3s-gtech Posted February 9, 2021 Posted February 9, 2021 Hi all, I've been trying to put the basic framework in for AoVPN here, but I've reached the point where I'm going to have to get someone in that actually knows what they're doing. I've followed the guides, I have a profile, but I'm not getting any useful logs and there's so many variables I don't know where to start. I'm not even 100% sure that the route into our RRAS is working correctly, as it's not as simple as pinging it or trying it in a browser I've been through some fantastically detailed guides, and have a RRAS that shows nice green ticks. It just doesn't work. I don't have a clue how to diagnose it. Anyone got any recommendations for consultants that could do this? It's the sort of thing that could probably be done over TeamViewer or similar. I have already in place: A VM running Server 2019 for RRAS, NPS on 2012 R2, Windows 10 20H2 clients, a VPN profile pointing to our server. I do not have in place: a functioning VPN.
Boredguy Posted February 9, 2021 Posted February 9, 2021 (edited) Which version of AoVPN are you aiming for. User based, or Device based? I've setup a User based "Forced" tunnel (script example has split-tunnel for users) with the VPN on a 2019 server with Dual NIC for the RRAS and the NPS on 2012 R2 without too many issues. Firewall has UDP ports 500 and 4500 open inbound pointing to the IP on the NIC we're using for the connection (different IP range than our main network for extra security). I basically followed the steps from https://docs.microsoft.com/en-us/windows-server/remote/remote-access/vpn/always-on-vpn/deploy/always-on-vpn-deploy-deployment and only fun I had was that the certificate had not been picked up on the first devices we sent out as the GPO wasn't applied. Also adjusted the SCCM deployment of the script to be by user group instead of just device. Assuming your device is showing that it has the AoVPN in the Network Connection box, if you have something blocking the ports, you will get an error number/message showing under it in a orange text (how we worked out certificate was wrong) Other authentication errors should appear in your NPS log in C:\Windows\System32\LogFiles folder on your 2012 box Edited February 9, 2021 by Boredguy
3s-gtech Posted February 9, 2021 Author Posted February 9, 2021 Device based is the plan. The certs seem to be dishing out okay, I have one in Personal, produced by my CA, which is the name of the test client. The VPN shows as a network connection (WAN Miniport IKEv2) but doesn't show in the VPN UI - it does show under Powershell and this seems to be the correct behaviour for an All Users VPN.
3s-gtech Posted February 12, 2021 Author Posted February 12, 2021 NM, fixd it myself https://welsheduit.wordpress.com/2021/02/12/always-on-vpn-device-tunnel-quick-notes/ 1
Squelch Posted May 21, 2021 Posted May 21, 2021 Having similar issues. The device tunnel is connecting to the vpn server, it's getting an IP via DHCP but nothing much else is happening. I can't ping anything or get to anything. Do I have to add a route to the DC? IP of DC 24 Thanks in advance.
3s-gtech Posted May 21, 2021 Author Posted May 21, 2021 I added routes to the specific server ranges, so I could access internal services. Not sure this was the best way - you could just allow to the particular servers you need. DHCP/DNS and AD will be necessary. 1
Squelch Posted May 21, 2021 Posted May 21, 2021 To test, I added 10.0.0.0/8 as my DC is 10.42.*.* Still doesn't work though. I'm missing something, probably fairly big and very important.
3s-gtech Posted May 21, 2021 Author Posted May 21, 2021 You’ll be very close, the fact that the VPN connects shows that. Have a look through all the pointers in the blog link, and re-check those steps in the setup guide.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now