Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

XP Credentials do not pass through correctly using VPN 1

Status
Not open for further replies.

astorre

Technical User
Jul 4, 2005
24
0
0
GB
Hi, I have a strange problem with Windows XP. Here is the setup:

Windows 2003 domain, XP Clients.
Outlook in cached mode, My documents redirected to their home drive and synchronizing at logon and logoff.
Remote users have ADSL / Broadband and connect to the office using SonicWall VPN Client. Nearly all users connect successfully and work on shared files, Outlook etc with no problems. 3 Users have the following problem:
They connect the VPN connection successfully.
Outlook does not connect. After about 5 minutes a login prompt appears from the Exchange server. If the user inputs their credentials they receive a message stating that this combination of username/password has already been tried. They get the same message when trying mapped drives.

I have got all three users to login at the office and they have no problems. Their passwords are set to never expire.
Now the really weird bit - At the office I have a separate ADSL line for testing purposes. I connect these users machines on this line, connect the vPN client and everthing works fine. The users take the machines home and have the same problems. From their homes with the VPN connected they can ping any server by IP address or FQDN. I can make Remote desktop connections to them and remote connections from the clients to the servers. If they map a drive from their machine the same password problem occurs but if I enter different credentials the mapping works fine.
All three users are using different ISP's. One is AOL, one is cable (telewest) the other is ADSL from a BT reseller.

Any ideas anyone?

Thanks
 
I am having the EXACT same problem as this with 1 client laptop. The reason they are able to get in in the office ADSL is because they have already authenticated on the domain while plugged in. If you reboot you'll have the same issue.

If anyone can help on this It'd be greatly appreciated.
 
The Solution is to force Kerberos to use TCP instead of UDP. MS KB article 244474

I have detailed the steps below. I hope this helps.

1. Start Registry Editor.
2. Locate and then click the following registry subkey:
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa\ Kerberos\Parameters
Note If the Parameters key does not exist, create it now.
3. On the Edit menu, point to New, and then click DWORD Value.
4. Type MaxPacketSize, and then press ENTER.
5. Double-click MaxPacketSize, type 1 in the Value data box, click to select the Decimal option, and then click OK.
6. Quit Registry Editor.
7. Restart your computer.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top