SSTP, NT Authentication on Windows 2012 issue

Post your questions about SoftEther VPN software here. Please answer questions if you can afford.
Post Reply
certinet
Posts: 6
Joined: Thu Apr 07, 2016 2:39 pm

SSTP, NT Authentication on Windows 2012 issue

Post by certinet » Thu Apr 07, 2016 2:43 pm

Hi,

We've setup a VPN with SoftEther on a Windows 2012 server. I can connect from the SoftEther VPN Client without issue using a Active Directory Account. When I try to connect through the Windows build-in (SSTP), I get an error about bad user name or password. On the server part, in Event Viewer, I get an AD error that the user could not authenticate.

What to do?

Thanks

certinet
Posts: 6
Joined: Thu Apr 07, 2016 2:39 pm

Re: SSTP, NT Authentication on Windows 2012 issue

Post by certinet » Thu Apr 07, 2016 3:14 pm

Found some information. If I set, on the client side, the authentication to PAP (password unencrypted), it works. If I set it back to MS-CHAPv2, it doesn't work.

Seems like CHAPv2 is not activated on Windows 2012 or SoftEther Server.

certinet
Posts: 6
Joined: Thu Apr 07, 2016 2:39 pm

Re: SSTP, NT Authentication on Windows 2012 issue

Post by certinet » Thu Apr 07, 2016 3:36 pm

Other findings!!!

Seems like MS-CHAPv2 supports only NTLM while my Windows 2012 server wants NTLMv2

certinet
Posts: 6
Joined: Thu Apr 07, 2016 2:39 pm

Re: SSTP, NT Authentication on Windows 2012 issue

Post by certinet » Fri Apr 15, 2016 12:26 pm

Up!

certinet
Posts: 6
Joined: Thu Apr 07, 2016 2:39 pm

Re: SSTP, NT Authentication on Windows 2012 issue

Post by certinet » Wed Apr 20, 2016 3:21 pm

No one has any idea?

Thanks

exciter0
Posts: 21
Joined: Wed Jun 03, 2015 9:03 pm

Re: SSTP, NT Authentication on Windows 2012 issue

Post by exciter0 » Thu Apr 21, 2016 11:59 pm

MS-CHAPv2 is not supported...see here http://www.vpnusers.com/viewtopic.php?f=7&t=4297

thisjun
Posts: 2458
Joined: Mon Feb 24, 2014 11:03 am

Re: SSTP, NT Authentication on Windows 2012 issue

Post by thisjun » Fri May 20, 2016 7:29 am

SoftEther VPN supports MS-CHAPv2.

Did you include domain name in username?

certinet
Posts: 6
Joined: Thu Apr 07, 2016 2:39 pm

Re: SSTP, NT Authentication on Windows 2012 issue

Post by certinet » Tue Jul 05, 2016 8:56 pm

Yes I did

domain\username and even username@domain

thisjun
Posts: 2458
Joined: Mon Feb 24, 2014 11:03 am

Re: SSTP, NT Authentication on Windows 2012 issue

Post by thisjun » Fri Jul 22, 2016 1:35 am

If domain name and virtual hub name is same, please append @virtual hub name.

Post Reply