VPN Sessions Destroyed Immediately by Windows Security Auditing Event ID 4634
I am attempting to establish a VPN connection between computers in my local network. I have enabled VPN on the server, forwarded port 1723 on the router, and permitted VPN traffic on the firewalls of the server and router. Yet when the client
attempts to connect, I receive the error message:
Verifying user name and password... Error 629: The connection was closed by the remote conmputer.
Here is what I'm pretty sure is the event viewer log entries for this behavior on the client side:
CoId={40E0F925-14F2-4C82-A625-9134646BF776}: The user D620\gt1763c dialed a connection named VPN Connection to Home Desktop which has terminated. The reason code returned on termination is 829.
- System
- Provider
[ Name] RasClient
- EventID 20226
[ Qualifiers] 0
Level 4
Task 0
Keywords 0x80000000000000
- TimeCreated
[ SystemTime] 2011-09-16T17:57:03.000000000Z
EventRecordID 33052
Channel Application
Computer D620
Security
- EventData
{40E0F925-14F2-4C82-A625-9134646BF776}
D620\gt1763c
VPN Connection to Home Desktop
829
CoId={40E0F925-14F2-4C82-A625-9134646BF776}: The user D620\gt1763c dialed a connection named VPN Connection to Home Desktop which has failed. The error code returned on failure is 629.
- System
- Provider
[ Name] RasClient
- EventID 20227
[ Qualifiers] 0
Level 2
Task 0
Keywords 0x80000000000000
- TimeCreated
[ SystemTime] 2011-09-16T17:57:03.000000000Z
EventRecordID 33053
Channel Application
Computer D620
Security
- EventData
{40E0F925-14F2-4C82-A625-9134646BF776}
D620\gt1763c
VPN Connection to Home Desktop
629
Here is the Event ID on the server side:
Log Name: Security
Source: Microsoft-Windows-Security-Auditing
Date: 9/16/2011 1:57:09 PM
Event ID: 4634
Task Category: Logoff
Level: Information
Keywords: Audit Success
User: N/A
Computer: queen_mum-PC
Description:
An account was logged off.
Subject:
Security ID: queen_mum-PC\awyarbr
Account Name: awyarbr
Account Domain: queen_mum-PC
Logon ID: 0xdd06d5
Logon Type: 3
This event is generated when a logon session is destroyed. It may be positively correlated with a logon event using the Logon ID value. Logon IDs are only unique between reboots on the same computer.
One other tidbit that might be useful: After the failed attempt at a VPN connection, the server shows among its active connections something called "RAS (Dial In) Interface, No Network Access" that won't go away until I delete the "Incoming Connections"
option from the list of Network Adapters.
September 16th, 2011 11:56pm


