![Vasco aXsGUARD Gatekeeper How To Do Download Page 51](http://html1.mh-extra.com/html/vasco/axsguard-gatekeeper/axsguard-gatekeeper_how-to-do_855712051.webp)
1. The client sits behind a firewall which is blocking PPTP / GRE traffic. The
firewall should be configured to allow this traffic (see
Section 2.6,
“Firewalls and PPTP”
and
Section 4.2, “Client-Side Firewall”
). Refer to your
router / firewall documentation if necessary.
2. Verify the user’s PPTP settings on the aXsGUARD Gatekeeper (see
Section 3.5, “User Settings”
).
3. Another error ocurred while setting up the connection, restart Windows
and try again.
4. Your Internet Service provider or in-between networks are blocking GRE
packets.
I cannot log on with my Active Directory Password (Directory Services
Password).
• On the aXsGUARD Gatekeeper, verify if the correct Authentication Policy
has been assigned under Authentication ⇒ Services.
• Verify if the user exists on your Active Directory Server. If the user exists,
make sure the AD user account isn’t locked. If the user is not present or
locked, authentication fails.
• A WINS server is required. The aXsGUARD Gatekeeper needs to be able to
resolve the domain/workgroup to the AD IP (see
Section 3.4.2, “Supported
Authentication Methods”
). The GlobalNames zones (WINS successor)
should work as well. WINS is slowly getting phased out by Microsoft being
and being replaced by "GlobalNames zones". On MS server 2008, WINS is
no longer a role but has become a "feature". The WINS configuration itself
is exactly the same as on MS server 2003. For more information about
setting up a WINS server, consult your Microsoft documentation.
Information can also be found on this MS Technet link:
http://technet.microsoft.com/en-us/library/cc787831%28WS.10%29.aspx
• Verify if the DS username with DS tree search permissions has the
appropriate privileges on the AD server. See the section "Specifying a
Directory Base" in the aXsGUARD Gatekeeper Directory Services How To,
which can be accessed by clicking on the permanently available
Documentation
button in the Administrator Tool. Only search (read)
permissions are required, but you may try to escalate the privileges as a
last resort. Consult your Microsoft documentation if necessary.
PPTP log Error
read(fd=5,buffer=804d580,len=8196) from PTY failed:
status = -1 error = Input/output error
.
The client is most probably getting
PPTP error 619 as mentioned above. GRE packets are being prevented from
reaching the aXsGUARD Gatekeeper.
Figure 5.2. PPTP Error 619
5.2. Server-Side Troubleshooting
© VASCO Data Security 2011
50