IKEv2 VPN Setup

I'm trying to setup an IKEv2 VPN on Server 2012 R2 to replace my old PPTP VPN. I have the Remote Access and NPS roles installed. 

When I try to connect from my Windows Phone I'm getting Error Code 13801 on the phone and on the server I'm seeing Event ID 20255 from source RemoteAccess and it says: The following error occurred in the Point to Point Protocol module on port: VPN2-127, UserName: <Unauthenticated User>. Negotiation timed out

When I try to connect from my Windows 8 machines I'm getting "Error 800: The remote connection was not made because the attempted VPN tunnels failed. The VPN server might be unreachable. If this connection is attempting to use an L2TP/IPsec tunnel, the security parameters required for the IPsec, negotiation might not be configured properly."

Can someone explain to me what I'm missing? I have the following ports open in the perimeter firewall.

UDP: 500, 4500, 1701 and protocol ESP

When I get back to the office I will try connecting directly to the server to rule out the firewall as an issue but I'm fairly certain that is not my problem.

*Update

When I attempt to connect directly to the server without the firewall in the middle I receive the same e

June 4th, 2015 9:08pm

Hi,

IKEv2 is different than PPTP. IKEv2 needs certificate to work properly.

Please make sure that you have install the suitable certificate on the IKEv2 server.

For detailed information about the certificate requirement of the IKEv2, please refer to the link below,

http://blogs.technet.com/b/rrasblog/archive/2009/06/10/what-type-of-certificate-to-install-on-the-vpn-server.aspx

Best Regards.

Free Windows Admin Tool Kit Click here and download it now
June 8th, 2015 7:08am

I already had a certificate on the server, I did update and replace the certificate with a new one but I'm still getting the same error message when I try to connect.
June 9th, 2015 12:33pm

Hi Vincent,

First, please make sure that the certificate has been placed in Machine Account--> Personal and it meets the requirement in the link above.

If issue persists, please check if there is any other certificate in the Machine Account--> Personal.

If yes, please delete them then try again.

Here is a troubleshooting guide, it may be helpful:

 https://technet.microsoft.com/en-us/library/dd941612%28v=ws.10%29.aspx?f=255&MSPPError=-2147217396

Best Regards.

 

Free Windows Admin Tool Kit Click here and download it now
June 25th, 2015 1:50am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics