SSTP, NT Authentication on Windows 2012 issue
-
- Posts: 6
- Joined: Thu Apr 07, 2016 2:39 pm
SSTP, NT Authentication on Windows 2012 issue
Hi,
We've setup a VPN with SoftEther on a Windows 2012 server. I can connect from the SoftEther VPN Client without issue using a Active Directory Account. When I try to connect through the Windows build-in (SSTP), I get an error about bad user name or password. On the server part, in Event Viewer, I get an AD error that the user could not authenticate.
What to do?
Thanks
We've setup a VPN with SoftEther on a Windows 2012 server. I can connect from the SoftEther VPN Client without issue using a Active Directory Account. When I try to connect through the Windows build-in (SSTP), I get an error about bad user name or password. On the server part, in Event Viewer, I get an AD error that the user could not authenticate.
What to do?
Thanks
-
- Posts: 6
- Joined: Thu Apr 07, 2016 2:39 pm
Re: SSTP, NT Authentication on Windows 2012 issue
Found some information. If I set, on the client side, the authentication to PAP (password unencrypted), it works. If I set it back to MS-CHAPv2, it doesn't work.
Seems like CHAPv2 is not activated on Windows 2012 or SoftEther Server.
Seems like CHAPv2 is not activated on Windows 2012 or SoftEther Server.
-
- Posts: 6
- Joined: Thu Apr 07, 2016 2:39 pm
Re: SSTP, NT Authentication on Windows 2012 issue
Other findings!!!
Seems like MS-CHAPv2 supports only NTLM while my Windows 2012 server wants NTLMv2
Seems like MS-CHAPv2 supports only NTLM while my Windows 2012 server wants NTLMv2
-
- Posts: 6
- Joined: Thu Apr 07, 2016 2:39 pm
-
- Posts: 6
- Joined: Thu Apr 07, 2016 2:39 pm
Re: SSTP, NT Authentication on Windows 2012 issue
No one has any idea?
Thanks
Thanks
-
- Posts: 21
- Joined: Wed Jun 03, 2015 9:03 pm
Re: SSTP, NT Authentication on Windows 2012 issue
MS-CHAPv2 is not supported...see here http://www.vpnusers.com/viewtopic.php?f=7&t=4297
-
- Posts: 2458
- Joined: Mon Feb 24, 2014 11:03 am
Re: SSTP, NT Authentication on Windows 2012 issue
SoftEther VPN supports MS-CHAPv2.
Did you include domain name in username?
Did you include domain name in username?
-
- Posts: 6
- Joined: Thu Apr 07, 2016 2:39 pm
Re: SSTP, NT Authentication on Windows 2012 issue
Yes I did
domain\username and even username@domain
domain\username and even username@domain
-
- Posts: 2458
- Joined: Mon Feb 24, 2014 11:03 am
Re: SSTP, NT Authentication on Windows 2012 issue
If domain name and virtual hub name is same, please append @virtual hub name.