted July 10, 2018 yeh so our users have a user cert our nps has an nps cert and vpn has a vpn cert
coreykeeling Posted July 10, 2018 Author Posted July 10, 2018 Sorry the photos were from my NPS and RRAS Server. Here is a photo of a user cert on the client machine which is the same as yours.
markwilfan Posted July 10, 2018 Posted July 10, 2018 Might want to revisit the certs section. It is a little confusing
coreykeeling Posted July 10, 2018 Author Posted July 10, 2018 yeh so our users have a user cert our nps has an nps cert and vpn has a vpn cert [ATTACH=CONFIG]49649[/ATTACH] [ATTACH=CONFIG]49651[/ATTACH] Your public certificate has the IP Security IKE Intermediate EKU but I don't seem to be able to add that on mine. The rest seem the same. I'll most likely start again on Friday.
rustiferch Posted April 2, 2020 Posted April 2, 2020 Did anyone actually get this working? I've followed this guide, the microsoft guide and another here: https://4sysops.com/archives/active-directory-group-policy-and-certificates-for-always-on-vpn/ but can't seem to get things to work. I keep getting the same IKE error 13806.
meakjoe Posted April 2, 2020 Posted April 2, 2020 I followed this guide which was very helpful, might be worth running through it and checking the steps are the same... Tutorial – Deploy Always On VPN | Alex Ø. T. Hansen
CAWJames Posted April 2, 2020 Posted April 2, 2020 Our settings are exactly like yours, but we have Max encryption in the drop down and automatic for VPN type, not sure that makes a difference! We found the docs extremely confusing tbh, and went with user rather than machine, but we are probably going 2FA on our firewalls eventually. Oh and make sure your servers can resolve the internal address of the NPS server you have in the boxes, not sure if the client needs to as well.
rustiferch Posted April 2, 2020 Posted April 2, 2020 Thanks Meakjoe. This guide looks way more in-depth but its relating to machine certificates not user. We are hoping to go down the user cert. path.
rustiferch Posted April 2, 2020 Posted April 2, 2020 I know its old, but still relevant! I've gone through and double checked the certificate side of things and can't seem to fault it. In my test environment I'm running all components on the one server (RRAS, NPS, CA, DHCP, DNS and AD).
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now