Jump to content

Recommended Posts

Posted

OK I'm sure this is linked:

 

OWA Cannot login to OWA 2007 externally - each time I get stuck in a login loop with the error

 

You could not be logged on to ISA Server. Make sure that your domain name, user name, and password are correct, and then try again.

 

I have tried domain\username, [email protected], and username - all loop back to above error..

 

Works perfectly internally..

 

VPN

 

When I try to connect to the VPN, it says "verifying username and password" then "connecting to " and then "verifying username and password" again before it errors with

error 718: The connection was terminated because the remote computer did not respond in a timely manner

 

I have a feeling both are linked - possibly to AD but not sure what...

 

Interestingly, Moodle (same ISA server) allows me to login using same AD server

 

:(

Posted (edited)

What ports are you forwarding for the VPN?

 

Also is the client Vista?

 

On the ISA Server try ticking only MS-CHAP for the Auth

Edited by FN-GM
Posted

@ Gatt

 

You know on your rules, are you using the Name? if so are you using the FQDN?

 

Have you tried using the Servers IP in the Rules instead?

 

It sounds like it's having problems passing through the authentication

 

James.

Posted
@ Gatt

 

You know on your rules, are you using the Name? if so are you using the FQDN?

 

Have you tried using the Servers IP in the Rules instead?

 

It sounds like it's having problems passing through the authentication

 

James.

 

The Firewall rules shouldn't cause this problem. Even if you have no rules setup it will still connect.

 

I have had problems connecting from Vista machines but when using XP its perfect.

Posted

I'm talking more from this error:

 

You could not be logged on to ISA Server. Make sure that your domain name, user name, and password are correct, and then try again.

 

I have had this happen to me, and it was because the ISA box could not talk to the DC so it could not autenticate.

 

James.

Posted
I'm talking more from this error:

 

 

 

I have had this happen to me, and it was because the ISA box could not talk to the DC so it could not autenticate.

 

James.

 

Sorry i forgot about the exchange bit. :doh:

Posted

@edutech - here is how my OWA rule is setup:

 

To: mail.moorsidehigh.com / / Fwd original Host header / Requests appear from ISA

Traffic - HTTPS

Listener - See below

Public Name - mail.moorsidehigh.com

Auth Delegation - Basic

 

OWA Listener:

Conntions - SSL Port 443

certifcates - mail.moorsidehigh.com

sso - no

Auth - HTML FOrm Auth - LDAP (AD) - LDAP Server set - DC / - Login Expression = MYDOMAIN\* / DC

Posted

Do you have a direct unfiltered connection from your ISA box to the net and is your ISA box acting as your VPN gateway?

 

This sounds like not all of the ports are avalible and/or the GRE protocol is not being fowarded. This could possibly be being held up in your router or by an upstream provider assuming your router supports GRE passthrough (protocol 47).

 

Routing and Remote Access Blog : Which ports to unblock for VPN traffic to pass-through?

Posted

@SYNACK - yep thats how its configured..

I have seen reference to GRE in the event logs but nothing on how to resolve it - will

check that link though :)

Posted

What ports are you forwarding for the VPN?

 

Also is the client Vista?

 

On the ISA Server try ticking only MS-CHAP for the Auth

  • Thanks 1
Posted

Glad to hear your got OWA working ;)

 

I'll keep out of the VPN, because i couldn't set it up on ours due to our LA blocking the ports :(

 

James.

Posted

OK this VPN error is really getting on my t1ts..

I have done everything that I know of to create the VPN on the ISA box and in RRAS

I have a rule for PPTP connections, and RRAS configured for Dial-in/VPN

 

But whenever I try to connect I get an error 718

 

Someone mentioned GRE - but despite scouring Google I have yet to fathom how to get ISA to work

 

Its not my Router as we have had VPN working all last year with no issues.

Posted

Did you not use the ISA 2006 wizzard to configure it, this handles all of the rras config and opening the right ports in ISA. Have you tried connecting to it directly on the external port from behind your router just in case anh have you got ISA 2k6 SP1 installed. Additionally have you run the ISA BPA (best practices analyser), I think that this is included in SP1 along with better diagnostic tools.

 

There is also this as a last resort test:

How to test GRE nd PPTP

  • Thanks 1
Posted
Did you not use the ISA 2006 wizzard to configure it, this handles all of the rras config and opening the right ports in ISA. Have you tried connecting to it directly on the external port from behind your router just in case anh have you got ISA 2k6 SP1 installed. Additionally have you run the ISA BPA (best practices analyser), I think that this is included in SP1 along with better diagnostic tools.

 

There is also this as a last resort test:

How to test GRE nd PPTP

 

 

Yep used the ISA Wizard to configure RRAS and created the access rule - will try again tomorrow though

Not sure if SP1 is on but it should have gone out via WSUS..

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...