Unable to get Windows clients connecting to VPN OS X Server












2














My aim is to allow for all employees to be able to connect to the office via a Mac mini running OS X Server (Mavericks).



I've set up the VPN service on the Mac and can connect to it fine with a MacBook Pro and iPhones; however, I'm struggling to enable a consistent (if at all) connection to the Mac with Windows 8.1 machines.



I'm using L2tp/ipsec with a PSK and have hotfixed the windows machines with the details outlined in this post.



I'm capable with setting up networks but by no means a professional, so let me know if there is information I've missed and bear with me. Has anyone run into similar issues, or are there things I might be missing?










share|improve this question
























  • Do you have CIFS service running on the server? If not start it to allow Windows shares. Or is sharing data not your goal?
    – Kevin
    May 19 '14 at 0:18










  • Sharing is one area, however the windows 8.1 machines cant seem to establish a connection. On the odd occasion that they can, they cant seem to maintain it. I'm looking to send all traffic through the VPN to allow for employees to work offsite
    – Khaled Shaaban
    May 19 '14 at 0:22
















2














My aim is to allow for all employees to be able to connect to the office via a Mac mini running OS X Server (Mavericks).



I've set up the VPN service on the Mac and can connect to it fine with a MacBook Pro and iPhones; however, I'm struggling to enable a consistent (if at all) connection to the Mac with Windows 8.1 machines.



I'm using L2tp/ipsec with a PSK and have hotfixed the windows machines with the details outlined in this post.



I'm capable with setting up networks but by no means a professional, so let me know if there is information I've missed and bear with me. Has anyone run into similar issues, or are there things I might be missing?










share|improve this question
























  • Do you have CIFS service running on the server? If not start it to allow Windows shares. Or is sharing data not your goal?
    – Kevin
    May 19 '14 at 0:18










  • Sharing is one area, however the windows 8.1 machines cant seem to establish a connection. On the odd occasion that they can, they cant seem to maintain it. I'm looking to send all traffic through the VPN to allow for employees to work offsite
    – Khaled Shaaban
    May 19 '14 at 0:22














2












2








2


2





My aim is to allow for all employees to be able to connect to the office via a Mac mini running OS X Server (Mavericks).



I've set up the VPN service on the Mac and can connect to it fine with a MacBook Pro and iPhones; however, I'm struggling to enable a consistent (if at all) connection to the Mac with Windows 8.1 machines.



I'm using L2tp/ipsec with a PSK and have hotfixed the windows machines with the details outlined in this post.



I'm capable with setting up networks but by no means a professional, so let me know if there is information I've missed and bear with me. Has anyone run into similar issues, or are there things I might be missing?










share|improve this question















My aim is to allow for all employees to be able to connect to the office via a Mac mini running OS X Server (Mavericks).



I've set up the VPN service on the Mac and can connect to it fine with a MacBook Pro and iPhones; however, I'm struggling to enable a consistent (if at all) connection to the Mac with Windows 8.1 machines.



I'm using L2tp/ipsec with a PSK and have hotfixed the windows machines with the details outlined in this post.



I'm capable with setting up networks but by no means a professional, so let me know if there is information I've missed and bear with me. Has anyone run into similar issues, or are there things I might be missing?







macos windows-8 vpn osx-mavericks osx-server






share|improve this question















share|improve this question













share|improve this question




share|improve this question








edited May 19 '14 at 0:31









Scott

15.6k113889




15.6k113889










asked May 18 '14 at 23:41









Khaled Shaaban

11112




11112












  • Do you have CIFS service running on the server? If not start it to allow Windows shares. Or is sharing data not your goal?
    – Kevin
    May 19 '14 at 0:18










  • Sharing is one area, however the windows 8.1 machines cant seem to establish a connection. On the odd occasion that they can, they cant seem to maintain it. I'm looking to send all traffic through the VPN to allow for employees to work offsite
    – Khaled Shaaban
    May 19 '14 at 0:22


















  • Do you have CIFS service running on the server? If not start it to allow Windows shares. Or is sharing data not your goal?
    – Kevin
    May 19 '14 at 0:18










  • Sharing is one area, however the windows 8.1 machines cant seem to establish a connection. On the odd occasion that they can, they cant seem to maintain it. I'm looking to send all traffic through the VPN to allow for employees to work offsite
    – Khaled Shaaban
    May 19 '14 at 0:22
















Do you have CIFS service running on the server? If not start it to allow Windows shares. Or is sharing data not your goal?
– Kevin
May 19 '14 at 0:18




Do you have CIFS service running on the server? If not start it to allow Windows shares. Or is sharing data not your goal?
– Kevin
May 19 '14 at 0:18












Sharing is one area, however the windows 8.1 machines cant seem to establish a connection. On the odd occasion that they can, they cant seem to maintain it. I'm looking to send all traffic through the VPN to allow for employees to work offsite
– Khaled Shaaban
May 19 '14 at 0:22




Sharing is one area, however the windows 8.1 machines cant seem to establish a connection. On the odd occasion that they can, they cant seem to maintain it. I'm looking to send all traffic through the VPN to allow for employees to work offsite
– Khaled Shaaban
May 19 '14 at 0:22










4 Answers
4






active

oldest

votes


















0














Please note that some Microsoft Windows clients may not be able to connect to the Mac OS X Server VPN service if the Mac OS X Server is behind a NAT (Network Address Translation) router or firewall. Therefore, you may need to modify settings on the Windows clients to allow access to the Mac OS X Server VPN service using L2TP (IPSec).



By default, the Windows client may not be configured to allow NAT traversal. This is necessary to allow a connection to the Mac OS X Server VPN service when the server itself is behind a NAT router or firewall.



The following Microsoft support articles applies to Windows Vista however it gives you better idea of how to configure an L2TP/IPsec server behind a NAT-T device:
http://support.microsoft.com/kb/926179






share|improve this answer





















  • Thanks @rose-ab, I have implemented this registry change but am still struggling to get these machines to connect. It seems that anything mac (not tested linux) based connects fine but windows just doesn't want to play nicely. I'm considering moving everything over to an openVPN solution and hoping this will fix the issues.
    – Khaled Shaaban
    May 19 '14 at 8:08





















0














I was able to get a VPN connection working from Windows 7 SP1 Pro to Mac OS X 10.9.4 Server VPN using L2TP with preshared key.




  1. Access your adapter settings (Start > search 'ncpa.cpl' >
    right-click, select 'Run as Administrator'

  2. Select your VPN connection > righ-click, select 'Properties'

  3. Select 'Options' tab > remove check from 'Include Windows logon domain'


That's it... it started working for me once I unchecked 'Include Windows logon domain'. I assume people have already configured the PSK and completed the changes listed here: http://support.apple.com/kb/HT5078.




  • If PSK has not been configured, access the VPN adapter properties and select 'Security' tab > select 'Layer 2 Tunneling Protocol with IPsec (L2TP/IPSec) from the 'Type of VPN:' drop-down list. Select 'Advanced settings' and choose 'Use preshared key for authentication' and populate the 'Key:' field with the configured preshared key, select OK.






share|improve this answer





























    0














    I made it following below steps.




    1. Click "PPP Settings..." under the Options tab, check "Negotiate multi-link for single-link connections".

    2. Under Security Tab, set Type of VPN to L2TP/IPsec.

    3. Click Advanced settings, enter/paste your pre-shared key.

    4. Then follow the steps in Apple's Support page here.

    5. Restart and you should connect.






    share|improve this answer































      0














      I was struggling with this today and followed all the recommendations given on this thread, with no luck. What finally worked was to configure the OSX VPN Service to L2TP and PPTP.






      share|improve this answer





















      • Bear in mind PPTP is broken and you should try to find/use a modern VPN technology - i.e. getting to the root cause as to why your clients can't connect to your L2TP VPN.
        – Kinnectus
        Oct 12 '18 at 8:16











      Your Answer








      StackExchange.ready(function() {
      var channelOptions = {
      tags: "".split(" "),
      id: "3"
      };
      initTagRenderer("".split(" "), "".split(" "), channelOptions);

      StackExchange.using("externalEditor", function() {
      // Have to fire editor after snippets, if snippets enabled
      if (StackExchange.settings.snippets.snippetsEnabled) {
      StackExchange.using("snippets", function() {
      createEditor();
      });
      }
      else {
      createEditor();
      }
      });

      function createEditor() {
      StackExchange.prepareEditor({
      heartbeatType: 'answer',
      autoActivateHeartbeat: false,
      convertImagesToLinks: true,
      noModals: true,
      showLowRepImageUploadWarning: true,
      reputationToPostImages: 10,
      bindNavPrevention: true,
      postfix: "",
      imageUploader: {
      brandingHtml: "Powered by u003ca class="icon-imgur-white" href="https://imgur.com/"u003eu003c/au003e",
      contentPolicyHtml: "User contributions licensed under u003ca href="https://creativecommons.org/licenses/by-sa/3.0/"u003ecc by-sa 3.0 with attribution requiredu003c/au003e u003ca href="https://stackoverflow.com/legal/content-policy"u003e(content policy)u003c/au003e",
      allowUrls: true
      },
      onDemand: true,
      discardSelector: ".discard-answer"
      ,immediatelyShowMarkdownHelp:true
      });


      }
      });














      draft saved

      draft discarded


















      StackExchange.ready(
      function () {
      StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f755910%2funable-to-get-windows-clients-connecting-to-vpn-os-x-server%23new-answer', 'question_page');
      }
      );

      Post as a guest















      Required, but never shown

























      4 Answers
      4






      active

      oldest

      votes








      4 Answers
      4






      active

      oldest

      votes









      active

      oldest

      votes






      active

      oldest

      votes









      0














      Please note that some Microsoft Windows clients may not be able to connect to the Mac OS X Server VPN service if the Mac OS X Server is behind a NAT (Network Address Translation) router or firewall. Therefore, you may need to modify settings on the Windows clients to allow access to the Mac OS X Server VPN service using L2TP (IPSec).



      By default, the Windows client may not be configured to allow NAT traversal. This is necessary to allow a connection to the Mac OS X Server VPN service when the server itself is behind a NAT router or firewall.



      The following Microsoft support articles applies to Windows Vista however it gives you better idea of how to configure an L2TP/IPsec server behind a NAT-T device:
      http://support.microsoft.com/kb/926179






      share|improve this answer





















      • Thanks @rose-ab, I have implemented this registry change but am still struggling to get these machines to connect. It seems that anything mac (not tested linux) based connects fine but windows just doesn't want to play nicely. I'm considering moving everything over to an openVPN solution and hoping this will fix the issues.
        – Khaled Shaaban
        May 19 '14 at 8:08


















      0














      Please note that some Microsoft Windows clients may not be able to connect to the Mac OS X Server VPN service if the Mac OS X Server is behind a NAT (Network Address Translation) router or firewall. Therefore, you may need to modify settings on the Windows clients to allow access to the Mac OS X Server VPN service using L2TP (IPSec).



      By default, the Windows client may not be configured to allow NAT traversal. This is necessary to allow a connection to the Mac OS X Server VPN service when the server itself is behind a NAT router or firewall.



      The following Microsoft support articles applies to Windows Vista however it gives you better idea of how to configure an L2TP/IPsec server behind a NAT-T device:
      http://support.microsoft.com/kb/926179






      share|improve this answer





















      • Thanks @rose-ab, I have implemented this registry change but am still struggling to get these machines to connect. It seems that anything mac (not tested linux) based connects fine but windows just doesn't want to play nicely. I'm considering moving everything over to an openVPN solution and hoping this will fix the issues.
        – Khaled Shaaban
        May 19 '14 at 8:08
















      0












      0








      0






      Please note that some Microsoft Windows clients may not be able to connect to the Mac OS X Server VPN service if the Mac OS X Server is behind a NAT (Network Address Translation) router or firewall. Therefore, you may need to modify settings on the Windows clients to allow access to the Mac OS X Server VPN service using L2TP (IPSec).



      By default, the Windows client may not be configured to allow NAT traversal. This is necessary to allow a connection to the Mac OS X Server VPN service when the server itself is behind a NAT router or firewall.



      The following Microsoft support articles applies to Windows Vista however it gives you better idea of how to configure an L2TP/IPsec server behind a NAT-T device:
      http://support.microsoft.com/kb/926179






      share|improve this answer












      Please note that some Microsoft Windows clients may not be able to connect to the Mac OS X Server VPN service if the Mac OS X Server is behind a NAT (Network Address Translation) router or firewall. Therefore, you may need to modify settings on the Windows clients to allow access to the Mac OS X Server VPN service using L2TP (IPSec).



      By default, the Windows client may not be configured to allow NAT traversal. This is necessary to allow a connection to the Mac OS X Server VPN service when the server itself is behind a NAT router or firewall.



      The following Microsoft support articles applies to Windows Vista however it gives you better idea of how to configure an L2TP/IPsec server behind a NAT-T device:
      http://support.microsoft.com/kb/926179







      share|improve this answer












      share|improve this answer



      share|improve this answer










      answered May 19 '14 at 6:11









      Rose Ab

      23114




      23114












      • Thanks @rose-ab, I have implemented this registry change but am still struggling to get these machines to connect. It seems that anything mac (not tested linux) based connects fine but windows just doesn't want to play nicely. I'm considering moving everything over to an openVPN solution and hoping this will fix the issues.
        – Khaled Shaaban
        May 19 '14 at 8:08




















      • Thanks @rose-ab, I have implemented this registry change but am still struggling to get these machines to connect. It seems that anything mac (not tested linux) based connects fine but windows just doesn't want to play nicely. I'm considering moving everything over to an openVPN solution and hoping this will fix the issues.
        – Khaled Shaaban
        May 19 '14 at 8:08


















      Thanks @rose-ab, I have implemented this registry change but am still struggling to get these machines to connect. It seems that anything mac (not tested linux) based connects fine but windows just doesn't want to play nicely. I'm considering moving everything over to an openVPN solution and hoping this will fix the issues.
      – Khaled Shaaban
      May 19 '14 at 8:08






      Thanks @rose-ab, I have implemented this registry change but am still struggling to get these machines to connect. It seems that anything mac (not tested linux) based connects fine but windows just doesn't want to play nicely. I'm considering moving everything over to an openVPN solution and hoping this will fix the issues.
      – Khaled Shaaban
      May 19 '14 at 8:08















      0














      I was able to get a VPN connection working from Windows 7 SP1 Pro to Mac OS X 10.9.4 Server VPN using L2TP with preshared key.




      1. Access your adapter settings (Start > search 'ncpa.cpl' >
        right-click, select 'Run as Administrator'

      2. Select your VPN connection > righ-click, select 'Properties'

      3. Select 'Options' tab > remove check from 'Include Windows logon domain'


      That's it... it started working for me once I unchecked 'Include Windows logon domain'. I assume people have already configured the PSK and completed the changes listed here: http://support.apple.com/kb/HT5078.




      • If PSK has not been configured, access the VPN adapter properties and select 'Security' tab > select 'Layer 2 Tunneling Protocol with IPsec (L2TP/IPSec) from the 'Type of VPN:' drop-down list. Select 'Advanced settings' and choose 'Use preshared key for authentication' and populate the 'Key:' field with the configured preshared key, select OK.






      share|improve this answer


























        0














        I was able to get a VPN connection working from Windows 7 SP1 Pro to Mac OS X 10.9.4 Server VPN using L2TP with preshared key.




        1. Access your adapter settings (Start > search 'ncpa.cpl' >
          right-click, select 'Run as Administrator'

        2. Select your VPN connection > righ-click, select 'Properties'

        3. Select 'Options' tab > remove check from 'Include Windows logon domain'


        That's it... it started working for me once I unchecked 'Include Windows logon domain'. I assume people have already configured the PSK and completed the changes listed here: http://support.apple.com/kb/HT5078.




        • If PSK has not been configured, access the VPN adapter properties and select 'Security' tab > select 'Layer 2 Tunneling Protocol with IPsec (L2TP/IPSec) from the 'Type of VPN:' drop-down list. Select 'Advanced settings' and choose 'Use preshared key for authentication' and populate the 'Key:' field with the configured preshared key, select OK.






        share|improve this answer
























          0












          0








          0






          I was able to get a VPN connection working from Windows 7 SP1 Pro to Mac OS X 10.9.4 Server VPN using L2TP with preshared key.




          1. Access your adapter settings (Start > search 'ncpa.cpl' >
            right-click, select 'Run as Administrator'

          2. Select your VPN connection > righ-click, select 'Properties'

          3. Select 'Options' tab > remove check from 'Include Windows logon domain'


          That's it... it started working for me once I unchecked 'Include Windows logon domain'. I assume people have already configured the PSK and completed the changes listed here: http://support.apple.com/kb/HT5078.




          • If PSK has not been configured, access the VPN adapter properties and select 'Security' tab > select 'Layer 2 Tunneling Protocol with IPsec (L2TP/IPSec) from the 'Type of VPN:' drop-down list. Select 'Advanced settings' and choose 'Use preshared key for authentication' and populate the 'Key:' field with the configured preshared key, select OK.






          share|improve this answer












          I was able to get a VPN connection working from Windows 7 SP1 Pro to Mac OS X 10.9.4 Server VPN using L2TP with preshared key.




          1. Access your adapter settings (Start > search 'ncpa.cpl' >
            right-click, select 'Run as Administrator'

          2. Select your VPN connection > righ-click, select 'Properties'

          3. Select 'Options' tab > remove check from 'Include Windows logon domain'


          That's it... it started working for me once I unchecked 'Include Windows logon domain'. I assume people have already configured the PSK and completed the changes listed here: http://support.apple.com/kb/HT5078.




          • If PSK has not been configured, access the VPN adapter properties and select 'Security' tab > select 'Layer 2 Tunneling Protocol with IPsec (L2TP/IPSec) from the 'Type of VPN:' drop-down list. Select 'Advanced settings' and choose 'Use preshared key for authentication' and populate the 'Key:' field with the configured preshared key, select OK.







          share|improve this answer












          share|improve this answer



          share|improve this answer










          answered Sep 3 '14 at 13:22









          Carlos

          1




          1























              0














              I made it following below steps.




              1. Click "PPP Settings..." under the Options tab, check "Negotiate multi-link for single-link connections".

              2. Under Security Tab, set Type of VPN to L2TP/IPsec.

              3. Click Advanced settings, enter/paste your pre-shared key.

              4. Then follow the steps in Apple's Support page here.

              5. Restart and you should connect.






              share|improve this answer




























                0














                I made it following below steps.




                1. Click "PPP Settings..." under the Options tab, check "Negotiate multi-link for single-link connections".

                2. Under Security Tab, set Type of VPN to L2TP/IPsec.

                3. Click Advanced settings, enter/paste your pre-shared key.

                4. Then follow the steps in Apple's Support page here.

                5. Restart and you should connect.






                share|improve this answer


























                  0












                  0








                  0






                  I made it following below steps.




                  1. Click "PPP Settings..." under the Options tab, check "Negotiate multi-link for single-link connections".

                  2. Under Security Tab, set Type of VPN to L2TP/IPsec.

                  3. Click Advanced settings, enter/paste your pre-shared key.

                  4. Then follow the steps in Apple's Support page here.

                  5. Restart and you should connect.






                  share|improve this answer














                  I made it following below steps.




                  1. Click "PPP Settings..." under the Options tab, check "Negotiate multi-link for single-link connections".

                  2. Under Security Tab, set Type of VPN to L2TP/IPsec.

                  3. Click Advanced settings, enter/paste your pre-shared key.

                  4. Then follow the steps in Apple's Support page here.

                  5. Restart and you should connect.







                  share|improve this answer














                  share|improve this answer



                  share|improve this answer








                  edited May 14 '15 at 12:48









                  kenorb

                  10.7k1577111




                  10.7k1577111










                  answered May 14 '15 at 12:21









                  Lu Ji

                  1




                  1























                      0














                      I was struggling with this today and followed all the recommendations given on this thread, with no luck. What finally worked was to configure the OSX VPN Service to L2TP and PPTP.






                      share|improve this answer





















                      • Bear in mind PPTP is broken and you should try to find/use a modern VPN technology - i.e. getting to the root cause as to why your clients can't connect to your L2TP VPN.
                        – Kinnectus
                        Oct 12 '18 at 8:16
















                      0














                      I was struggling with this today and followed all the recommendations given on this thread, with no luck. What finally worked was to configure the OSX VPN Service to L2TP and PPTP.






                      share|improve this answer





















                      • Bear in mind PPTP is broken and you should try to find/use a modern VPN technology - i.e. getting to the root cause as to why your clients can't connect to your L2TP VPN.
                        – Kinnectus
                        Oct 12 '18 at 8:16














                      0












                      0








                      0






                      I was struggling with this today and followed all the recommendations given on this thread, with no luck. What finally worked was to configure the OSX VPN Service to L2TP and PPTP.






                      share|improve this answer












                      I was struggling with this today and followed all the recommendations given on this thread, with no luck. What finally worked was to configure the OSX VPN Service to L2TP and PPTP.







                      share|improve this answer












                      share|improve this answer



                      share|improve this answer










                      answered May 10 '18 at 21:37









                      VictorEspina

                      11




                      11












                      • Bear in mind PPTP is broken and you should try to find/use a modern VPN technology - i.e. getting to the root cause as to why your clients can't connect to your L2TP VPN.
                        – Kinnectus
                        Oct 12 '18 at 8:16


















                      • Bear in mind PPTP is broken and you should try to find/use a modern VPN technology - i.e. getting to the root cause as to why your clients can't connect to your L2TP VPN.
                        – Kinnectus
                        Oct 12 '18 at 8:16
















                      Bear in mind PPTP is broken and you should try to find/use a modern VPN technology - i.e. getting to the root cause as to why your clients can't connect to your L2TP VPN.
                      – Kinnectus
                      Oct 12 '18 at 8:16




                      Bear in mind PPTP is broken and you should try to find/use a modern VPN technology - i.e. getting to the root cause as to why your clients can't connect to your L2TP VPN.
                      – Kinnectus
                      Oct 12 '18 at 8:16


















                      draft saved

                      draft discarded




















































                      Thanks for contributing an answer to Super User!


                      • Please be sure to answer the question. Provide details and share your research!

                      But avoid



                      • Asking for help, clarification, or responding to other answers.

                      • Making statements based on opinion; back them up with references or personal experience.


                      To learn more, see our tips on writing great answers.





                      Some of your past answers have not been well-received, and you're in danger of being blocked from answering.


                      Please pay close attention to the following guidance:


                      • Please be sure to answer the question. Provide details and share your research!

                      But avoid



                      • Asking for help, clarification, or responding to other answers.

                      • Making statements based on opinion; back them up with references or personal experience.


                      To learn more, see our tips on writing great answers.




                      draft saved


                      draft discarded














                      StackExchange.ready(
                      function () {
                      StackExchange.openid.initPostLogin('.new-post-login', 'https%3a%2f%2fsuperuser.com%2fquestions%2f755910%2funable-to-get-windows-clients-connecting-to-vpn-os-x-server%23new-answer', 'question_page');
                      }
                      );

                      Post as a guest















                      Required, but never shown





















































                      Required, but never shown














                      Required, but never shown












                      Required, but never shown







                      Required, but never shown

































                      Required, but never shown














                      Required, but never shown












                      Required, but never shown







                      Required, but never shown







                      Popular posts from this blog

                      flock() on closed filehandle LOCK_FILE at /usr/bin/apt-mirror

                      Mangá

                      Eduardo VII do Reino Unido